I want to learn IPv6
The best way to learn IPv6 is by running it. Do read up on it, but above all, build your own network at home where you can experiment, make mistakes and see what happens. It doesn't take much: a router or firewall that you control yourself, a couple of computers or virtual machines, and IPv6 addresses that are yours to experiment with.
A stable prefix makes a big difference
In a home lab, a prefix that doesn't change is worth its weight in gold. Many broadband providers that offer IPv6 hand out a prefix that can change after a reboot or an outage, and when it does, every device on the network gets a new address. What breaks then is exactly what you want to practise:
- AAAA records in DNS
- firewall rules
- the addressing plan and the division into multiple networks
- services that need to be reachable from outside
With a static prefix, you can build something, leave it and come back next week without having to start by troubleshooting the addresses.
Route64: a static prefix through a tunnel
route64.org is an excellent fit for a home lab. It's a non-profit service that gives you your own routed /56 with a static assignment through a tunnel, completely free of charge. A /56 holds 256 networks, so you have plenty of room to divide your lab into several parts.
You can choose between several tunnel types, including WireGuard, GRE and IP6IP, and everything is set up through a self-service portal. It works whether or not your own ISP offers IPv6.
Why not Hurricane Electric?
Hurricane Electric's tunnels have helped many people get started and work well if you have a static, public IPv4 address. But they rely on the tunnel terminating directly at your IPv4 address, and that causes trouble in two common cases:
- You're behind CGNAT. You then have no public IPv4 address of your own for the tunnel to terminate at, and it won't get through.
- Your IPv4 address changes. The tunnel stops working every time the address changes, until the new address has been registered.
This is where Route64 wins. WireGuard copes with CGNAT much better: the tunnel is established from the inside out over UDP, just like any other traffic, and survives your address changing along the way.
MikroTik and containers
A MikroTik router makes a good foundation for your lab. RouterOS has full support for IPv6 and for the tunnel types above, and the hardware is inexpensive. From version 7, the router can also run containers, and they work superbly with IPv6: each container gets its own interface and its own address from your prefix, and can be reached directly without port forwarding or address translation.
That makes it easy to set up small services to practise on, such as a name server or a web server, without any extra hardware.
Start with RIPE Atlas
A container running RIPE Atlas is a good first step. RIPE Atlas is a global measurement network in which thousands of small probes measure how the internet is performing, over both IPv4 and IPv6. The probe is also available as software, and RIPE describes how to install it and links to ready-made container images in its documentation on software probes.
You learn how a container gets its IPv6 address and reaches the outside world, and you get something up and running that's actually useful: the measurements help operators and researchers, and you earn credits that you can spend on your own measurements of your network.
464XLAT: an IPv6-only network
The most fun thing you can try in your lab right now is a network with no IPv4 at all. What long stood in the way was applications and services that only speak IPv4. 464XLAT solves this with two-stage translation:
- CLAT on the client gives IPv4 applications an address to talk to and translates their traffic to IPv6.
- NAT64 in the router or at the ISP translates it back to IPv4 towards the internet.
In between, everything runs over IPv6. The client learns which prefix NAT64 uses from the router's RA (PREF64) or through DNS64.
iOS, Android, ChromeOS and macOS have had CLAT for many years. The one missing was Windows, but now Windows 11 has CLAT too, known as WinCLAT. Microsoft is rolling it out gradually following a public preview. This means all common clients can now handle an IPv6-only network.
NAT64 in your router
You'll need NAT64 in your lab. Here's how it works in some common routers and firewalls:
- MikroTik. RouterOS has no built-in NAT64, but you can work around that with Tayga in a container.
- OpenWrt. Read about IPv6 and about NAT64 with Jool or Tayga.
- pfSense. Read about IPv6 and about NAT64, with PREF64 and DNS64.
- OPNsense. Read about IPv6 and about NAT64 with Tayga.
- VyOS. Has NAT64 built in.
- Linux. Jool and Tayga can be run on an ordinary Linux machine.
Things to keep in mind
- MTU. A tunnel takes up a little space in every packet. With WireGuard, 1420 bytes is the usual value. Set it on the tunnel and have the router advertise it to the networks behind it, otherwise some sites and services may hang.
- Firewall. With public addresses on every device, there's no NAT to hide a forgotten filter. Start by blocking all inbound traffic that doesn't belong to a connection initiated from the inside, and then open up only what you want to try.
What should I try?
- Split your /56 into several /64s and route between them.
- Let clients get addresses via SLAAC, then try DHCPv6, for example with Kea (see below).
- Look at neighbours, RA and DAD with the usual tools and with a packet sniffer.
- Set up a service, give it an AAAA record in DNS and reach it from outside, for example from your phone.
- Turn off IPv4 on one of the networks and see what still works.
- Set up NAT64 on the same network and see how clients with CLAT get by without IPv4 at all.
Further reading
- RIPE NCC training. RIPE NCC Academy offers free online courses on IPv6, from the basics to security. Slides and exercises from the instructor-led courses IPv6 Fundamentals, IPv6 Advanced and IPv6 Security can be downloaded from the course material, and upcoming courses and webinars are listed in the training calendar.
- Kea DHCPv6. Kea from ISC is a modern, open-source DHCP server that works well in a lab. The chapter on the DHCPv6 server in the manual covers address assignment, prefix delegation and all the configuration options.