IPv6 in OT and SCADA networks
OT networks are the networks that control things: machinery, fans, heating, water, lighting. They are a grey area when it comes to IPv6. Here you should be careful about switching it on in what is already in place – and all the more thorough about asking for it when you buy something new.
Why you should be careful
- The equipment has a long life. What sits in an OT network often keeps chugging along for 10–15 years. Much of it was built before anyone asked for IPv6.
- Static addresses talk to static addresses. That is how these networks have always been built. There is rarely any address shortage to solve, and nothing that moves around.
- DNS is barely used. Addresses are entered directly in the control systems. Changing protocol means going through every single configuration.
- The protocols don't always keep up. Several of the most common ones were written for IPv4, see below.
So if an OT network works and is separated from everything else, there is rarely any reason to rebuild it just for the sake of IPv6.
But don't forget that IPv6 is there anyway. Operator panels and servers running Windows or Linux have it enabled out of the box and are happy to talk link-local with each other. Firewall rules and segmentation must therefore cover both protocols, even in a network where you only use IPv4.
What about the protocols?
| Protocol | Used for | IPv6 |
|---|---|---|
| Modbus TCP | Industry, energy, buildings | Runs over TCP, but the implementation guide dates from 2006 and does not mention IPv6. Older equipment rarely supports it. |
| BACnet | Building automation | Part of the standard since addendum 135-2012aj (BACnet/IPv6). Product support varies. |
| KNX | Building automation | KNXnet/IP is IPv4. The newer KNX IoT is built on IPv6. |
| DALI | Lighting | DALI-2 is a separate bus without IP. DALI+ carries the same commands over IP networks, starting with Thread, which is IPv6. |
| EtherNet/IP | Industry | Does not support IPv6 yet. In 2025 ODVA presented a roadmap for it. |
| PROFINET | Industry | Built on IPv4. |
| OPC UA, MQTT | Data collection and integration | Not tied to IPv4. Here the product decides, not the protocol. |
| Wi-SUN, Thread, Matter | Street lighting, meters, sensors | Built on IPv6 from the start. |
The pattern is clear: the old fieldbuses and their IP variants are IPv4, while everything designed for large numbers of small devices is IPv6.
When you procure something new
This is where it turns around. If you are procuring, say, a new lighting control system – check whether it can be done with IPv6.
When it comes to large numbers of sensors and devices, IPv6 is far superior. Every device gets its own address, the networks don't have to be squeezed into tight address ranges, and you avoid address translation between the different parts. That is why the large wireless networks for street lighting and electricity meters are built on IPv6. Wi-SUN is one example, with over 100 million devices deployed according to the Wi-SUN Alliance.
Ask the supplier:
- Do the control system, the devices and the monitoring support IPv6 – individually and together?
- Can the system run on IPv6 only, or is IPv4 required anywhere?
- How do the devices get their addresses, and can they be reached by name instead of hard-coded addresses?
- If the answer is no today: when will support arrive, and is the upgrade included?
What you buy today will still be in place in 2040. The RIPE-772 requirements list is a good starting point here too.
Further reading
- NIST: Guide to Operational Technology (OT) Security (SP 800-82) – on segmentation and protection of OT networks in general.
- AutomatedBuildings: IPv6 in building automation – on BACnet/IPv6, written by a vendor.
- Thread Group: DALI+ with Thread.