IPv6 anycast addresses look exactly like unicast ones; how does the network deliver a packet to one, and what risks does a stateful TCP service behind one carry?
answer
- no format of its own
- nearest by whose measure
- host route inside the region
- per-packet choice, per-connection state
basics
~20 sAn anycast address is a unicast-format address configured on several interfaces; routing delivers each packet to the nearest holder by its own metric. If routing changes mid-connection, later TCP segments can reach a holder with no state, which resets the connection.
solid answer
~50 sRFC 4291 allocates anycast addresses from unicast space, so they are syntactically indistinguishable; only the holders are configured to know. Inside the holders' region the address is carried as a separate host route and outside it can be aggregated; with no topological locality it needs its own route across the whole internet, which limits global anycast. "Nearest" means the routing protocols' measure of distance, not latency or load. Holders skip Duplicate Address Detection (RFC 4862) and answer Neighbor Solicitations with the Override flag clear. The TCP risk is that delivery is decided per packet: a link failure, a metric change, a holder added or withdrawn, or a changed equal-cost next hop can move the rest of a connection to a holder with no state, which answers with a reset. Short exchanges suit anycast; long sessions need stable routing, shared state or a hand-off to unicast.
go deeper
Recall that an anycast address looks like any unicast address but is held by several interfaces, and that a packet sent to it reaches only one of them.
Explain how routing carries anycast as host routes inside its region, what the Subnet-Router anycast address is, and why holders skip Duplicate Address Detection.
Diagnose resets on anycast services: route changes, withdrawn holders and ECMP rehashing move live TCP flows to holders without state. Propose draining, short sessions or a unicast hand-off.
Decide which services earn anycast: short, stateless exchanges gain locality and failover cheaply, while long sessions pay for it in routing discipline, shared state or a two-step design.
## What makes an address anycast RFC 4291 defines an **anycast address** as one assigned to more than one interface, with packets routed to the "nearest" of them according to the routing protocols' measure of distance. Everything else follows from one design choice: anycast has **no format of its own**. - It is allocated from the **unicast address space**, in any unicast format, so a sender cannot tell it from unicast; RFC 4861 notes that senders generally do not know. - The nodes holding it **must be configured** to know it is anycast. - **Duplicate Address Detection must not be run** on it (RFC 4862): duplication is the whole point. - On a shared link, holders answer Neighbor Solicitations for it with the **Override flag clear** and should delay each answer randomly by up to `MAX_ANYCAST_DELAY_TIME` (1 second), so the first advertisement wins and later ones do not replace it. - Each holder joins the solicited-node group for it, as for any unicast address. RFC 4291 also removed the restrictions its predecessor, RFC 3513, placed on using anycast addresses, citing enough operational experience. ## How routing delivers it For an anycast set there is a longest prefix **P** covering every holder: 1. **Inside** the region identified by P, the anycast address is carried as its own **host route**, so routers can steer to the nearest holder. 2. **Outside** P, it can be aggregated into the route for P; distant networks only need to reach the region. 3. When the holders have **no topological locality** (P is the null prefix), the address needs its own route throughout the internet, a scaling limit that leads RFC 4291 to expect global anycast sets to be unavailable or very restricted. "Nearest" is whatever the routing protocol's metric says, such as path attributes or configured cost; it is not measured latency, and it is not server load. ## The Subnet-Router anycast address RFC 4291 predefines one anycast address: the **subnet prefix with an all-zero interface identifier**. On the link `2001:db8:0:7::/64` it is `2001:db8:0:7::`. Every router must support it for each subnet it attaches to, so a node that needs "any one router on this subnet" has an address for it. Its solicited-node group is `ff02::1:ff00:0`. ## Why stateful TCP is at risk Anycast delivery is decided **per packet**, by routing, while TCP needs every segment of a connection to reach the same endpoint. A trace: 1. A client's SYN to `2001:db8:a::53` is routed to holder A, and the handshake completes there. 2. Mid-connection, routing changes: a link fails, a metric changes, holder A's route is withdrawn, or a holder closer to the client is announced. 3. The next segment reaches holder B, which has no connection for that address and port pair. 4. Under RFC 9293, a segment for a connection that does not exist draws a **reset**, so the client sees the connection die although no server failed. Equal-cost multipath (ECMP) adds a second route to the same failure. Many routers hash a flow's header fields so one flow stays on one next hop, an implementation choice; RFC 2991 (Informational) notes that adding or removing a next hop still moves some flows, and with anycast each next hop can lead to a different holder. | Workload | Fit for anycast | Why | |---|---|---| | One-packet request and reply, such as a DNS query over UDP | good | no state outlives the exchange | | Short TCP exchanges | usually fine | a routing change inside a few seconds is unlikely | | Long-lived TCP or other stateful sessions | risky | every routing event can move live connections | ## Designing for it - **Keep routing stable** around holders: drain a holder before withdrawing its route, rather than letting live connections move. - **Keep connections short**, and make clients retry cleanly on a reset. - **Use anycast to find, unicast to stay**: answer the first request from the nearest holder, then give the client a unicast address for the long session. - **Share or rebuild state** across holders where sessions cannot be short. - Remember that anycast divides traffic by topology, not by capacity: the nearest holder takes whatever its catchment sends. ## Common confusions - "Anycast has a reserved prefix": it uses ordinary unicast space. - "Nearest means lowest latency": it means the routing metric. - "Anycast sends to every holder and takes the first reply": that would be multicast plus a race; anycast delivers each packet to one holder.
- Why must an IPv6 node not run Duplicate Address Detection on an anycast address?Because other holders legitimately answer for it. RFC 4862 says Duplicate Address Detection MUST NOT be performed on anycast addresses, and since they look exactly like unicast, the node must be configured to know which addresses are anycast. Otherwise its probe would hear another holder and declare the address a duplicate.
- How does Neighbor Discovery cope with several holders of one anycast address on the same link?RFC 4861 has every holder answer a Neighbor Solicitation with the Override flag clear and delay the answer randomly by up to `MAX_ANYCAST_DELAY_TIME`, one second. The first advertisement fills the asker's neighbour cache and later non-override ones do not replace it, so the asker sticks with one holder.
- On one link, how is reaching 'any one router' through anycast different from sending to all-routers?The Subnet-Router anycast address (the subnet prefix with a zero interface identifier) is delivered to one router on the subnet, and every router must support it. All-routers `ff02::2` is a multicast group, so every router on the link receives the packet. The first suits a request any router can answer; the second suits one every router must hear.
saying these in an interview costs you the question
- Anycast addresses come from a dedicated reserved prefix, so clients can spot them.
- A packet to an anycast address is copied to every holder and the fastest reply wins.
- Nearest means the holder with the lowest measured latency or the lightest load.
- Anycast holders must pass Duplicate Address Detection like any unicast address.
- Anycast is safe for any TCP service because a connection stays pinned to one server.