IPv6 in practice: address planning and operations

IPv6 is not harder than IPv4 – but it is different. The biggest shift is that you no longer ration addresses. This guide shows how to build an address plan that is easy to read and operate.

Why care about IPv6 now?

  • There are no more free IPv4 addresses to get from the regional registries, and many mobile and fibre networks are IPv6-first.
  • Every modern operating system uses IPv6 by default when available. If there is IPv6 on your network without you knowing, there is also traffic you have no rules for.
  • A good address plan from the start is much easier than tidying up later.

What an IPv6 address looks like

An IPv6 address is 128 bits, written as eight groups of four hexadecimal characters: 2001:0db8:abcd:0110:0000:0000:0000:0001. Per RFC 5952 it is written compactly: lower case, no leading zeros in each group, and the longest run of zero groups replaced by :: – once. The result is 2001:db8:abcd:110::1.

The first 64 bits are the network part (prefix and subnet ID), the last 64 the interface ID.

Address types

RangeTypeUsed for
2000::/3Global unicast (GUA)Normal, routable addresses from a provider or registry
fd00::/8Unique local (ULA)Internal addresses, equivalent to private IPv4 addresses
fe80::/10Link-localPresent on every interface, used locally on the link (neighbours, router advertisements)
ff00::/8MulticastReplaces broadcast
::1/128LoopbackThe machine itself
2001:db8::/32DocumentationExamples only, as in this guide

What do you get assigned?

A business or site typically gets a /48 from its provider or registry. Smaller sites and residential customers often get a /56. A /48 gives 65,536 networks of size /64 – enough for a network per VLAN with plenty of margin.

Rule 1: every LAN is a /64

Stateless address autoconfiguration (SLAAC) requires the LAN to be exactly a /64. It feels wasteful coming from IPv4, but that is how the protocol is built. The exceptions are point-to-point links between routers, which can use a /127 (RFC 6164), and loopbacks, which use a /128. It is still wise to set aside a whole /64 per link in the plan.

Rule 2: split on nibble boundaries

Each hexadecimal character is four bits. Split the prefix in four-bit steps and every level of the plan becomes its own character in the address:

LevelPrefixCountExample
Organisation/4812001:db8:abcd::/48
Site or building/52162001:db8:abcd:1000::/52
Function or floor/5616 per site2001:db8:abcd:1100::/56
VLAN/64256 per function2001:db8:abcd:1110::/64

Reverse DNS then becomes simple too, because ip6.arpa zones are split per character.

Rule 3: make the plan readable

A good IPv6 plan can be read straight from the address. A practical trick is to use the VLAN number as the subnet ID: VLAN 110 becomes 2001:db8:abcd:110::/64, VLAN 20 becomes 2001:db8:abcd:20::/64. It is not mathematically “correct” (the number is read as hexadecimal), but everyone on the operations team recognises the network immediately.

Example dual-stack plan
VLAN 10  Administration   10.10.10.0/26    2001:db8:abcd:10::/64
VLAN 20  Staff            10.10.16.0/23    2001:db8:abcd:20::/64
VLAN 30  Students         10.10.32.0/21    2001:db8:abcd:30::/64
VLAN 99  Network devices  10.10.63.0/27    2001:db8:abcd:99::/64

How do machines get an address?

MethodHowSuits
SLAACThe machine builds its own address from the prefix in the router advertisementClients. Simple and robust
DHCPv6 (stateful)A DHCPv6 server hands out addresses, as in IPv4Networks where you must know exactly who has which address
DHCPv6 (stateless)SLAAC for the address, DHCPv6 for DNS and other optionsWhen you need to hand out extra options
StaticConfigured manuallyServers, routers and network equipment
Android does not support stateful DHCPv6. Networks with Android devices must therefore have SLAAC enabled.

With SLAAC the interface ID is built either from the MAC address (EUI-64), as a stable but not MAC-based ID (RFC 7217), or as temporary random addresses for privacy (RFC 8981). Modern clients normally use the last two. For servers and equipment, fixed addresses are best – ideally short and readable, like 2001:db8:abcd:20::10.

You can work out the EUI-64 address for a MAC with the IPv6 subnet calculator.

ULA or global addresses?

Use global addresses (GUA) as the rule – internally too. IPv6 is designed for every machine to have a globally unique address, and security lives in the firewall, not in address translation. ULA (fd00::/8) is useful for services that should only be reached internally, and for networks that need stable addresses even if the provider changes the prefix. The ULA prefix should contain a random global ID – generate one in the calculator.

Avoid NAT for IPv6 (NAT66) unless you have a very specific reason.

Dual stack

Most networks run IPv4 and IPv6 side by side for many years. Plan them together: the same VLANs, the same segmentation and the same firewall rules for both. Add AAAA records in DNS for services that should be reachable over IPv6. Clients automatically pick whichever protocol responds fastest (Happy Eyeballs).

Reverse DNS

IPv6 reverse DNS lives under ip6.arpa, with one level per hexadecimal character in reverse order. For 2001:db8:abcd::/48 the zone is d.c.b.a.8.b.d.0.1.0.0.2.ip6.arpa. If you split on nibble boundaries, each zone can be delegated cleanly. For clients with random addresses it is common to skip PTR records, or to let the DHCP server update them.

Security

  • Firewall rules must cover IPv6. A common mistake is that IPv4 is locked down while IPv6 is wide open.
  • Do not block all ICMPv6. Neighbour discovery, router advertisements and Path MTU Discovery depend on it. Allow at least types 1–4, 128–129 and 133–136.
  • Enable RA Guard and DHCPv6 Guard on switches where possible, so clients cannot announce themselves as routers.
  • Monitor the network for IPv6 traffic even if you “do not use IPv6” yet.

Checklist

  1. Find out which prefix you have been assigned, and register it in ipmanager.
  2. Build a plan on nibble boundaries, with one /64 per VLAN.
  3. Decide SLAAC or DHCPv6 per segment.
  4. Update firewall rules for IPv6, including the required ICMPv6.
  5. Give servers and network equipment fixed addresses, and add them to DNS.
  6. Enable IPv6 one segment at a time, and test.

The IPv6 planner in ipmanager creates one /64 per segment from a /48 or /56, with the VLAN number as the subnet ID, and shows addresses in both compressed and full form. Get started free.

Get your IP addresses under control today

Free for up to 100 IP addresses. Sign-in details by email immediately, no credit card.