# Configure and test IPv6 on your server

> Add a static IPv6 address and gateway on Ubuntu with netplan, Debian with ifupdown or Windows Server with PowerShell, then test it and publish an AAAA record.

Difficulty: Intermediate\
Tested on: Ubuntu 24.04 LTS, Ubuntu 26.04 LTS, Debian 12, Debian 13, Windows Server 2022, Windows Server 2025

IPv6 gives your server addresses in a much larger space than IPv4 and reaches visitors whose networks prefer it. This guide adds a static IPv6 address to Ubuntu, Debian or Windows Server, tests it and publishes it in DNS. The examples use the documentation prefix `2001:db8::/64`, with `2001:db8::10` as the server address and `2001:db8::1` as the gateway; use the values of your service.

## Before you start

- **Check that your service has IPv6.** Look at **Assigned IPs** on the service page and in your welcome email. Dedicated servers in the United States and South Korea include a /64 block; for other products, ask us.
- **Have a way back in.** Network changes can cut your connection; keep the web console ready if your service page shows one.
- Find the name of your network interface:

```bash
ip -brief link
ip -6 address
```

The examples use `eth0`; yours may be called `ens3`, `enp1s0` or similar.

## Step 1: Test the address without making it permanent

Adding the address by hand first lets you check it before you change configuration files. It disappears at the next reboot:

```bash
sudo ip -6 address add 2001:db8::10/64 dev eth0
sudo ip -6 route add default via 2001:db8::1 dev eth0
ping -6 -c 4 2606:4700:4700::1111
```

**Verify:** the ping receives replies. If it fails, check the address, prefix length and gateway against your service details before going further.

## Step 2: Make it permanent

**Ubuntu (netplan)**

Edit the netplan file in `/etc/netplan/` (for example `50-cloud-init.yaml`; keep the existing IPv4 lines) and add the IPv6 address and route:

```yaml
network:
  version: 2
  ethernets:
    eth0:
      addresses:
        - 203.0.113.10/24
        - "2001:db8::10/64"
      routes:
        - to: default
          via: 203.0.113.1
        - to: default
          via: "2001:db8::1"
```

Apply it with a safety net: `netplan try` rolls back automatically if you do not confirm within two minutes:

```bash
sudo netplan try
```

If the file says it is generated by cloud-init, also disable cloud-init's network configuration, or your change may be overwritten: create `/etc/cloud/cloud.cfg.d/99-disable-network-config.cfg` containing `network: {config: disabled}`.
**Debian (ifupdown)**

Add an `inet6` section for the interface in `/etc/network/interfaces`, below the existing IPv4 section:

```text
iface eth0 inet6 static
    address 2001:db8::10/64
    gateway 2001:db8::1
```

Apply it from the web console, because restarting the network briefly interrupts your connection:

```bash
sudo systemctl restart networking
```
**Windows Server**

In PowerShell as administrator, find the interface name with `Get-NetAdapter`, then add the address and gateway:

```powershell
New-NetIPAddress -InterfaceAlias "Ethernet" -IPAddress 2001:db8::10 -PrefixLength 64 -DefaultGateway 2001:db8::1
```

Settings made this way are persistent.

**Verify** after a reboot (Linux):

```bash
ip -6 address show dev eth0
ip -6 route
```

On Windows: `Get-NetIPAddress -AddressFamily IPv6` and `Get-NetRoute -AddressFamily IPv6`.

## Step 3: Test from outside

From another IPv6-capable computer:

```bash
ping -6 -c 4 2001:db8::10
curl -6 -I http://[2001:db8::10]/
```

On Windows: `Test-NetConnection 2001:db8::10 -Port 443`.

## Step 4: Open the firewall for IPv6

- **UFW** handles IPv6 when `/etc/default/ufw` contains `IPV6=yes`, the default. Rules you add apply to both protocols.
- **nftables** rules in a table of family `inet` apply to both. Allow ICMPv6, which IPv6 needs for neighbour discovery: see [nftables firewall](/guides/nftables-firewall).
- **Windows Defender Firewall** rules apply to IPv4 and IPv6 unless you limit them.

## Step 5: Publish it in DNS

Add an AAAA record for your domain with the new address; see [point a domain to your server](/guides/point-domain-to-server). Make sure your web server listens on IPv6 (nginx: `listen [::]:443 ssl;`), or visitors who prefer IPv6 get errors. If the server sends mail over IPv6, request a PTR record for that address: [reverse DNS](/guides/reverse-dns-ptr).

## Troubleshooting

**`ping -6` reports "Network is unreachable".** No default IPv6 route. Check the gateway and that the route exists with `ip -6 route`.

**The address works until the next reboot.** The permanent configuration was not applied, or cloud-init overwrote it.

**The website fails over IPv6 only.** The web server does not listen on IPv6, or the firewall blocks it. Check `sudo ss -tlnp` for `[::]:443`.

## Next steps

- Firewall rules for both protocols: [UFW firewall](/guides/ufw-firewall).
- IPv6 and mail: [reverse DNS (PTR)](/guides/reverse-dns-ptr).

## Frequently asked questions

### Does my server have IPv6?

Check Assigned IPs on the service page and your welcome email. Dedicated servers in the United States and South Korea include a /64 IPv6 block; for other products and locations, ask us before you order.

### What is a /64?

A block of IPv6 addresses that share the first 64 bits. You pick addresses from it for your server and services. One address is enough to start.

### Do I need IPv6 for my website?

It is optional: visitors without IPv6 use IPv4. If you publish an AAAA record, make sure the site really works over IPv6, because some visitors will prefer it.

### Does my firewall cover IPv6 too?

UFW handles IPv6 when IPV6=yes is set, which is the default. nftables rules in an inet table and Windows Defender Firewall rules apply to both protocols.

### Which gateway do I use?

Exactly the one in your service details. It can be an address in your block or a link-local address such as fe80::1.

---

Source: <https://hyperdc.com/guides/networking/ipv6-setup>\
Updated: 2026-10-09
