Skip to content

NetworkingIP addresses & IPv6

Configure and test IPv6 on your server

Add a static IPv6 address and gateway on Ubuntu with netplan, Debian with ifupdown or Windows Server with PowerShell, then test it and publish an AAAA record.

  • Intermediate
  • 15 min read
  • Updated

Tested on: Ubuntu 24.04 LTS, Ubuntu 26.04 LTS, Debian 12, Debian 13, Windows Server 2022, Windows Server 2025

This guide is not available in your language yet, so it is shown in English.

On this page
  1. Before you start
  2. Step 1: Test the address without making it permanent
  3. Step 2: Make it permanent
  4. Step 3: Test from outside
  5. Step 4: Open the firewall for IPv6
  6. Step 5: Publish it in DNS
  7. Troubleshooting
  8. Next steps

IPv6 gives your server addresses in a much larger space than IPv4 and reaches visitors whose networks prefer it. This guide adds a static IPv6 address to Ubuntu, Debian or Windows Server, tests it and publishes it in DNS. The examples use the documentation prefix 2001:db8::/64, with 2001:db8::10 as the server address and 2001:db8::1 as the gateway; use the values of your service.

Before you start

  • Check that your service has IPv6. Look at Assigned IPs on the service page and in your welcome email. Dedicated servers in the United States and South Korea include a /64 block; for other products, ask us.
  • Have a way back in. Network changes can cut your connection; keep the web console ready if your service page shows one.
  • Find the name of your network interface:
Bash
ip -brief link
ip -6 address

The examples use eth0; yours may be called ens3, enp1s0 or similar.

Step 1: Test the address without making it permanent

Adding the address by hand first lets you check it before you change configuration files. It disappears at the next reboot:

Bash
sudo ip -6 address add 2001:db8::10/64 dev eth0
sudo ip -6 route add default via 2001:db8::1 dev eth0
ping -6 -c 4 2606:4700:4700::1111

Verify: the ping receives replies. If it fails, check the address, prefix length and gateway against your service details before going further.

Step 2: Make it permanent

Ubuntu (netplan)

Edit the netplan file in /etc/netplan/ (for example 50-cloud-init.yaml; keep the existing IPv4 lines) and add the IPv6 address and route:

YAML
network:
  version: 2
  ethernets:
    eth0:
      addresses:
        - 203.0.113.10/24
        - "2001:db8::10/64"
      routes:
        - to: default
          via: 203.0.113.1
        - to: default
          via: "2001:db8::1"

Apply it with a safety net: netplan try rolls back automatically if you do not confirm within two minutes:

Bash
sudo netplan try

If the file says it is generated by cloud-init, also disable cloud-init's network configuration, or your change may be overwritten: create /etc/cloud/cloud.cfg.d/99-disable-network-config.cfg containing network: {config: disabled}.

Debian (ifupdown)

Add an inet6 section for the interface in /etc/network/interfaces, below the existing IPv4 section:

Text
iface eth0 inet6 static
    address 2001:db8::10/64
    gateway 2001:db8::1

Apply it from the web console, because restarting the network briefly interrupts your connection:

Bash
sudo systemctl restart networking

Windows Server

In PowerShell as administrator, find the interface name with Get-NetAdapter, then add the address and gateway:

PowerShell
New-NetIPAddress -InterfaceAlias "Ethernet" -IPAddress 2001:db8::10 -PrefixLength 64 -DefaultGateway 2001:db8::1

Settings made this way are persistent.

Verify after a reboot (Linux):

Bash
ip -6 address show dev eth0
ip -6 route

On Windows: Get-NetIPAddress -AddressFamily IPv6 and Get-NetRoute -AddressFamily IPv6.

Step 3: Test from outside

From another IPv6-capable computer:

Bash
ping -6 -c 4 2001:db8::10
curl -6 -I http://[2001:db8::10]/

On Windows: Test-NetConnection 2001:db8::10 -Port 443.

Step 4: Open the firewall for IPv6

  • UFW handles IPv6 when /etc/default/ufw contains IPV6=yes, the default. Rules you add apply to both protocols.
  • nftables rules in a table of family inet apply to both. Allow ICMPv6, which IPv6 needs for neighbour discovery: see nftables firewall.
  • Windows Defender Firewall rules apply to IPv4 and IPv6 unless you limit them.

Step 5: Publish it in DNS

Add an AAAA record for your domain with the new address; see point a domain to your server. Make sure your web server listens on IPv6 (nginx: listen [::]:443 ssl;), or visitors who prefer IPv6 get errors. If the server sends mail over IPv6, request a PTR record for that address: reverse DNS.

Troubleshooting

ping -6 reports "Network is unreachable". No default IPv6 route. Check the gateway and that the route exists with ip -6 route.

The address works until the next reboot. The permanent configuration was not applied, or cloud-init overwrote it.

The website fails over IPv6 only. The web server does not listen on IPv6, or the firewall blocks it. Check sudo ss -tlnp for [::]:443.

Next steps

Frequently asked questions

Does my server have IPv6?

Check Assigned IPs on the service page and your welcome email. Dedicated servers in the United States and South Korea include a /64 IPv6 block; for other products and locations, ask us before you order.

What is a /64?

A block of IPv6 addresses that share the first 64 bits. You pick addresses from it for your server and services. One address is enough to start.

Do I need IPv6 for my website?

It is optional: visitors without IPv6 use IPv4. If you publish an AAAA record, make sure the site really works over IPv6, because some visitors will prefer it.

Does my firewall cover IPv6 too?

UFW handles IPv6 when IPV6=yes is set, which is the default. nftables rules in an inet table and Windows Defender Firewall rules apply to both protocols.

Which gateway do I use?

Exactly the one in your service details. It can be an address in your block or a link-local address such as fe80::1.

Sources

Generar contrasenya

Please confirm