Routelearn.net
Course menu

Unit 5: IP Addressing BasicsLesson 5.6 (6 of 6 in this unit)30 of 84 in the Network Fundamentals course

IPv6 Address Types and Autoconfiguration

An IPv6 device usually has several addresses at the same time, each with a different job. This lesson explains the address types you will see, how a device gets its address with SLAAC or DHCPv6, how Neighbor Discovery replaces ARP, and how to check IPv6 settings on Windows and Linux.

Beginner · 17 min read · Before this: IPv6 addressing basics, ARP fundamentals

IPv6 address types are the kinds of IPv6 address, told apart by their scope and how packets sent to them are delivered: global unicast, link-local, unique local, multicast and anycast. An interface normally holds several at the same time, for example a link-local address plus one or more global unicast addresses.

In simple terms: An IPv6 device usually has more than one address, each for a different job. One works only on the local link, another reaches the whole internet, and special ones reach groups of devices.

One interface, many addresses

In IPv4, a network card usually has one address. In IPv6, it is normal for one interface to have three or more: one that only works on the local link, one or two that work across the whole internet, and perhaps an internal one. Each type is recognised by its first few bits, called its prefix. If the format of IPv6 addresses is still new to you, read IPv6 addressing basics first.

💡 In simple terms: a person at work might have a desk extension (works only inside the office: link-local), a mobile number (works worldwide: global unicast) and membership of a few email lists (multicast groups). Different addresses for different jobs.

The address types

Global unicast

2000::/3 · e.g. 2001:db8:abcd:10::25

The public, internet-routable address of one interface. Today, all of them start with 2 or 3. It is the IPv6 equivalent of a public IPv4 address.

Link-local

fe80::/10 · e.g. fe80::1

Works only on the local link (one LAN or VLAN); routers never forward it. Every IPv6 interface creates one automatically.

Unique local

fc00::/7 (fd00::/8 in practice) · e.g. fd12:3456:789a:1::25

For internal use only, like the IPv4 private ranges, and not routed on the internet. You pick a random 40-bit ID after fd, so two companies are unlikely to choose the same prefix.

Loopback

::1/128 · e.g. ::1

Means “this device”, like 127.0.0.1. Packets to ::1 never leave the computer.

Unspecified

::/128 · e.g. ::

All zeros, meaning “I have no address yet”. Used as the source address by a device that is still setting itself up. Never used as a destination.

Multicast

ff00::/8 · e.g. ff02::1

One-to-many: a packet sent to a group address reaches every device that has joined that group. Multicast replaces broadcast.

Global unicast: 2000::/3

Unicast means one-to-one: the address belongs to exactly one interface. A global unicast address (GUA) is unique on the whole internet and can be routed anywhere. The prefix 2000::/3 means the first 3 bits are 001, so every one starts with the hex digit 2 or 3. Your provider gives you a prefix (for example, a /48 or /56), and your router uses /64s from it for each LAN. The examples in this lesson use 2001:db8::/32, which is reserved for documentation.

Link-local: fe80::/10

A link-local address only works on one link, meaning one LAN segment or VLAN. Routers never forward packets with a link-local source or destination to another network. Every interface that runs IPv6 creates one by itself as soon as it comes up, even if there is no router and no DHCP server. In practice, they always look like fe80:: followed by a 64-bit interface ID.

Link-local addresses do important work:

  • Devices use them to talk to neighbours on the same LAN, for example during Neighbor Discovery.
  • Routers send their Router Advertisements from their link-local address, so hosts usually see the default gateway as something like fe80::1.
  • Routing protocols use them to exchange information between neighbouring routers.

Because every interface on every LAN uses the same fe80::/64 range, a computer with two network cards cannot tell which one to use to reach fe80::1. So you add a zone ID: fe80::1%eth0 on Linux or fe80::1%12 on Windows, where the part after % names the interface.

Unique local: fc00::/7

Unique local addresses (ULA) are for internal use, like the private IPv4 ranges. They are not routed on the internet. The block is fc00::/7, but only the fd00::/8 half is used in practice. After fd, you add a random 40-bit number, which gives you your own /48, for example fd12:3456:789a::/48. The random part makes it unlikely that two companies pick the same prefix, which matters if they ever merge or connect over a VPN.

Many networks never use ULA. IPv6 has enough global addresses for everything, so ULA is mostly used for devices that should never reach the internet, or for labs.

Loopback ::1 and unspecified ::

::1 is the loopback address: the device itself, exactly like 127.0.0.1 in IPv4. Only this one address is loopback in IPv6 (not a whole /8). :: (all zeros) is the unspecified address. A device uses it as its source address while it has no address yet, for example when it checks whether its new address is already taken.

Multicast: ff00::/8

Multicast means one-to-many: a packet goes to a group address, and every device that has joined the group receives it. Devices that have not joined simply ignore it, often in the network card itself. All multicast addresses start with ff. The 02 in ff02:: means “link-local scope”: the packet stays on this LAN.

AddressGroupWhat it is used for
ff02::1All nodesEvery IPv6 device on the link listens. This is the nearest thing to a broadcast; routers send their Router Advertisements here.
ff02::2All routersOnly routers listen. A new device sends Router Solicitations here.
ff02::1:2All DHCPv6 servers and relaysA client looking for a DHCPv6 server sends its request here.
ff02::1:ffXX:XXXXSolicited-nodeBuilt from the last 24 bits of a unicast address. Used to find a neighbour's MAC address without disturbing every device.

The solicited-node address

Every unicast address automatically joins one extra group: its solicited-node multicast address. To build it, take ff02::1:ff and add the last 24 bits (the last 6 hex digits) of the unicast address.

Start with the unicast address
2001:db8:abcd:10::25 = 2001:0db8:abcd:0010:0000:0000:0000:0025
Take the last 24 bits (6 hex digits)
00:0025
Put them after ff02::1:ff
ff02:0000:0000:0000:0000:0001:ff00:0025
Shorten
ff02::1:ff00:25
Only the few devices whose addresses end in the same 24 bits share this group, so a lookup sent here disturbs almost no other device.

Anycast

Anycast means one-to-nearest. The same unicast address is given to several devices in different places, and routing delivers each packet to the nearest one. There is no special anycast prefix: it is just a normal unicast address used on more than one device. Large public DNS services use anycast so that you reach a nearby server wherever you are.

And no broadcast

IPv6 has no broadcast address. Jobs that needed a broadcast in IPv4, such as ARP and DHCP discovery, use multicast groups instead. When a message really must reach every device on the link, it goes to ff02::1.

How a device gets its IPv6 address

In IPv4, a device usually asks a DHCP server for its address. IPv6 has three common methods. The router decides which one is used, through flags in its Router Advertisement (RA). An RA is a message in which a router says “I am a router, and here is the prefix for this LAN”.

MethodAddress comes fromDNS servers come fromGateway comes from
SLAACThe device builds it (prefix from RA + own interface ID)The RA (or nothing)RA
SLAAC + stateless DHCPv6The device builds itDHCPv6 serverRA
Stateful DHCPv6DHCPv6 server assigns itDHCPv6 serverRA

Notice the last column. In IPv6, the default gateway always comes from Router Advertisements, never from DHCPv6.

SLAAC: building your own address

SLAAC (Stateless Address Autoconfiguration) lets a device create its own global address without a server. “Stateless” means no server keeps a list of which device has which address. It works because a LAN is normally a /64 (SLAAC needs a /64): the router supplies the first 64 bits, and the device fills in the last 64 bits itself.

Make a link-local address
fe80:: + an interface ID the device picks.
Check that no other device has it (DAD)
Duplicate Address Detection: ask “is anyone using this?”; no answer means it is free.
Look for routers: Router Solicitation
Sent to ff02::2 (all routers).
A router answers: Router Advertisement
Prefix 2001:db8:abcd:10::/64, use SLAAC, and use me as your gateway.
Build the global address
Prefix (64 bits) + interface ID (64 bits). Check it with DAD, then start using it.
SLAAC, from power-on to a working global address. Routers also send RAs every few minutes without being asked.

Where the interface ID comes from: EUI-64 or random

EUI-64 is the original method. It builds the 64-bit interface ID from the 48-bit MAC address of the network card:

MAC address
00:00:5e:00:53:2a
Split it in half and insert ff:fe in the middle
00:00:5e | ff:fe | 00:53:2a → 0000:5eff:fe00:532a
Flip the 7th bit of the first byte
00 = 0000 0000 → 0000 0010 = 02 → 0200:5eff:fe00:532a
Add the prefix
2001:db8:abcd:10:200:5eff:fe00:532a
EUI-64. The ff:fe in the middle shows that an address was built from a MAC address.

The problem is that the MAC address usually stays the same, so the last half of the IPv6 address would be the same on every network you join. Websites could then track a laptop from home to café to office. So modern systems use random interface IDs instead:

  • A stable random ID: it looks random, but stays the same on one network. Used for incoming connections.
  • A temporary (privacy) address: a new random ID about once a day. Used for outgoing connections, such as web browsing.

Windows, macOS, iOS and Android use random IDs by default. EUI-64 is still common on routers and some Linux setups.

DHCPv6: stateful and stateless

DHCPv6 is DHCP for IPv6. It uses UDP ports 546 (client) and 547 (server), and clients find servers by sending to ff02::1:2.

  • Stateful DHCPv6: the server picks the address and keeps a record of it, just like DHCP for IPv4. Companies use it when they want a record of which device had which address. Some devices, notably Android phones, do not support it and only use SLAAC.
  • Stateless DHCPv6: the device builds its address with SLAAC and only asks DHCPv6 for extra settings, such as DNS servers and a domain name.

Neighbor Discovery: how IPv6 replaces ARP

In IPv4, a device that knows an IP address but needs the matching MAC address uses ARP, which broadcasts the question to every device. IPv6 replaces ARP, router discovery and more with the Neighbor Discovery Protocol (NDP). NDP messages are ICMP messages for IPv6 (ICMPv6). There are four that you need to know:

MessageShortSent toMeaning
Router SolicitationRSff02::2“Are there any routers here?”
Router AdvertisementRAff02::1 (or the asker)“I am a router. Here is the prefix and how to get an address.”
Neighbor SolicitationNSSolicited-node multicast“Who has this IPv6 address? What is your MAC address?” (like an ARP request)
Neighbor AdvertisementNAUsually unicast to the asker“That is me. Here is my MAC address.” (like an ARP reply)

Here is a laptop joining a LAN, getting its address and then finding the MAC address of a printer on the same LAN. Tap a message to see its addresses.

Step 1 of 4 · Router Solicitation (RS)
LAN 2001:db8:abcd:10::/64 · one VLAN, no broadcast
Laptop
MAC 00:00:5e:00:53:2a
Router
fe80::1
Printer
2001:db8:abcd:10::30
What the laptop now knows
Global address:
2001:db8:abcd:10:200:5eff:fe00:532a/64
Default gateway:
fe80::1
Neighbour cache:
2001:db8:abcd:10::30 → 00:00:5e:00:53:30
Neighbor Discovery: RS and RA find the router and prefix; NS and NA find a neighbour's MAC address. No broadcast is used.

Duplicate Address Detection (DAD) uses the same NS message. Before using a new address, the device sends an NS for its own address, with :: as the source. If anyone answers with an NA, the address is already taken and the device must not use it.

Seeing IPv6 settings on Windows

Example output from a Windows PC, shortened and written for this lesson
C:\> ipconfig
Ethernet adapter Ethernet:

   Connection-specific DNS Suffix  . : home.arpa
   IPv6 Address. . . . . . . . . . . : 2001:db8:abcd:10:4c1f:a2e9:7b30:d815
   Temporary IPv6 Address. . . . . . : 2001:db8:abcd:10:91d2:6e04:3a7c:b2f8
   Link-local IPv6 Address . . . . . : fe80::4c1f:a2e9:7b30:d815%12
   IPv4 Address. . . . . . . . . . . : 192.168.10.25
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Default Gateway . . . . . . . . . : fe80::1%12
                                       192.168.10.1
What to look for: three IPv6 addresses. IPv6 Address is the stable global address (random ID, not EUI-64), Temporary IPv6 Address is the privacy address used for browsing, and Link-local IPv6 Address starts with fe80::. The IPv6 Default Gateway is the router's link-local address, and %12 is the interface number (zone ID).

ipconfig /all also shows DHCPv6 details and the DNS servers. To see the neighbour cache (the IPv6 version of the ARP table), use netsh interface ipv6 show neighbors.

Seeing IPv6 settings on Linux

Example output from a Linux PC, shortened and written for this lesson
$ ip -6 addr
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 state UNKNOWN qlen 1000
    inet6 ::1/128 scope host
       valid_lft forever preferred_lft forever
2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 state UP qlen 1000
    inet6 2001:db8:abcd:10:8d3e:41a2:9f07:c3b1/64 scope global temporary dynamic
       valid_lft 86321sec preferred_lft 14321sec
    inet6 2001:db8:abcd:10:200:5eff:fe00:532a/64 scope global dynamic mngtmpaddr
       valid_lft 86321sec preferred_lft 14321sec
    inet6 fe80::200:5eff:fe00:532a/64 scope link
       valid_lft forever preferred_lft forever
What to look for: scope host is loopback, scope link is link-local and scope global is global unicast. This machine uses EUI-64 (notice the ff:fe) plus a temporary privacy address. dynamic means the address was learned from an RA and has a limited lifetime (valid_lft).
Example output from a Linux PC, written for this lesson
$ ip -6 route
::1 dev lo proto kernel metric 256 pref medium
2001:db8:abcd:10::/64 dev eth0 proto ra metric 100 pref medium
fe80::/64 dev eth0 proto kernel metric 256 pref medium
default via fe80::1 dev eth0 proto ra metric 100 pref medium
What to look for: proto ra means the route came from a Router Advertisement. The default via line shows the default gateway: the router's link-local address, fe80::1.
Example output from a Linux PC, written for this lesson
$ ip -6 neigh
fe80::1 dev eth0 lladdr 00:00:5e:00:53:01 router REACHABLE
2001:db8:abcd:10::30 dev eth0 lladdr 00:00:5e:00:53:30 STALE
What to look for: this is the neighbour cache, filled by Neighbor Discovery. lladdr is the neighbour's MAC address, and router marks the gateway. STALE only means the entry has not been confirmed recently; it is checked again the next time it is used.

Testing with ping

Ping the loopback address first. If ::1 answers, IPv6 is working inside the computer itself:

Example output from a Windows PC, written for this lesson
C:\> ping ::1
Pinging ::1 with 32 bytes of data:
Reply from ::1: time<1ms
Reply from ::1: time<1ms
Reply from ::1: time<1ms
Reply from ::1: time<1ms
What to look for: four Reply from ::1 lines. The replies never leave the computer, so this only proves that the IPv6 software is working, not the network.

Then use ping -6 to force IPv6 when you ping a name or a remote host. On Linux, a link-local target needs the zone ID:

Example output from a Linux PC, written for this lesson
$ ping -6 -c 3 fe80::1%eth0
PING fe80::1%eth0(fe80::1%eth0) 56 data bytes
64 bytes from fe80::1%eth0: icmp_seq=1 ttl=64 time=0.41 ms
64 bytes from fe80::1%eth0: icmp_seq=2 ttl=64 time=0.38 ms
64 bytes from fe80::1%eth0: icmp_seq=3 ttl=64 time=0.40 ms

--- fe80::1%eth0 ping statistics ---
3 packets transmitted, 3 received, 0% packet loss, time 2003ms
What to look for: three replies and 0% packet loss mean the gateway answers on the local link. Next, try ping -6 www.example.com to test the path to the internet over IPv6. The same command works on Windows.

When it goes wrong

SymptomLikely causeWhat to check
Only an fe80:: address, no global oneNo Router Advertisements reach the device (the router isn't configured for IPv6, or RAs are blocked)ip -6 route: is there a default route with proto ra?
Global address but no IPv6 internetThe provider link has no IPv6, or a firewall drops IPv6 trafficping -6 the gateway, then a public IPv6 host
Address marked “duplicate” (Windows) or dadfailed (Linux)Another device already uses that addressLook for a static address typed on two devices; find the other device in the neighbour cache
Android phones get no IPv6 address, but laptops doThe network uses only stateful DHCPv6Enable SLAAC on the router as well
Devices get addresses from a strange prefixA rogue device is sending Router AdvertisementsCheck the gateway in ip -6 route; switches can block rogue RAs with RA Guard
IPv6 neighbours unreachable after a firewall changeAll ICMPv6 is blocked, which breaks Neighbor DiscoveryAllow ICMPv6 NDP messages (types 133–136)

Common mistakes

  • Blocking all ICMPv6 “for security”. IPv6 cannot find neighbours or routers without it.
  • Expecting DHCPv6 to give the default gateway. The gateway always comes from Router Advertisements.
  • Thinking an fe80:: address means DHCP failed. It is not like a 169.254.x.x address in IPv4: every IPv6 interface always has one. There is only a problem when it is the only IPv6 address.
  • Forgetting the zone ID when pinging a link-local address on Linux. Without %eth0, the computer doesn't know which interface to use.
  • Treating ULA as required. Unlike IPv4 networks, IPv6 networks normally use global addresses internally and need no NAT.
  • Looking for an IPv6 broadcast address. There is none; IPv6 uses multicast, such as ff02::1, instead.
✅ Key takeaways
  • An IPv6 interface normally has several addresses: link-local, global and often a temporary one.
  • Global unicast is 2000::/3; link-local is fe80::/10; unique local is fc00::/7 (fd00::/8 in practice); loopback is ::1; unspecified is ::.
  • Multicast (ff00::/8) replaces broadcast: ff02::1 is all nodes, ff02::2 is all routers and ff02::1:ffXX:XXXX is solicited-node.
  • Anycast is one address on several devices; the nearest one receives the packet.
  • SLAAC builds an address from the RA's /64 prefix plus an interface ID (EUI-64 or random).
  • DHCPv6 can be stateful (assigns addresses) or stateless (only extra settings). The gateway always comes from RAs.
  • Neighbor Discovery (RS, RA, NS, NA, all ICMPv6) replaces ARP.
  • Check settings with ipconfig on Windows and ip -6 addr, route and neigh on Linux; test with ping ::1 and ping -6.

Check yourself

Predict · scenario 1

You run ipconfig and see these four IPv6 addresses. Which one is a link-local address?

Predict · scenario 2

A laptop runs ip -6 route and sees: default via fe80::1 dev eth0 proto ra. Where did it learn this gateway?

Predict · scenario 3

A laptop needs the MAC address of 2001:db8:abcd:10::4:2b7c. To which solicited-node multicast address does it send the Neighbor Solicitation?

Predict · scenario 4

A device's interface ID is 0200:5eff:fe00:532a. How was it most likely created?

Predict · scenario 5

A firewall administrator blocks all ICMPv6. What breaks on the LAN?

To plan IPv6 subnets, split a /48 into /64s with the IPv6 Subnet Calculator. To review the address format and shortening rules, go back to the previous lesson.

Learn more: IPv6 Addressing Basics

FAQ

Why does my computer have so many IPv6 addresses?
That is normal. Each interface has a link-local address (fe80::), usually one or more global addresses built from the router's prefix, and often a temporary privacy address that changes about once a day. Each address has its own job.
Does IPv6 use ARP?
No. IPv6 uses Neighbor Discovery, which is part of ICMPv6. A Neighbor Solicitation asks for a MAC address, and a Neighbor Advertisement answers. The question is sent to a solicited-node multicast address instead of a broadcast.
Why is my IPv6 default gateway an fe80:: address?
Routers send Router Advertisements from their link-local address, so hosts learn that fe80:: address as their default gateway. This is normal, and the address stays the same even if the global prefix changes.
Can DHCPv6 give me a default gateway?
No. In IPv6, the default gateway always comes from Router Advertisements. DHCPv6 can hand out addresses and settings such as DNS servers, but not the gateway.
Is a unique local address (fd00::/8) the same as a private IPv4 address?
It plays a similar role: it is for internal use only and is not routed on the internet. The difference is that IPv6 networks normally also have global addresses, so devices do not need NAT to reach the internet.