Configure and test IPv6 on your server
Add a static IPv6 address and gateway on Ubuntu with netplan, Debian with ifupdown or Windows Server with PowerShell, then test it and publish an AAAA record.
- Intermediate
- 15 min read
- Updated
Tested on: Ubuntu 24.04 LTS, Ubuntu 26.04 LTS, Debian 12, Debian 13, Windows Server 2022, Windows Server 2025
On this page
IPv6 gives your server addresses in a much larger space than IPv4 and reaches visitors whose networks prefer it. This guide adds a static IPv6 address to Ubuntu, Debian or Windows Server, tests it and publishes it in DNS. The examples use the documentation prefix 2001:db8::/64, with 2001:db8::10 as the server address and 2001:db8::1 as the gateway; use the values of your service.
Before you start
- Check that your service has IPv6. Look at Assigned IPs on the service page and in your welcome email. Dedicated servers in the United States and South Korea include a /64 block; for other products, ask us.
- Have a way back in. Network changes can cut your connection; keep the web console ready if your service page shows one.
- Find the name of your network interface:
ip -brief link
ip -6 addressThe examples use eth0; yours may be called ens3, enp1s0 or similar.
Step 1: Test the address without making it permanent
Adding the address by hand first lets you check it before you change configuration files. It disappears at the next reboot:
sudo ip -6 address add 2001:db8::10/64 dev eth0
sudo ip -6 route add default via 2001:db8::1 dev eth0
ping -6 -c 4 2606:4700:4700::1111Verify: the ping receives replies. If it fails, check the address, prefix length and gateway against your service details before going further.
Step 2: Make it permanent
Ubuntu (netplan)
Edit the netplan file in /etc/netplan/ (for example 50-cloud-init.yaml; keep the existing IPv4 lines) and add the IPv6 address and route:
network:
version: 2
ethernets:
eth0:
addresses:
- 203.0.113.10/24
- "2001:db8::10/64"
routes:
- to: default
via: 203.0.113.1
- to: default
via: "2001:db8::1"Apply it with a safety net: netplan try rolls back automatically if you do not confirm within two minutes:
sudo netplan tryIf the file says it is generated by cloud-init, also disable cloud-init's network configuration, or your change may be overwritten: create /etc/cloud/cloud.cfg.d/99-disable-network-config.cfg containing network: {config: disabled}.
Debian (ifupdown)
Add an inet6 section for the interface in /etc/network/interfaces, below the existing IPv4 section:
iface eth0 inet6 static
address 2001:db8::10/64
gateway 2001:db8::1Apply it from the web console, because restarting the network briefly interrupts your connection:
sudo systemctl restart networkingWindows Server
In PowerShell as administrator, find the interface name with Get-NetAdapter, then add the address and gateway:
New-NetIPAddress -InterfaceAlias "Ethernet" -IPAddress 2001:db8::10 -PrefixLength 64 -DefaultGateway 2001:db8::1Settings made this way are persistent.
Verify after a reboot (Linux):
ip -6 address show dev eth0
ip -6 routeOn Windows: Get-NetIPAddress -AddressFamily IPv6 and Get-NetRoute -AddressFamily IPv6.
Step 3: Test from outside
From another IPv6-capable computer:
ping -6 -c 4 2001:db8::10
curl -6 -I http://[2001:db8::10]/On Windows: Test-NetConnection 2001:db8::10 -Port 443.
Step 4: Open the firewall for IPv6
- UFW handles IPv6 when
/etc/default/ufwcontainsIPV6=yes, the default. Rules you add apply to both protocols. - nftables rules in a table of family
inetapply to both. Allow ICMPv6, which IPv6 needs for neighbour discovery: see nftables firewall. - Windows Defender Firewall rules apply to IPv4 and IPv6 unless you limit them.
Step 5: Publish it in DNS
Add an AAAA record for your domain with the new address; see point a domain to your server. Make sure your web server listens on IPv6 (nginx: listen [::]:443 ssl;), or visitors who prefer IPv6 get errors. If the server sends mail over IPv6, request a PTR record for that address: reverse DNS.
Troubleshooting
ping -6 reports "Network is unreachable". No default IPv6 route. Check the gateway and that the route exists with ip -6 route.
The address works until the next reboot. The permanent configuration was not applied, or cloud-init overwrote it.
The website fails over IPv6 only. The web server does not listen on IPv6, or the firewall blocks it. Check sudo ss -tlnp for [::]:443.
Next steps
- Firewall rules for both protocols: UFW firewall.
- IPv6 and mail: reverse DNS (PTR).
Frequently asked questions
Does my server have IPv6?
Check Assigned IPs on the service page and your welcome email. Dedicated servers in the United States and South Korea include a /64 IPv6 block; for other products and locations, ask us before you order.
What is a /64?
A block of IPv6 addresses that share the first 64 bits. You pick addresses from it for your server and services. One address is enough to start.
Do I need IPv6 for my website?
It is optional: visitors without IPv6 use IPv4. If you publish an AAAA record, make sure the site really works over IPv6, because some visitors will prefer it.
Does my firewall cover IPv6 too?
UFW handles IPv6 when IPV6=yes is set, which is the default. nftables rules in an inet table and Windows Defender Firewall rules apply to both protocols.
Which gateway do I use?
Exactly the one in your service details. It can be an address in your block or a link-local address such as fe80::1.