An IPv6 host interface holds a link-local, a stable global and a temporary global address; how does it pick a packet's source address?
answer
- an ordered list of rules
- scope of the destination first
- deprecated loses to preferred
- temporary beats public by default
- longest prefix comes last
basics
~20 sRFC 6724's ordered rules run over the outgoing interface's addresses: match the destination's scope (link-local for link-scoped destinations, global for global ones), avoid deprecated addresses, then prefer the temporary over the stable address by default; longest matching prefix is the late tiebreaker.
solid answer
~40 sHolding all three is normal: RFC 4291 lets one interface carry many addresses, and RFC 6724 (which obsoletes RFC 3484) chooses the source. The candidates are the unicast addresses on the outgoing interface, compared pairwise by ordered rules. **Rule 2** prefers the smallest scope that still covers the destination, so `fe80::1` gets the link-local source and a global destination gets a global one. **Rule 3** avoids deprecated addresses. **Rule 6** prefers a matching policy label, which pairs unique local sources with unique local destinations. **Rule 7** prefers the **temporary** address over the stable one by default; an application can reverse that, and an implementation may default the other way. **Rule 8**, longest matching prefix, comes last. In practice a client's new outbound connections show its temporary address, which changes over time.
go deeper
Recall that an IPv6 interface normally holds several addresses at once, including a mandatory link-local one, and that a link-local destination gets a link-local source.
Walk through RFC 6724's order: appropriate scope, avoid deprecated, matching label, prefer temporary, longest prefix last, and show which rule decides each destination.
Connect the rules to incidents: allowlists that miss rotating temporary addresses, connections that outlive deprecation, and hosts on different systems choosing different defaults.
Set the policy for a fleet: privacy from temporary addresses on clients against stable, auditable sources for servers and partner links, and decide where that preference is configured.
## One interface, several addresses at once RFC 4291 requires a link-local address on every interface and allows any number of others. A typical host on the link `2001:db8:0:7::/64` holds: | Address | Kind | Purpose | |---|---|---| | `fe80::1c4b:72e9:a05d:3f18` | link-local | traffic on this link only: neighbours, the router | | `2001:db8:0:7:6e2a:91d4:c837:5b5e` | stable global | a long-lived address others can reach the host at | | `2001:db8:0:7:d3e0:5b19:a2c4:7f01` | temporary global (RFC 8981) | outbound connections, replaced periodically for privacy | The interface has also joined several multicast groups, but multicast addresses and the unspecified address `::` are never source candidates. How the stable and temporary interface identifiers are generated is autoconfiguration's business; the question here is which address goes into the Source Address field. ## The candidate set RFC 6724 recommends that the candidates be the unicast addresses assigned to the **outgoing interface**, the one the route to the destination uses. For a link-local or multicast destination, candidates must come from interfaces on that same link. The algorithm then compares candidates two at a time with ordered rules: - a rule that produces a winner discards the losers; - a tie passes the tied addresses on to the next rule; - if every rule ties, the final tiebreaker is implementation-specific. ## The rules, in order 1. **Prefer the same address**: if a candidate equals the destination, use it. 2. **Prefer appropriate scope**: the smallest scope that is still at least the destination's scope. 3. **Avoid deprecated addresses**: a "preferred" address beats a deprecated one, in RFC 4862's sense. 4. **Prefer home addresses**: relevant only to Mobile IPv6. 5. **Prefer the outgoing interface** (and, as Rule 5.5 for implementations that track it, a prefix advertised by the chosen next hop). 6. **Prefer a matching label** from the policy table. By default `fc00::/7` has label 13 and `::/0` label 1, so unique local talks to unique local and global to global. 7. **Prefer temporary addresses** over public (stable) ones. 8. **Use the longest matching prefix**, counted only up to the source's prefix length, so the interface identifier never counts. ## Three destinations, worked | Destination | Winning source | Deciding rule | |---|---|---| | `fe80::1` (the router's link-local address) | `fe80::1c4b:72e9:a05d:3f18` | Rule 2: both global addresses are wider than needed | | `2001:db8:5::80` (a remote web server) | `2001:db8:0:7:d3e0:5b19:a2c4:7f01` | Rule 2 removes link-local; Rule 7 picks temporary | | the same server, temporary address now deprecated | `2001:db8:0:7:6e2a:91d4:c837:5b5e` | Rule 3: avoid the deprecated address | | `ff02::2` (all-routers, link scope) | `fe80::1c4b:72e9:a05d:3f18` | Rule 2: a link-scoped group needs only a link-local source | | `ff05::2` (all-routers, site scope) | a global address | Rule 2: link-local is smaller than the destination's site scope | For a multicast destination, the scope compared in Rule 2 is the one in the group's own scope field, which is why the same all-routers group gets a different source at link scope and at site scope. The same RFC also defines a second algorithm that orders a list of destination addresses, for example a name that resolves to both IPv6 and IPv4; that one decides which destination to try, not which source to use. ## What this means in production - **Allowlists keyed on a source address** break quietly. A client's outbound connections normally come from its temporary address, which RFC 8981 replaces regularly: by default it caps the preferred lifetime at one day and the valid lifetime at two days, both tunable, the latter down from RFC 4941's seven days. Allow the prefix, or make that client prefer its stable address. - **Existing connections survive deprecation.** RFC 4862 says a deprecated address should keep serving existing communications; only new ones move. A connection dies only when the address's valid lifetime ends and the address is removed. - **Applications can reverse Rule 7.** RFC 6724 requires a per-application mechanism, and lets an implementation default to public addresses when compatibility outweighs privacy, so two operating systems may legitimately choose differently. - **Rule 8 rarely decides between globals on one /64.** Both candidates share the same 64-bit prefix and the count stops there, so they tie on it; in practice Rule 3 or Rule 7 has already chosen between them. ## Common confusions - "The link-local address is the primary one": it wins only for link-local unicast and link-scoped multicast destinations. - "The first address configured wins": configuration order is at most the implementation-specific tiebreaker after every rule has tied. - "Longest prefix match decides everything": it is the last rule, after scope, deprecation, labels and the temporary preference.
- A long-lived TCP connection was opened from a temporary address that has since become deprecated; does it break?No. RFC 4862 says a deprecated address SHOULD continue to be used for existing communications; RFC 6724's Rule 3 only steers new source choices. The connection breaks only when the address's valid lifetime ends and it is removed, which under RFC 8981's default is at most two days after creation, down from seven in RFC 4941.
- Why does RFC 6724 require a way for an application to reverse the temporary-address preference?Rule 7 exists for privacy, but temporary addresses are short-lived and their reverse lookups may fail or return random names, which breaks applications that need a stable identity. So RFC 6724 requires a per-application override, and lets an implementation default to public addresses when compatibility outweighs privacy.
- If the host also holds a unique local address, which source does a global destination get?The global one, by Rule 6. RFC 6724's default policy table labels `fc00::/7` as 13 and `::/0` as 1; a global destination carries label 1, so the global source matches and the unique local one does not. A unique local destination gets the unique local source for the same reason.
saying these in an interview costs you the question
- An IPv6 host always sends from its link-local address, the primary one.
- The first address configured on the interface is always chosen as source.
- A deprecated address stops working at once, killing its open connections.
- By RFC 6724's default, temporary addresses are used only when an application asks.
- Longest-prefix match is the first rule applied when choosing a source.