Why IPv6?
On 3 February 2011, IANA handed out the last free IPv4 blocks to the five Regional Internet Registries (RIRs). That was 15 years ago. Since then, there have been no new IPv4 addresses to be had, only the ones already allocated, and there aren't enough of them.
The maths doesn't add up
IPv4 has 32 bits, which gives roughly 4.3 billion addresses. Subtract the reserved blocks, the private ones and the cloud providers' blocks, and you're left with around 3 billion that can actually be used on the internet.
Set that against:
- 8 billion people on Earth
- 30 billion connected devices
That works out to one public address per ten devices, and not even one per person. There's simply no way for every phone, computer, TV, car, sensor and server to get an address of its own.
NAT and CGNAT solve the shortage, on paper
The internet still works because of address translation. With NAT, every device in a home or office shares a single public address. When even that wasn't enough, CGNAT (Carrier-Grade NAT) came along, where the operator has hundreds or thousands of customers share the same address. As a result, many devices sit behind two layers of translation.

This hides the shortage, but it doesn't solve it. And it comes at a cost:
- End-to-end is lost. The internet was built so that any device could reach any other device. Behind NAT you can connect outwards, but nobody can reach you. Behind CGNAT you can't even open a port yourself.
- Services work less well. Gaming, video calls, VPNs, remote access and peer-to-peer need detours through relay servers to get through, which means higher latency and more things that can break.
- How many criminals do you share an IP address with? When thousands of customers appear behind the same address, everyone gets hit by blocks, CAPTCHAs and incorrect geolocation if just one of them misbehaves.
- Troubleshooting and traceability get harder. An address no longer identifies a customer. The operator has to log every translation to be able to say who did what.
- It doesn't scale. Every connection requires state in the operator's equipment, and the number of ports per address is limited. More customers and more devices mean more expensive equipment, more bottlenecks and more customers per address.
Meanwhile, the addresses that do exist have become a commodity. Anyone who wants to grow has to buy or lease IPv4 addresses on a secondary market, a cost that ends up with customers and makes it harder for new players to get in.
Even the private addresses have run out
Behind NAT, private addresses as defined in RFC 1918 are used: 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16. Together that's just under 18 million addresses that anyone may use in their own network. That sounded like a lot in 1996. Today it isn't enough, and because everyone uses the same addresses, networks collide with each other:
- Large networks don't fit. Large operators, cloud providers and enterprises have exhausted the whole of 10.0.0.0/8. They're forced to reuse the same addresses in several parts of the network and deploy NAT internally as well.
- VPNs collide with the home network. If the office and the home use the same network, say 192.168.1.0/24, the computer can't tell whether an address is local or at the other end of the tunnel. Either the server at work becomes unreachable, or the printer at home disappears.
- Guest networks collide with VPNs. In hotels, cafés, trains and conferences, someone else has chosen the addresses. If the guest network lands in the same address space as the company network, the VPN connection doesn't work, and there's nothing the user can do about it.
- Mergers become renumbering projects. When two companies merge, or need to connect their networks to a partner's, both often use the same 10 network. That leaves renumbering one of the networks or putting NAT between them.
- Containers and virtual networks collide with the physical ones. Docker, Kubernetes and virtual networks in the cloud pick their own private addresses, which are quite often already in use somewhere else in the organisation.
- Not even CGNAT fitted. Operators couldn't use RFC 1918 addresses between their CGNAT and their customers, because they collided with the customers' own networks. The solution was to take yet another block, 100.64.0.0/10, out of the public address space.
Every collision is resolved with more NAT, renumbering or special rules: yet another layer of stopgaps on top of the ones already in place.
Remember: most things stay the same
The only thing that differs between the two protocols is the IP layer, the actual transport of the packets. Everything else is pretty much the same whichever one you run: the same applications, the same protocols on top and the same tools:
| IPv4 | IPv6 |
|---|---|
| TCP/UDP | TCP/UDP |
| HTTP/HTTPS | HTTP/HTTPS |
| TLS | TLS |
| SSH | SSH |
| DNS | DNS |
| SMTP | SMTP |
| curl | curl |
| BGP | BGP |
| IS-IS | IS-IS |
| ping | ping (ping6) |
| traceroute | traceroute (traceroute6) |
A few things have a new version or a successor, but do the same job:
| IPv4 | IPv6 |
|---|---|
| A record in DNS | AAAA record in DNS |
| ICMP | ICMPv6 |
| ARP | Neighbor Discovery (NDP) |
| DHCP | SLAAC and DHCPv6 |
| OSPFv2 | OSPFv3 |
| IGMP snooping | MLD snooping |
Troubleshooting will feel familiar too. Here's how to show the neighbours on the local network, what IPv4 calls the ARP table:
| System | IPv4 | IPv6 |
|---|---|---|
| Windows | arp -a |
netsh interface ipv6 show neighbors |
| Linux | ip -4 neigh |
ip -6 neigh |
| macOS | arp -an |
ndp -an |
What actually differs
| IPv4 | IPv6 | |
|---|---|---|
| Address space | 32 bits, for example 192.0.2.100 |
128 bits, for example 2001:db8:0100:1234:ab12:ea32:18de:de56 |
| Header | 20–60 bytes, with a checksum and fields for fragmentation | Always 40 bytes, with no checksum. Options go in separate extension headers after the fixed one |
| Address assignment | DHCP and ARP | RS/RA, DAD, DHCPv6, MLDv2 and ND |
IPv6 solves the problem for real
IPv6 has 128 bits. That gives 340 undecillion addresses, enough for every device to get its own public address, with room to spare for the foreseeable future. No address translation is needed, end-to-end works again, and the network becomes simpler to build, operate and troubleshoot. And since every network gets globally unique addresses, two networks can't collide either, whether over a VPN, on a guest network or when two companies merge.
IPv6 isn't the future. It has been around for over 25 years, and a large share of internet traffic already runs over IPv6. The question isn't whether to deploy it, but how long you can afford not to.