Quick reference
| Item | Meaning | Example / note |
|---|---|---|
| Global unicast | Globally scoped address | 2001:db8::/32 is documentation only |
| Link-local | Valid on the local link | fe80::/10; identify the interface |
| Loopback | This host | ::1/128 |
| Unspecified | No assigned address | ::/128 |
| Multicast | Group delivery | ff00::/8; no IPv6 broadcast |
| LAN prefix | Common SLAAC design | /64; not every link must be /64 |
What to understand first
IPv6 has 128 bits, usually written as eight hexadecimal groups. Leading zeros may be omitted; one run of zero groups can be compressed with ::. Canonical text uses lowercase and the longest eligible run.
The prefix length identifies network bits. A /48 allocation contains 65,536 /64 prefixes. 2001:db8:1200:30::/64 and 2001:db8:1200:31::/64 are separate LANs.
ICMPv6 supports Neighbor Discovery and path-MTU feedback. IPv4-style blanket ICMP blocking can break IPv6 even when addresses and routes look correct.
Duplicate Address Detection, neighbor reachability, RA flags and address lifetimes are separate checks. Dual-stack applications may choose IPv6 even while IPv4 tests pass.
Commands and interpretation
Inspection commands are read-only unless explicitly labeled otherwise. Capture commands start collection; configuration-mode commits change device state.
Cisco IOS XE
Read-only EXEC
show ipv6 interface brief
show ipv6 neighbors
show ipv6 routeInspect: Check address state, neighbor status and default route; inspect the specific interface for RA settings.
Junos
Read-only operational
show interfaces terse
show ipv6 neighbors
show route table inet6.0Inspect: inet6.0 is the default IPv6 table. Use the appropriate instance table for tenant traffic.
Worked example · Illustrative, not a device capture
Illustrative dual-stack failure
Client: 2001:db8:1200:30::25/64
Neighbor: fe80::1 on the client link
IPv4 application: works
IPv6 default route: absentThe neighbor can resolve locally while the remote application still has no route. Check the RA/default-router path.
These are teaching observations, not captured device output. Do not infer a default route from an assigned address.
Troubleshooting sequence
- Confirm whether the failing attempt used IPv4 or IPv6; check DNS A and AAAA answers.
- Check address validity and DAD status, then the intended /64 and VLAN.
- Inspect the link-local neighbor on the correct interface and whether an RA supplies a usable router.
- Check the destination prefix and reverse route in the correct IPv6 table.
- If small traffic works but transfers stall, review ICMPv6 Packet Too Big delivery and tunnel MTU.
Common mistakes
- Using multiple :: compressions in one address.
- Treating a link-local address as unique without its link/interface context.
- Assuming IPv4 firewall rules, DNS results or tests also validate IPv6.
Acceptance checks
- Both address families pass the intended application tests.
- ND/RA behavior matches design and unwanted RAs are controlled.
- Path-MTU feedback works and address lifetimes are documented.
Primary references
Vendor documentation and protocol specifications support this guide. The diagrams, scenarios and troubleshooting sequences are Wolex-authored.
