r/ipv6

▲ 12 r/ipv6

IPv6 multihoming without BGP on OPNsense

Hello everyone,

I'm currently trying to get multihoming without BGP on OPNsense to work. Uplink A has a /56 delegation that I use to provide GUAs for each device. Uplink B is using the cellular network and receives a /128 GUA and a /128 ULA. If uplink A goes down I want to route the traffic with NAT over uplink B. None of the IPv6 addresses are static.

I've been setting it up and it works if I specify the /128 GUA as a translation address. If I just specify the interface address it will unfortunately translate to the ULA and not work. Is there a way to fix this without scripting?

Looking forward to your responses!

reddit.com
u/Proof_Bodybuilder740 — 2 days ago
▲ 36 r/ipv6

How many Clients can I put on a /64 subnet?

I know, I know, the answer is 2^64 (or 2^64-1).

But how many can I realistically put on a /64 subnet without any problems?

Every time I read about the advantages of IPv6 over IPv4, bigger address space and no broadcast come up. Because broadcast is one of the reasons we usually don't use much bigger subnets than /24 in IPv4, i was wondering how much of a difference it really makes.

Do u have any experience or resources on this?

reddit.com
u/Senyyyo — 4 days ago
▲ 12 r/ipv6

new to IPv6 - I have some basic addressing questions.

I am new to IPv6. I've used IPv4 since the late 80s so its mostly the V6 part that I have questions on.

My local ISP ( Frontier Texas region ) still does not do IPv6 so I've never really seen much need for it.. one reason I haven't paid much attention to it. Seriously... the MAJOR thing I've never liked about IPv6 is because I am old and set in my ways and I've am very familiar with IPv4 addresses and subnets.

I see:
2607:f8b0:4023:100b::64

fe80::2a13:ff4f:44ff:c1e2

fe80::fc54:ff:fe59:4166

fe80::fc54:ff:fe34:35d4

fe80::2e0:4cff:fe6a:6edd

fe80::c24:eb03:3c7d:d777

fe80::dc49:5a0:2144:8ca9

fe80::aad4:ce50:2157:56c2

and I just want to bury my head in my pillow...

I was asking google about setting up a local ipv6 network and it said that I could use:
fd00:10:12:14::31 (NIC 1 for serverA)

fd00:172:16:12::31 (NIC 2 for serverA)

fd00:10:12:14::32 (NIC 1 for serverB)

fd00:10:12:14::4 (NIC 1 for serverC)

is that True? I could have used those all along? That never occurred to me. I know that it's hex and not base 10.. but I am a visual person and I can visualize those ips just fine.

is it really that simple?

reddit.com
u/mylinuxguy — 4 days ago
▲ 68 r/ipv6

Sharing my IPv6-Mostly Home Lab: NAT64, 464XLAT, internal NAT64 & RFC 8781

Hi r/ipv6,

About 8 months ago I shared my IPv6-mostly home lab and the lessons I had learned while moving my network toward IPv6-first operation. Since then, the lab has evolved quite a bit, and I thought I'd share some of the more interesting additions and implementation details.

The goal of this project is still the same: run day-to-day services over IPv6 wherever possible while providing transparent access to IPv4 resources only when necessary. Rather than simply making IPv6 "work", I've been trying to understand how the transition technologies actually behave and how they can be combined into a practical network.

Some of the additions since my last post include:

  • Native NAT64/DNS64 for IPv6-only clients
  • 464XLAT using dedicated CLAT gateway for IPv4-only applications on an IPv6-only network.
  • An internal NAT64 translator that allows IPv6-only devices to reach IPv4-only internal services (currently Plex).
  • An IPv6-only transit network between translation components.
  • Automatic recovery after reboot using systemd services for Jool and the required iptables steering rules.

One of the more interesting discoveries involved RFC 8781.

I wanted to keep a single PREF64 (/96) while sending only the embedded 10.0.0.0/8 addresses to a separate NAT64 translator. Linux routing made this possible by installing a more-specific /104 route for the embedded 10/8 space, while all remaining traffic continued to the primary Internet NAT64 translator.

Initially this didn't work because I was running Jool in Netfilter mode. Jool intercepted every packet destined for the /96 before Linux had a chance to apply longest-prefix routing, so the /104 route was never used.

Switching Jool to iptables mode solved the problem by allowing selective interception. Internal NAT64 traffic is now routed first by Linux to the second translator, while Internet traffic continues to be translated locally by the NAT64 gateway.

The result is a design where clients only know about a single NAT64 prefix, while the network transparently selects the appropriate translator.

Tha lab now successfully supports all three simultaneously:

  • Native Internet NAT64
  • 464XLAT for legacy IPv4 applications
  • Internal NAT64 for IPv4-only services such as Plex

This has been a really fun learning project over the past few years. Although it's build entirely from repurposed hardware rather than carrier equipment, it is been a great way to explore how IPv6 transition mechanism interact in practice and to better understand the operational behavior behind the RFCs.

I'm happy to answer questions, and I'd also be interested in hearing how others are approaching IPv6-only or IPv6-mostly home networks.

reddit.com
u/myth20_ — 4 days ago
▲ 6 r/ipv6+1 crossposts

Enabling IPv6?

My parents have Planet Networks service in Vernon, NJ. I recently installed a Unifi Dream Router 7 on their network (so I can remotely manage it). The router says IPv6 is available. I turned on DHCPv6 on the WAN side but nothing is happening. The router is seeing an IPv6 router advertisement (says it's a /64 but the prefix given looks like a /48). Do we need to contact Planet Networks to enable IPv6? Does Planet Networks use SLAAC or another method for IPv6? Is Planet Networks working towards IPv6 but not there yet?

Thank you for any help.

reddit.com
u/s6484d2843 — 5 days ago
▲ 42 r/ipv6

How does IPv6 win over IPv7, IPv8 and IPv9?

Recentlly I'm learning the history of the IP protocol, and find out during 1990s, there're IPv7(RFC 1475), IPv8(here I mean RFC 1621, not rencently suspicious vide-drafted document) and IPv9(RFC 1347).

How does IPv6 finally win over other protocols? And why is IPv6 extended to 128 bits? I found out in the early version for IPv6(simple Internet Protocol, RFC 8507), the address length is 64 bits.

Is there any collection for all those kind of historic discussions?

reddit.com
u/ybx332 — 7 days ago
▲ 91 r/ipv6

iCloud outgoing Mail supporting IPv6 now

Noticed that Mails from Apple / iCloud now are coming in from IPv6 sources. Seems like they have been rolling out over the past few weeks and have finished by 4th of august, screenshot from a mail provider, filtered to mail from *@icloud.com:

https://preview.redd.it/ninvjcytf5jh1.png?width=584&format=png&auto=webp&s=a65c8db7c6d774c2e91ac51b15a6df444023ed9b

But still no IPv6 endpoints on the MX records of icloud.com though.

reddit.com
u/ninmuzz — 7 days ago
▲ 159 r/ipv6+1 crossposts

IPv6 is no longer optional for DNS: RFC10001 replaces RFC3901 in BCP91

This document provides guidelines and documents best current practice for operating authoritative DNS servers, recursive resolvers, and stub resolvers in a mixed IPv4/IPv6 environment. This document recommends that both authoritative DNS servers and recursive resolvers support IPv4 and IPv6. It also provides guidance on how recursive DNS resolvers should select upstream DNS servers, including when IPv4-embedded IPv6 addresses are available. This document obsoletes RFC 3901. This document is a product of the Domain Name System Operations Working Group of the IETF.

https://datatracker.ietf.org/doc/rfc10001/

reddit.com
u/ichdasich — 9 days ago
▲ 55 r/ipv6

September Deadline Looms as U.S. Federal Government Pushes Toward 60% IPv6 Deployment

The clock is ticking toward the end of FY2026, and the federal government's next major IPv6 milestone is rapidly approaching. While many agencies missed the original FY2025 objective, the Trump administration is continuing federal IT modernization efforts as agencies push ahead with IPv6 deployment across government networks. Proposed transition milestones call for 60% IPv6-only deployment by the end of FY2026, 80% by the end of FY2027, and full IPv6-only deployment by the end of FY2028 as the government continues reducing reliance on legacy IPv4 infrastructure.

https://www.gsa.gov/directives-library/internet-protocol-version-6-ipv6-policy-1

u/LiberalJewMan — 8 days ago
▲ 29 r/ipv6+1 crossposts

Connecting an illumos server to a Japanese IPv6 service

My Japanese ISP provides native IPv6 while carrying IPv4 through a mechanism selected by its own discovery protocol. That protocol uses the ISP DNS resolver to locate a provisioning service, which then returns the IPv4 over IPv6 mechanism and its endpoint. On my connection it selected DS-Lite.

I implemented the discovery protocol and a DS-Lite tunnel daemon in Rust, then connected my OmniOS host to the ISP supplied modem, with no router in between. The tunnel worked, but the final test exposed another part of the IPv6 access model. The ISP delegated a /56 through DHCPv6 prefix delegation, while stock illumos DHCP client requested only a host address and could not manage the delegated prefix.

I wrote about the implementation, Japanese ISP provisioning, and the direct connection experiment.

skalski.dev
u/MegaMotyl — 8 days ago
▲ 7 r/ipv6

Usually, for IPv6, /64 subnets for local use are recommended. Will there be any issues if I choose a /32 or a larger subnet?

For a container orchestrator I need to make a choice on the subnet I want the containers to use. Usually I've seen /64 subnets being recommended in this sub for general local use but it seems like the Container Network Interface (CNI) supports subnets of any size. To keep IPs of the containers short I chose a /32 subnet, i.e. fe42:42::/32 for simplicity. Containers get assigned addresses like fe42:42::2/128 correctly and the whole dual-stack setup seems to work flawlessly so far. Is there anything worth knowing when choosing a larger subnet than the usual /64 besides possible collisions with other subnets if I can be sure that there won't be any other local subnets with that prefix? I use stateful DHCPv6 so SLAAC is not an issue.

reddit.com
u/One_Ninja_8512 — 12 days ago
▲ 29 r/ipv6+2 crossposts

IPv6 works perfectly through UniFi switches, but switch management has no GUA and UniFi cannot see wired clients’ IPv6 addresses

Hi everyone,
I’m trying to understand some IPv6 behavior in a mixed Swisscom/UniFi network.
This is NOT an IPv6 connectivity problem. IPv6 itself works perfectly. What I’m trying to understand is how UniFi handles IPv6 on the management plane and how UniFi Network learns and reports IPv6 addresses when the gateway is not a UniFi device.
My setup is:
Swisscom Internet-Box 5 Pro, 10 Gbit/s FTTH, acting as IPv4/IPv6 router and firewall.
Connected to it is a UniFi Flex XG running firmware 7.5.10.
Behind the Flex XG I have a UniFi Flex 2.5G 8 running firmware 7.4.2.
The Flex 2.5G 8 has, among other devices, a QNAP TS-264 connected through a 2 x 2.5 GbE ALB trunk.
I also have Mac Studios connected both directly to the Flex XG and behind the Flex 2.5G.
The UniFi devices are managed by a CloudKey Plus running UniFi Network 10.5.67.
There is NO UniFi gateway in the network. Routing, DHCP, IPv6 Router Advertisements, firewalling, etc. are all handled by the Swisscom Internet-Box 5 Pro.
The LAN currently uses the public IPv6 prefix:
2a02:1210:6614:5900::/64
IPv6 itself definitely works
Macs receive both global IPv6 addresses and link-local addresses correctly.
My QNAP TS-264 is explicitly configured for IPv6 Auto-Configuration (Stateless/SLAAC) and receives:
2a02:1210:6614:5900:265e:beff:fe83:9c38/64
I can ping6 that address from a Mac with 0% packet loss.
I can also open the QNAP web interface directly using its IPv6 address.
The important point is that the QNAP is physically behind the Flex 2.5G 8, which is itself behind the Flex XG.
I also ran an Internet speed test against Swisscom’s IPv6 server and obtained approximately 8.0 Gbit/s download and 7.6–7.8 Gbit/s upload, with 0% packet loss.
So IPv6 forwarding through both UniFi switches is unquestionably working correctly.
Problem/question 1: UniFi does not show IPv6 addresses for wired clients
In UniFi Network, under Client Devices, I can enable two columns:
IPv6 Address
IPv6 Link Local
However, both columns show “-” for my wired clients.
For example, I have a Mac Studio connected DIRECTLY to the Flex XG at 10 GbE.
UniFi sees the Mac correctly, including its IPv4 address, but shows “-” under both IPv6 columns.
The Swisscom Internet-Box, however, correctly shows both the Mac’s global IPv6 address and its link-local IPv6 address.
The exact same thing happens with another Mac located behind the Flex 2.5G 8.
Therefore this cannot be caused by the Flex 2.5G being downstream from the Flex XG.
My main question here is whether this is expected when UniFi Network is used with a third-party IPv6 gateway.
Does UniFi normally obtain the IPv6-to-client association from the NDP/Neighbor table of a UniFi gateway?
If there is no UniFi gateway, is it expected that the IPv6 Address and IPv6 Link Local columns remain empty?
Should the UniFi switches themselves be capable of learning and reporting those IPv6 addresses, or does this information fundamentally depend on the gateway?
Problem/question 2: Flex XG has a link-local IPv6 address but apparently no GUA
The Flex XG is managed via IPv4 at:
192.168.1.11
UniFi also reports this IPv6 link-local address for the Flex XG:
fe80::265a:4cff:fe1b:59d
However, neither UniFi nor the Swisscom router shows any global 2a02:… IPv6 address for the switch.
This is interesting because Macs, the QNAP and even the CloudKey Plus on the exact same LAN all obtain global IPv6 addresses without any problem.
I found the following official Ubiquiti release-note entry for UniFi Switch 7.2.123:
[USW-Flex-XG] Fixed a device crash issue while requesting a DHCPv6 address.
So we know that, at least under some circumstances, the Flex XG has DHCPv6 functionality capable of requesting an IPv6 address.
What I have NOT been able to find is reliable documentation explaining exactly how IPv6 addressing of the Flex XG management interface works.
Does the USW-Flex-XG use SLAAC for its management GUA?
Does it use DHCPv6?
Does it support both?
If DHCPv6 is used, does it specifically use IA_NA?
Does its behavior change depending on whether the gateway is a UniFi gateway or a third-party router?
Is it normal for a Flex XG to have only a link-local IPv6 address and no global IPv6 management address?
Is there any way to configure SLAAC, DHCPv6 or a static IPv6 address for switch management?
I have found contradictory claims about this online, so I would be especially interested in first-hand experience, packet captures, SSH/debug-console output or actual Ubiquiti documentation.
Importantly, I do NOT want to assume that “the Flex XG requests a DHCPv6 address” means that it ONLY supports DHCPv6 or that it does not support SLAAC. The release note alone does not prove that.
Problem/question 3: Flex 2.5G 8
The Flex 2.5G 8 is managed via IPv4 at:
192.168.1.12
Unlike the Flex XG, UniFi does not even show an IPv6 Link Local field for this switch.
Yet IPv6 forwarding through it works perfectly, as demonstrated by the QNAP and other devices behind it.
Does anyone know whether the USW-Flex-2.5G-8 currently supports IPv6 on its own management plane?
Does it support SLAAC?
Does it support DHCPv6?
Should it at least have a link-local IPv6 address?
Is the lack of IPv6 information simply a firmware/UniFi Network reporting limitation?
Is IPv6 management implemented differently on the Flex 2.5G family compared with the Flex XG?
What I am NOT trying to fix
I do not actually need to manage the switches over IPv6. Managing them over IPv4 is perfectly fine for me.
I also do not want to modify a working IPv6 configuration just to make an address appear in UniFi.
IPv6 forwarding already works perfectly end-to-end.
What I am trying to understand is why the situation looks like this:
Wired clients use IPv6 perfectly and the Swisscom router sees their IPv6 addresses, but UniFi shows “-”.
The Flex XG has a link-local IPv6 address, but apparently no visible global IPv6 address.
The Flex 2.5G 8 forwards IPv6 perfectly, but UniFi shows no IPv6 management information for it.
Meanwhile the CloudKey Plus, Macs and QNAP all receive normal global IPv6 addresses on the same LAN.
If this is simply a limitation of UniFi management/reporting when using a third-party IPv6 gateway, that is perfectly fine. I would just like to understand the actual technical mechanism rather than start changing a network that already works correctly.
Any experience with Flex XG, Flex 2.5G, UniFi Network without a UniFi gateway, SLAAC/DHCPv6 switch management, or NDP-based client discovery would be very welcome.

reddit.com
u/bubeli — 11 days ago
▲ 4 r/ipv6+1 crossposts

The push to mandatory IPv6 is coming. With the majority of Internet traffic already using IPv6, web services are beginning to plan rolling IPv4 blackouts to identify IPv4-only client networks and accelerate IPv6 adoption.

The push to mandatory IPv6 is coming, with the majority of traffic already being IPv6, and there are now efforts to normalize rolling IPv4 blackouts to bring remaining client networks into compliance.

https://www.ietf.org/archive/id/draft-martin-retry-over-ipv6-04.txt

reddit.com
u/CuriousCowMeat — 13 days ago
▲ 7 r/ipv6

Validating a host idea: Low-cost IPv6-only LXC & VMs in Brazil vs. Big Tech saturation.

I have an infrastructure based in Brazil fully available to offer LXCs or VMs to small developers on IPv6 only, at attractive prices. Would it be a good strategy to offer this type of service in the market? I've noticed the market is saturated with providers, and competing with big tech is a challenge.

reddit.com
u/BeautifulTrade4488 — 11 days ago
▲ 12 r/ipv6

Caribbean IPv6 Monitor

"You can't fix, what you don't monitor"

After building this site: https://pacific.ipv6forum.com I was requested to build the same but for the Caribbean. I use EEZ because land masses are difficult to see on a map for island countries. It uses the same code base, and it is on Github. It uses data from APNIC for the IPv6 % preference, but also monitor sites for their deployment of IPv6 and measure a couple of extra standards (DNSSEC, DMARC, RPKI,...)

If there are domain names missing or errors, please let me know, or better submit a PR.

caribbean.ipv6forum.com
u/FranckMartin — 14 days ago