IPv6 myths
Certain claims about IPv6 come up every time the subject is raised. Twenty years ago, most of them were reasonable objections. Today they are myths.
“IPv4 is more secure than IPv6”
No, not if you do it right. The threats are fundamentally the same in both protocols, and every protection has its counterpart. Take attacks where someone on the local network places themselves between two parties (MITM). You have to protect against those regardless of protocol:
| IPv4 | IPv6 |
|---|---|
| DHCP snooping | DHCPv6 snooping |
| Dynamic ARP inspection | Neighbor discovery inspection |
And so it goes on. What's more, the payload is always the same: an attack on a web application or a mail server looks exactly the same whichever version of IP is carrying it.
“We have enough IPv4 addresses”
The last free blocks were allocated in 2011. What keeps IPv4 going today is NAT, CGNAT and a secondary market for addresses, and even the private addresses are no longer enough. More on that in Why IPv6?.
“IPv6 is expensive”
Support is already built into the equipment and operating systems you buy today. What costs money is knowledge and effort, and that can be spread out in stages: run IPv4 and IPv6 side by side, and introduce IPv6 as the network gets rebuilt anyway.
What gets more expensive every year is IPv4. Addresses have to be bought or leased, CGNAT requires hardware and logging, and every additional layer of address translation makes the network harder to operate and troubleshoot.
“IPv6 support is poor”
Every mainstream operating system, router, firewall, cloud service and content delivery network has supported IPv6 for many years. According to Google's statistics, almost half of users reach Google's services over IPv6, and several large mobile operators give their customers IPv6 only.
There are still individual products with gaps. The answer is to require IPv6 in every purchase, not to wait.
“NAT provides security”
NAT is address translation, not protection. What stops outside traffic from getting into the network is the firewall's stateful inspection: only traffic belonging to a connection opened from the inside is let in. It works exactly the same way with IPv6, without NAT.

I've tested this on ordinary home routers: with IPv6 enabled and no NAT, nothing except ping got through any of them. The results are in Home router test, October 2025 (PDF).
“Nobody is asking for IPv6”
Users don't ask for protocols. They want services that work, and that is getting harder and harder with IPv4 alone. The demand shows up instead among the people who build the networks: operators who have no more IPv4 addresses to hand out, and cloud providers who have started charging for every public IPv4 address.
More myths
More examples, in English:
- Network World: The 6 biggest misconceptions about IPv6
- LogicMonitor: IPv6 adoption