A real-life situation
In Configuring IPv6 addresses on IOS you gave R1 and R2 their IPv6 addresses. Each router can ping its neighbour. But PC1 still can't reach the server on 2001:db8:acad:2::/64. R1 only knows its own connected networks. Just as in IPv4, someone has to tell it where the far LAN is. In a small network, static routes are the quickest answer.
What an IPv6 static route is
An IPv6 static route is a route you type by hand into the IPv6 routing table. It works exactly like an IPv4 static route (see Configuring static routes), with three differences in how you write it:
- The command is
ipv6 routeinstead ofip route. - The destination is written with a prefix length (
/64), never a mask. - A link-local next hop must be paired with the exit interface.
ipv6 route <prefix>/<length> {<next-hop> | <exit-interface> [<next-hop>]} [<AD>]Global configuration mode. The optional number at the end is the administrative distance (default 1).
The four kinds you need to know
| Kind | Destination | Example on R1 |
|---|---|---|
| Network route | A whole prefix | ipv6 route 2001:db8:acad:2::/64 2001:db8:acad:12::2 |
| Host route | One address (/128) | ipv6 route 2001:db8:acad:2::10/128 2001:db8:acad:12::2 |
| Default route | Everything (::/0) | ipv6 route ::/0 2001:db8:acad:12::2 |
| Floating route | A backup with a higher AD | ipv6 route ::/0 2001:db8:acad:21::2 5 |
Why a link-local next hop needs an exit interface
On Ethernet, routers often use the neighbour's link-local address as the next hop. Routing protocols such as OSPFv3 do exactly this. The problem: link-local addresses are only unique on one link. R2 could be fe80::2 on Gi0/1 and on Gi0/2. Even the fe80::/10 range is "connected" on every interface, so R1 has no way to look it up in the routing table and pick a link.
So IOS refuses a static route with only a link-local next hop. You give both: the interface says which link, and the link-local address says which neighbour on that link.
ipv6 route 2001:db8:acad:2::/64 GigabitEthernet0/1 fe80::2A fully specified route: out Gi0/1, to the neighbour fe80::2. This is the required form for a link-local next hop.
A global next hop such as 2001:db8:acad:12::2 doesn't need the interface. The router finds it with a recursive lookup: which connected prefix contains 2001:db8:acad:12::2? Gi0/1's. An exit interface on its own is fine on a point-to-point serial link, but avoid it on Ethernet: the router would have to run Neighbor Discovery for every destination as if it were on the link.
How it works, step by step
- 1. PC1 sends to its gateway. The destination is off-link, so PC1 sends the packet to fe80::1, the gateway it learned from R1's RA.
- 2. R1 needs a route. Longest match in R1's IPv6 table: 2001:db8:acad:2::/64 via 2001:db8:acad:12::2 (or ::/0). It resolves R2's MAC with Neighbor Discovery and forwards.
- 3. R2 delivers it. 2001:db8:acad:2::/64 is connected on R2's Gi0/0.
- 4. The reply needs a route too. R2 must know 2001:db8:acad:1::/64 points back to R1, or the reply is dropped. Routes are needed in both directions.
- 5. If Gi0/1 fails… The primary route is removed and the floating route through the backup link (Gi0/2, 2001:db8:acad:21::/64) is installed.
For each packet, the router does the same steps as for IPv4: find the longest matching prefix, find the next hop's MAC (with Neighbor Discovery instead of ARP), rewrite the Ethernet header, decrease the Hop Limit by one (IPv6's TTL), and send the packet out.
How to configure it on Cisco IOS
⚠️ Commands are based on Cisco IOS / IOS XE documentation and haven't been run on a lab device here. Make sure ipv6 unicast-routing is on, or the router won't forward anything.
! R1: reach the server LAN through R2
ipv6 route 2001:db8:acad:2::/64 2001:db8:acad:12::2A network route with a global next hop.
! R2: the return route to PC1's LAN
ipv6 route 2001:db8:acad:1::/64 GigabitEthernet0/1 fe80::1A fully specified route with R1's link-local address as the next hop.
R1 is an edge router: everything it doesn't know lives behind R2. A default route is simpler than listing every prefix, and a floating default over the backup link keeps PC1 online if Gi0/1 fails:
! R1: complete IPv6 routing configuration
ipv6 unicast-routing
!
interface GigabitEthernet0/2
description Backup link to R2
ipv6 address 2001:db8:acad:21::1/64
no shutdown
!
ipv6 route ::/0 2001:db8:acad:12::2
ipv6 route ::/0 2001:db8:acad:21::2 5
ipv6 route 2001:db8:acad:2::10/128 2001:db8:acad:12::2Primary default (AD 1), floating default over the backup link (AD 5), and a host route that pins the server to the primary link.
! R2
ipv6 route 2001:db8:acad:1::/64 GigabitEthernet0/1 fe80::1
ipv6 route 2001:db8:acad:1::/64 GigabitEthernet0/2 fe80::1 5R2's return route, with its own floating backup over Gi0/2.
The floating route only works if a failure actually removes the primary route. That happens when Gi0/1 goes down on R1. If the link stays up but R2 stops answering (a switch in the middle, for example), the static route stays and traffic is lost. The Floating static routes lesson explains this limit in detail.
How to verify it
R1#show ipv6 route IPv6 Routing Table - default - 9 entries Codes: C - Connected, L - Local, S - Static, U - Per-user Static route B - BGP, R - RIP, H - NHRP, I1 - ISIS L1 I2 - ISIS L2, IA - ISIS interarea, IS - ISIS summary, D - EIGRP EX - EIGRP external, ND - ND Default, NDp - ND Prefix O - OSPF Intra, OI - OSPF Inter, OE1 - OSPF ext 1, OE2 - OSPF ext 2 S ::/0 [1/0] via 2001:DB8:ACAD:12::2 C 2001:DB8:ACAD:1::/64 [0/0] via GigabitEthernet0/0, directly connected L 2001:DB8:ACAD:1::1/128 [0/0] via GigabitEthernet0/0, receive S 2001:DB8:ACAD:2::10/128 [1/0] via 2001:DB8:ACAD:12::2 C 2001:DB8:ACAD:12::/64 [0/0] via GigabitEthernet0/1, directly connected L 2001:DB8:ACAD:12::1/128 [0/0] via GigabitEthernet0/1, receive C 2001:DB8:ACAD:21::/64 [0/0] via GigabitEthernet0/2, directly connected L 2001:DB8:ACAD:21::1/128 [0/0] via GigabitEthernet0/2, receive L FF00::/8 [0/0] via Null0, receive
R2#show ipv6 route static IPv6 Routing Table - default - 8 entries Codes: C - Connected, L - Local, S - Static, U - Per-user Static route ... S 2001:DB8:ACAD:1::/64 [1/0] via FE80::1, GigabitEthernet0/1
After shutting down R1's Gi0/1 to test the backup:
R1#show ipv6 route static IPv6 Routing Table - default - 6 entries Codes: C - Connected, L - Local, S - Static, U - Per-user Static route ... S ::/0 [5/0] via 2001:DB8:ACAD:21::2
R1#ping 2001:db8:acad:2::10 source GigabitEthernet0/0 Type escape sequence to abort. Sending 5, 100-byte ICMP Echos to 2001:DB8:ACAD:2::10, timeout is 2 seconds: Packet sent with a source address of 2001:DB8:ACAD:1::1 !!!!! Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/2 ms
traceroute 2001:db8:acad:2::10 shows each hop if the ping fails.What goes wrong and how to troubleshoot it
- The route is in the config but not in the table. The next hop isn't reachable: its interface is down, or the global next hop isn't in any connected prefix. Check
show ipv6 interface brief. - Ping works from R1 but not from PC1. A missing return route on R2 for
2001:db8:acad:1::/64. Test withping … source GigabitEthernet0/0. - Nothing is forwarded at all.
ipv6 unicast-routingis missing on one of the routers. - Wrong next hop. A typing error in a long address (for example
2001:db8:acad:21::2instead of…:12::2). Compare the route withshow ipv6 neighborson the link. - The backup never takes over. The primary's interface stays up even though the path is broken, so the primary route is never removed.
Common mistakes
- Writing
ipv6 route 2001:db8:acad:2::/64 fe80::2without the exit interface. - Using
ip routefor an IPv6 prefix, or a mask instead of a prefix length. - Giving the floating route a lower AD than the primary, so it becomes the primary.
- Adding routes in one direction only.
- Writing the default route as
::/128(the unspecified address) instead of::/0.
Exam tip: the exam gives you a topology and four or five ipv6 route commands and asks which one is correct, or shows a show ipv6 route output and asks where a packet goes. Watch for: a link-local next hop without an interface (invalid), a missing ipv6 unicast-routing, a default route written as ::/0, and floating routes with the AD at the end. Remember that the longest prefix wins before AD is considered.
Key takeaways
ipv6 route prefix/length next-hop [AD]. No masks.- A link-local next hop needs the exit interface too (fully specified route).
- The IPv6 default route is
::/0; a host route is/128. - A floating route has a higher AD and appears only when the primary is removed.
- IPv4 and IPv6 routing tables are separate: dual stack needs both sets of routes.
Check yourself
Which of these IPv6 static routes is valid on a router whose neighbour on Gi0/1 is fe80::2?
R1 has ipv6 route ::/0 2001:db8:acad:12::2 and ipv6 route ::/0 2001:db8:acad:21::2 5. Both links are up. Which route is in the routing table?
R1 has routes for 2001:db8:acad:2::/64 via R2 and ::/0 via an ISP. A packet goes to 2001:db8:acad:2::10. Where does it go?
PC1 can't reach the server, but a ping from R1 to the server (default source) works. What is the likely cause?
Which command configures an IPv6 host route to 2001:db8:acad:2::10?