One interface, many addresses
In IPv4, a network card usually has one address. In IPv6, it is normal for one interface to have three or more: one that only works on the local link, one or two that work across the whole internet, and perhaps an internal one. Each type is recognised by its first few bits, called its prefix. If the format of IPv6 addresses is still new to you, read IPv6 addressing basics first.
💡 In simple terms: a person at work might have a desk extension (works only inside the office: link-local), a mobile number (works worldwide: global unicast) and membership of a few email lists (multicast groups). Different addresses for different jobs.
The address types
Global unicast
2000::/3 · e.g. 2001:db8:abcd:10::25
The public, internet-routable address of one interface. Today, all of them start with 2 or 3. It is the IPv6 equivalent of a public IPv4 address.
Link-local
fe80::/10 · e.g. fe80::1
Works only on the local link (one LAN or VLAN); routers never forward it. Every IPv6 interface creates one automatically.
Unique local
fc00::/7 (fd00::/8 in practice) · e.g. fd12:3456:789a:1::25
For internal use only, like the IPv4 private ranges, and not routed on the internet. You pick a random 40-bit ID after fd, so two companies are unlikely to choose the same prefix.
Loopback
::1/128 · e.g. ::1
Means “this device”, like 127.0.0.1. Packets to ::1 never leave the computer.
Unspecified
::/128 · e.g. ::
All zeros, meaning “I have no address yet”. Used as the source address by a device that is still setting itself up. Never used as a destination.
Multicast
ff00::/8 · e.g. ff02::1
One-to-many: a packet sent to a group address reaches every device that has joined that group. Multicast replaces broadcast.
Global unicast: 2000::/3
Unicast means one-to-one: the address belongs to exactly one interface. A global unicast address (GUA) is unique on the whole internet and can be routed anywhere. The prefix 2000::/3 means the first 3 bits are 001, so every one starts with the hex digit 2 or 3. Your provider gives you a prefix (for example, a /48 or /56), and your router uses /64s from it for each LAN. The examples in this lesson use 2001:db8::/32, which is reserved for documentation.
Link-local: fe80::/10
A link-local address only works on one link, meaning one LAN segment or VLAN. Routers never forward packets with a link-local source or destination to another network. Every interface that runs IPv6 creates one by itself as soon as it comes up, even if there is no router and no DHCP server. In practice, they always look like fe80:: followed by a 64-bit interface ID.
Link-local addresses do important work:
- Devices use them to talk to neighbours on the same LAN, for example during Neighbor Discovery.
- Routers send their Router Advertisements from their link-local address, so hosts usually see the default gateway as something like
fe80::1. - Routing protocols use them to exchange information between neighbouring routers.
Because every interface on every LAN uses the same fe80::/64 range, a computer with two network cards cannot tell which one to use to reach fe80::1. So you add a zone ID: fe80::1%eth0 on Linux or fe80::1%12 on Windows, where the part after % names the interface.
Unique local: fc00::/7
Unique local addresses (ULA) are for internal use, like the private IPv4 ranges. They are not routed on the internet. The block is fc00::/7, but only the fd00::/8 half is used in practice. After fd, you add a random 40-bit number, which gives you your own /48, for example fd12:3456:789a::/48. The random part makes it unlikely that two companies pick the same prefix, which matters if they ever merge or connect over a VPN.
Many networks never use ULA. IPv6 has enough global addresses for everything, so ULA is mostly used for devices that should never reach the internet, or for labs.
Loopback ::1 and unspecified ::
::1 is the loopback address: the device itself, exactly like 127.0.0.1 in IPv4. Only this one address is loopback in IPv6 (not a whole /8). :: (all zeros) is the unspecified address. A device uses it as its source address while it has no address yet, for example when it checks whether its new address is already taken.
Multicast: ff00::/8
Multicast means one-to-many: a packet goes to a group address, and every device that has joined the group receives it. Devices that have not joined simply ignore it, often in the network card itself. All multicast addresses start with ff. The 02 in ff02:: means “link-local scope”: the packet stays on this LAN.
| Address | Group | What it is used for |
|---|---|---|
ff02::1 | All nodes | Every IPv6 device on the link listens. This is the nearest thing to a broadcast; routers send their Router Advertisements here. |
ff02::2 | All routers | Only routers listen. A new device sends Router Solicitations here. |
ff02::1:2 | All DHCPv6 servers and relays | A client looking for a DHCPv6 server sends its request here. |
ff02::1:ffXX:XXXX | Solicited-node | Built from the last 24 bits of a unicast address. Used to find a neighbour's MAC address without disturbing every device. |
The solicited-node address
Every unicast address automatically joins one extra group: its solicited-node multicast address. To build it, take ff02::1:ff and add the last 24 bits (the last 6 hex digits) of the unicast address.
Anycast
Anycast means one-to-nearest. The same unicast address is given to several devices in different places, and routing delivers each packet to the nearest one. There is no special anycast prefix: it is just a normal unicast address used on more than one device. Large public DNS services use anycast so that you reach a nearby server wherever you are.
And no broadcast
IPv6 has no broadcast address. Jobs that needed a broadcast in IPv4, such as ARP and DHCP discovery, use multicast groups instead. When a message really must reach every device on the link, it goes to ff02::1.
How a device gets its IPv6 address
In IPv4, a device usually asks a DHCP server for its address. IPv6 has three common methods. The router decides which one is used, through flags in its Router Advertisement (RA). An RA is a message in which a router says “I am a router, and here is the prefix for this LAN”.
| Method | Address comes from | DNS servers come from | Gateway comes from |
|---|---|---|---|
| SLAAC | The device builds it (prefix from RA + own interface ID) | The RA (or nothing) | RA |
| SLAAC + stateless DHCPv6 | The device builds it | DHCPv6 server | RA |
| Stateful DHCPv6 | DHCPv6 server assigns it | DHCPv6 server | RA |
Notice the last column. In IPv6, the default gateway always comes from Router Advertisements, never from DHCPv6.
SLAAC: building your own address
SLAAC (Stateless Address Autoconfiguration) lets a device create its own global address without a server. “Stateless” means no server keeps a list of which device has which address. It works because a LAN is normally a /64 (SLAAC needs a /64): the router supplies the first 64 bits, and the device fills in the last 64 bits itself.
Where the interface ID comes from: EUI-64 or random
EUI-64 is the original method. It builds the 64-bit interface ID from the 48-bit MAC address of the network card:
The problem is that the MAC address usually stays the same, so the last half of the IPv6 address would be the same on every network you join. Websites could then track a laptop from home to café to office. So modern systems use random interface IDs instead:
- A stable random ID: it looks random, but stays the same on one network. Used for incoming connections.
- A temporary (privacy) address: a new random ID about once a day. Used for outgoing connections, such as web browsing.
Windows, macOS, iOS and Android use random IDs by default. EUI-64 is still common on routers and some Linux setups.
DHCPv6: stateful and stateless
DHCPv6 is DHCP for IPv6. It uses UDP ports 546 (client) and 547 (server), and clients find servers by sending to ff02::1:2.
- Stateful DHCPv6: the server picks the address and keeps a record of it, just like DHCP for IPv4. Companies use it when they want a record of which device had which address. Some devices, notably Android phones, do not support it and only use SLAAC.
- Stateless DHCPv6: the device builds its address with SLAAC and only asks DHCPv6 for extra settings, such as DNS servers and a domain name.
Neighbor Discovery: how IPv6 replaces ARP
In IPv4, a device that knows an IP address but needs the matching MAC address uses ARP, which broadcasts the question to every device. IPv6 replaces ARP, router discovery and more with the Neighbor Discovery Protocol (NDP). NDP messages are ICMP messages for IPv6 (ICMPv6). There are four that you need to know:
| Message | Short | Sent to | Meaning |
|---|---|---|---|
| Router Solicitation | RS | ff02::2 | “Are there any routers here?” |
| Router Advertisement | RA | ff02::1 (or the asker) | “I am a router. Here is the prefix and how to get an address.” |
| Neighbor Solicitation | NS | Solicited-node multicast | “Who has this IPv6 address? What is your MAC address?” (like an ARP request) |
| Neighbor Advertisement | NA | Usually unicast to the asker | “That is me. Here is my MAC address.” (like an ARP reply) |
Here is a laptop joining a LAN, getting its address and then finding the MAC address of a printer on the same LAN. Tap a message to see its addresses.
- Global address:
- 2001:db8:abcd:10:200:5eff:fe00:532a/64
- Default gateway:
- fe80::1
- Neighbour cache:
- 2001:db8:abcd:10::30 → 00:00:5e:00:53:30
Duplicate Address Detection (DAD) uses the same NS message. Before using a new address, the device sends an NS for its own address, with :: as the source. If anyone answers with an NA, the address is already taken and the device must not use it.
Seeing IPv6 settings on Windows
C:\> ipconfig Ethernet adapter Ethernet: Connection-specific DNS Suffix . : home.arpa IPv6 Address. . . . . . . . . . . : 2001:db8:abcd:10:4c1f:a2e9:7b30:d815 Temporary IPv6 Address. . . . . . : 2001:db8:abcd:10:91d2:6e04:3a7c:b2f8 Link-local IPv6 Address . . . . . : fe80::4c1f:a2e9:7b30:d815%12 IPv4 Address. . . . . . . . . . . : 192.168.10.25 Subnet Mask . . . . . . . . . . . : 255.255.255.0 Default Gateway . . . . . . . . . : fe80::1%12 192.168.10.1
fe80::. The IPv6 Default Gateway is the router's link-local address, and %12 is the interface number (zone ID).ipconfig /all also shows DHCPv6 details and the DNS servers. To see the neighbour cache (the IPv6 version of the ARP table), use netsh interface ipv6 show neighbors.
Seeing IPv6 settings on Linux
$ ip -6 addr 1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 state UNKNOWN qlen 1000 inet6 ::1/128 scope host valid_lft forever preferred_lft forever 2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 state UP qlen 1000 inet6 2001:db8:abcd:10:8d3e:41a2:9f07:c3b1/64 scope global temporary dynamic valid_lft 86321sec preferred_lft 14321sec inet6 2001:db8:abcd:10:200:5eff:fe00:532a/64 scope global dynamic mngtmpaddr valid_lft 86321sec preferred_lft 14321sec inet6 fe80::200:5eff:fe00:532a/64 scope link valid_lft forever preferred_lft forever
scope host is loopback, scope link is link-local and scope global is global unicast. This machine uses EUI-64 (notice the ff:fe) plus a temporary privacy address. dynamic means the address was learned from an RA and has a limited lifetime (valid_lft).$ ip -6 route ::1 dev lo proto kernel metric 256 pref medium 2001:db8:abcd:10::/64 dev eth0 proto ra metric 100 pref medium fe80::/64 dev eth0 proto kernel metric 256 pref medium default via fe80::1 dev eth0 proto ra metric 100 pref medium
proto ra means the route came from a Router Advertisement. The default via line shows the default gateway: the router's link-local address, fe80::1.$ ip -6 neigh fe80::1 dev eth0 lladdr 00:00:5e:00:53:01 router REACHABLE 2001:db8:abcd:10::30 dev eth0 lladdr 00:00:5e:00:53:30 STALE
lladdr is the neighbour's MAC address, and router marks the gateway. STALE only means the entry has not been confirmed recently; it is checked again the next time it is used.Testing with ping
Ping the loopback address first. If ::1 answers, IPv6 is working inside the computer itself:
C:\> ping ::1 Pinging ::1 with 32 bytes of data: Reply from ::1: time<1ms Reply from ::1: time<1ms Reply from ::1: time<1ms Reply from ::1: time<1ms
Then use ping -6 to force IPv6 when you ping a name or a remote host. On Linux, a link-local target needs the zone ID:
$ ping -6 -c 3 fe80::1%eth0 PING fe80::1%eth0(fe80::1%eth0) 56 data bytes 64 bytes from fe80::1%eth0: icmp_seq=1 ttl=64 time=0.41 ms 64 bytes from fe80::1%eth0: icmp_seq=2 ttl=64 time=0.38 ms 64 bytes from fe80::1%eth0: icmp_seq=3 ttl=64 time=0.40 ms --- fe80::1%eth0 ping statistics --- 3 packets transmitted, 3 received, 0% packet loss, time 2003ms
ping -6 www.example.com to test the path to the internet over IPv6. The same command works on Windows.When it goes wrong
| Symptom | Likely cause | What to check |
|---|---|---|
Only an fe80:: address, no global one | No Router Advertisements reach the device (the router isn't configured for IPv6, or RAs are blocked) | ip -6 route: is there a default route with proto ra? |
| Global address but no IPv6 internet | The provider link has no IPv6, or a firewall drops IPv6 traffic | ping -6 the gateway, then a public IPv6 host |
Address marked “duplicate” (Windows) or dadfailed (Linux) | Another device already uses that address | Look for a static address typed on two devices; find the other device in the neighbour cache |
| Android phones get no IPv6 address, but laptops do | The network uses only stateful DHCPv6 | Enable SLAAC on the router as well |
| Devices get addresses from a strange prefix | A rogue device is sending Router Advertisements | Check the gateway in ip -6 route; switches can block rogue RAs with RA Guard |
| IPv6 neighbours unreachable after a firewall change | All ICMPv6 is blocked, which breaks Neighbor Discovery | Allow ICMPv6 NDP messages (types 133–136) |
Common mistakes
- Blocking all ICMPv6 “for security”. IPv6 cannot find neighbours or routers without it.
- Expecting DHCPv6 to give the default gateway. The gateway always comes from Router Advertisements.
- Thinking an fe80:: address means DHCP failed. It is not like a 169.254.x.x address in IPv4: every IPv6 interface always has one. There is only a problem when it is the only IPv6 address.
- Forgetting the zone ID when pinging a link-local address on Linux. Without
%eth0, the computer doesn't know which interface to use. - Treating ULA as required. Unlike IPv4 networks, IPv6 networks normally use global addresses internally and need no NAT.
- Looking for an IPv6 broadcast address. There is none; IPv6 uses multicast, such as
ff02::1, instead.
- An IPv6 interface normally has several addresses: link-local, global and often a temporary one.
- Global unicast is 2000::/3; link-local is fe80::/10; unique local is fc00::/7 (fd00::/8 in practice); loopback is ::1; unspecified is ::.
- Multicast (ff00::/8) replaces broadcast: ff02::1 is all nodes, ff02::2 is all routers and ff02::1:ffXX:XXXX is solicited-node.
- Anycast is one address on several devices; the nearest one receives the packet.
- SLAAC builds an address from the RA's /64 prefix plus an interface ID (EUI-64 or random).
- DHCPv6 can be stateful (assigns addresses) or stateless (only extra settings). The gateway always comes from RAs.
- Neighbor Discovery (RS, RA, NS, NA, all ICMPv6) replaces ARP.
- Check settings with ipconfig on Windows and ip -6 addr, route and neigh on Linux; test with ping ::1 and ping -6.
Check yourself
You run ipconfig and see these four IPv6 addresses. Which one is a link-local address?
A laptop runs ip -6 route and sees: default via fe80::1 dev eth0 proto ra. Where did it learn this gateway?
A laptop needs the MAC address of 2001:db8:abcd:10::4:2b7c. To which solicited-node multicast address does it send the Neighbor Solicitation?
A device's interface ID is 0200:5eff:fe00:532a. How was it most likely created?
A firewall administrator blocks all ICMPv6. What breaks on the LAN?
To plan IPv6 subnets, split a /48 into /64s with the IPv6 Subnet Calculator. To review the address format and shortening rules, go back to the previous lesson.
Learn more: IPv6 Addressing Basics