A real-life situation
Your company has a new IPv6 prefix from its provider. The plan is dual stack: keep IPv4 running and add IPv6 alongside it. You log in to R1, the router for the office LAN, and need to give its interfaces IPv6 addresses. You also want the PCs to configure themselves, so nobody has to type an address into every laptop.
This lesson assumes you can read and shorten IPv6 addresses and know the address types. If not, start with IPv6 addressing and IPv6 address types. This lesson focuses on the IOS commands.
- 1. R1 advertises the LAN prefix. With ipv6 unicast-routing on, R1 sends Router Advertisements on Gi0/0. PC1 learns the prefix and its default gateway (R1's link-local address).
- 2. PC1 reaches the server. PC1 sends to R1. R1 forwards toward R2 once it has a route (the next lesson adds the static routes).
The addressing plan for the whole IPv6 course:
| Device | Interface | Global address | Link-local |
|---|---|---|---|
| R1 | Gi0/0 (LAN) | 2001:db8:acad:1::1/64 | fe80::1 |
| R1 | Gi0/1 (to R2) | 2001:db8:acad:12::1/64 | fe80::1 |
| R2 | Gi0/1 (to R1) | 2001:db8:acad:12::2/64 | fe80::2 |
| R2 | Gi0/0 (server LAN) | 2001:db8:acad:2::1/64 | fe80::2 |
| Server | NIC | 2001:db8:acad:2::10/64 | automatic |
Using the same link-local address (fe80::1) on every interface of R1 is allowed. A link-local address only has to be unique on its own link, and each interface is a different link.
What you configure
IPv6 on a Cisco router comes down to a few commands:
ipv6 unicast-routing(global): turns on IPv6 forwarding. It is off by default, unlike IPv4 routing, which is on.ipv6 address <address>/<length>(interface): a static global unicast address. The prefix length is written with a slash, not as a mask.ipv6 address <prefix>/64 eui-64: you give the first 64 bits, the router makes the interface ID from its MAC address.ipv6 address fe80::1 link-local: sets the link-local address by hand instead of the automatic one.ipv6 address autoconfigoripv6 address dhcp: the interface acts as a client and gets its address with SLAAC or DHCPv6.ipv6 enable: turns IPv6 on with only a link-local address and no global address.
Why it works that way
IPv6 was designed so that every link always has working local addresses. That is why a link-local address appears the moment you enable IPv6 on an interface. Routers use link-local addresses to talk to their neighbours, and hosts use the router's link-local address as their default gateway.
ipv6 unicast-routing is a separate switch because a Cisco device can use IPv6 just as a host (for management, for example) without being a router. Turning it on changes three things: the router forwards IPv6 packets, it joins the all-routers group FF02::2, and it starts sending Router Advertisements (RAs). RAs are the messages that let hosts build their own address with SLAAC (Stateless Address Autoconfiguration).
How it works, step by step
Here is what happens on the LAN after you configure R1's Gi0/0 and a PC is plugged in. All of it uses ICMPv6 Neighbor Discovery (NDP) messages, IPv6's replacement for ARP.
- Address:
- 2001:db8:acad:1:<interface ID>/64
- Default gateway:
- fe80::1 (R1 Gi0/0)
- DNS:
- From the RA (RDNSS) or stateless DHCPv6
How EUI-64 builds an interface ID
With eui-64, and for the automatic link-local address, IOS turns the 48-bit MAC address into a 64-bit interface ID. Take the MAC 001a.2b3c.4d5e:
The seventh bit is the universal/local bit. Flipping it is why a MAC that starts with 00 gives an interface ID that starts with 02. With the prefix 2001:db8:acad:1::/64, the final address is 2001:db8:acad:1:21a:2bff:fe3c:4d5e (the leading zero of 021a is dropped when shortened).
How to configure it on Cisco IOS
⚠️ Commands are based on Cisco IOS / IOS XE documentation and haven't been run on a lab device here. Interface names vary by platform.
ipv6 unicast-routingGlobal configuration. Without it the router will not forward IPv6 packets or send Router Advertisements.
interface GigabitEthernet0/0
ipv6 address 2001:db8:acad:1::1/64
ipv6 address fe80::1 link-local
no shutdownA static global address and a short, readable link-local address. The prefix length uses slash notation.
interface GigabitEthernet0/0
ipv6 address 2001:db8:acad:1::/64 eui-64Alternative: give only the /64 prefix and let the router fill in the interface ID from its MAC.
interface GigabitEthernet0/2
ipv6 address autoconfig defaultClient role, e.g. toward an ISP: build an address with SLAAC from the provider's RA. The 'default' keyword also installs a default route toward the advertising router. Use 'ipv6 address dhcp' to get the address from DHCPv6 instead.
interface GigabitEthernet0/3
ipv6 enableIPv6 with only a link-local address. Useful on router-to-router links when routing protocols run over link-local addresses.
Full configuration for the lab
! R1
ipv6 unicast-routing
!
interface GigabitEthernet0/0
description LAN
ipv6 address 2001:db8:acad:1::1/64
ipv6 address fe80::1 link-local
no shutdown
!
interface GigabitEthernet0/1
description Link to R2
ipv6 address 2001:db8:acad:12::1/64
ipv6 address fe80::1 link-local
no shutdownR1. The IPv4 configuration stays as it was: this is dual stack.
! R2
ipv6 unicast-routing
!
interface GigabitEthernet0/1
description Link to R1
ipv6 address 2001:db8:acad:12::2/64
ipv6 address fe80::2 link-local
no shutdown
!
interface GigabitEthernet0/0
description Server LAN
ipv6 address 2001:db8:acad:2::1/64
ipv6 address fe80::2 link-local
no shutdownR2. Each router now knows its connected IPv6 networks. Routes to the far LANs come in the next lesson.
How to verify it
R1#show ipv6 interface brief GigabitEthernet0/0 [up/up] FE80::1 2001:DB8:ACAD:1::1 GigabitEthernet0/1 [up/up] FE80::1 2001:DB8:ACAD:12::1 GigabitEthernet0/2 [administratively down/down] unassigned
R1#show ipv6 interface GigabitEthernet0/0 GigabitEthernet0/0 is up, line protocol is up IPv6 is enabled, link-local address is FE80::1 No Virtual link-local address(es): Global unicast address(es): 2001:DB8:ACAD:1::1, subnet is 2001:DB8:ACAD:1::/64 Joined group address(es): FF02::1 FF02::2 FF02::1:FF00:1 MTU is 1500 bytes ICMP error messages limited to one every 100 milliseconds ICMP redirects are enabled ICMP unreachables are sent ND DAD is enabled, number of DAD attempts: 1 ND reachable time is 30000 milliseconds (using 30000) ND router advertisements are sent every 200 seconds ND router advertisements live for 1800 seconds ND advertised default router preference is Medium Hosts use stateless autoconfig for addresses.
ipv6 unicast-routing is on. FF02::1:FF00:1 is the solicited-node group for both FE80::1 and 2001:DB8:ACAD:1::1, since they share the same last 24 bits. The last line says hosts on this LAN should use SLAAC.With the EUI-64 version, the address is marked so you can tell:
R1#show ipv6 interface GigabitEthernet0/0 | include subnet 2001:DB8:ACAD:1:21A:2BFF:FE3C:4D5E, subnet is 2001:DB8:ACAD:1::/64 [EUI]
R1#ping 2001:db8:acad:12::2 Type escape sequence to abort. Sending 5, 100-byte ICMP Echos to 2001:DB8:ACAD:12::2, timeout is 2 seconds: !!!!! Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/2 ms
ping works for both versions. ping ipv6 <address> also works.R1#show ipv6 neighbors IPv6 Address Age Link-layer Addr State Interface 2001:DB8:ACAD:12::2 0 001a.2b3c.4d71 REACH Gi0/1 FE80::2 0 001a.2b3c.4d71 REACH Gi0/1
What goes wrong and how to troubleshoot it
| Symptom | Likely cause | Check / fix |
|---|---|---|
| PCs on the LAN only have a FE80 address | No RAs: ipv6 unicast-routing is missing | show ipv6 interface: FF02::2 missing and no "router advertisements are sent" line. Add the global command. |
| The router can ping its neighbours but packets aren't forwarded | Same: the router behaves as a host | show running-config | include unicast-routing |
An address is marked [DUP], log shows %IPV6_ND-4-DUPLICATE | DAD found another device using it | Fix the addressing plan, then shutdown / no shutdown to rerun DAD. |
| Two routers on a link can't ping | Different prefixes or lengths typed on each end | Compare the "subnet is" line on both routers. |
| SLAAC hosts don't get an address | Prefix is not a /64 | SLAAC needs a /64 to fill a 64-bit interface ID. Use /64 on LANs. |
Common mistakes
- Forgetting
ipv6 unicast-routing. Everything looks configured, but nothing is routed and hosts get no RAs. - Typing a mask, as in IPv4. IPv6 uses only the
/lengthform. - Using
eui-64with a full address. Give only the prefix (2001:db8:acad:1::/64 eui-64); the router supplies the last 64 bits. - Expecting a new
ipv6 addressto replace the old one. It is added. Remove the old one withno ipv6 address <address>/<length>. - Giving a host the router's global address as its gateway and wondering why the routing table shows a FE80 gateway. Hosts using SLAAC always learn the link-local address. Both work.
Exam tip: expect to work out an EUI-64 address from a MAC (insert FFFE, flip the seventh bit), to pick the command that enables IPv6 routing, and to read show ipv6 interface: which groups were joined, which address is link-local, and whether the address came from EUI-64. Know that ipv6 address autoconfig means SLAAC and ipv6 address dhcp means DHCPv6.
Key takeaways
ipv6 unicast-routingis off by default. It enables forwarding and RAs.- Every IPv6 interface has a link-local address, created automatically or set with
link-local. - EUI-64 builds the interface ID from the MAC: FFFE in the middle, seventh bit flipped.
- Extra
ipv6 addresscommands add addresses; they don't replace them. - Verify with
show ipv6 interface brief,show ipv6 interfaceandshow ipv6 neighbors.
Check yourself
R1's LAN interface has ipv6 address 2001:db8:acad:1::1/64, but PCs on the LAN only get FE80 addresses. What is most likely missing?
An interface with MAC 0200.1111.2222 is configured with ipv6 address 2001:db8:1:1::/64 eui-64. Which interface ID does it get?
show ipv6 interface lists FF02::1 but not FF02::2. What does that tell you?
You want an interface to have IPv6 with only a link-local address and no global address. Which command?
You configure ipv6 address 2001:db8:acad:1::5/64 on an interface that already has 2001:db8:acad:1::1/64. What happens?