skip to content

IPv6

IPv6 brings 128-bit addresses, hosts that configure themselves from router advertisements, and a lean fixed header. Interviews focus on how it changes assumptions built around NAT, ARP and broadcast.

on this pageshow

questions

30

How is a 128-bit IPv6 address written as text, and what rules govern compressing it with :: in RFC 5952 canonical form?

level: juniorimportance: must knowfreq 62%

answer

  1. eight sixteen-bit groups
  2. leading zeros go, trailing stay
  3. one double colon only
  4. longest zero run, first on a tie
  5. never for a lone zero group

basics

~20 s

An IPv6 address is eight 16-bit hex groups separated by colons. RFC 5952 canonical form drops leading zeros, uses lowercase, and writes :: once, for the longest run of two or more zero groups, the first run on a tie.

solid answer

~40 s

An IPv6 address is 128 bits, written as eight 16-bit groups of one to four hex digits separated by colons. RFC 4291 lets you drop leading zeros inside a group and replace one run of all-zero groups with `::`, which may appear only once, because a parser could not otherwise tell how many groups each `::` hides. RFC 5952 then fixes one canonical output: lowercase, leading zeros always dropped, a zero group written `0`, `::` used to the maximum on the longest run of zero groups (the first if two runs tie), and never to shorten a single zero group. So `2001:0DB8:0000:0000:0001:0000:0000:0001` becomes `2001:db8::1:0:0:1`. Parsers must still accept every legal RFC 4291 form; the canonical rules govern what software writes.

go deeper

for a junior

Know the shape: eight 16-bit hex groups, leading zeros dropped, :: once for a run of zero groups. Expand and compress a couple of addresses by hand until it is automatic.

for a middle

Explain why :: may appear only once and apply all of RFC 5952's tie-breaks: longest run wins, first on a tie, never a single group, lowercase output.

for a senior

Separate what parsers must accept from what software should emit, and push teams to store and compare addresses as 128-bit values rather than strings in logs and inventories.

for a principal

Treat canonical form as a data-quality standard: inventory, logging and audit tooling across teams should emit RFC 5952 text so that searches, diffs and joins across systems agree.

## The 128 bits and the eight groups An **IPv6 address** is a 128-bit number. Written in full it is eight **groups** (RFC 4291 calls them 16-bit pieces) of four hexadecimal digits, separated by colons: `2001:0db8:0000:0000:0001:0000:0000:0001` Each hex digit is 4 bits, so each group is 16 bits and eight groups make 128. The text form exists for people, logs and configuration files: inside the packet header the address is always the full 128 bits, so compressing the text never changes what goes on the wire. ## What RFC 4291 allows RFC 4291 (the IPv6 addressing architecture) defines the legal text forms: - **Leading zeros** inside a group may be dropped: `0db8` can be written `db8`, `0001` can be written `1`. **Trailing** zeros may not: `cd30` is not `cd3`. - Every group must keep at least one digit, except where `::` stands in. - **`::`** means "one or more groups of zeros". It can compress leading zeros (`::1`), trailing zeros (`2001:db8::`) or a run in the middle. - `::` may appear **only once**. With two of them, as in `2001:db8::1::2`, the reader knows six groups are missing in total but not how they split, so the address is ambiguous and invalid. - Hex digits may be upper or lower case; RFC 4291 states no preference. That flexibility means one address has many legal spellings. RFC 5952 (2010) lists the damage: searches in spreadsheets and logs miss matches, configuration diffs show changes where none happened, and audit scripts need their own parsers. ## What RFC 5952 makes canonical RFC 5952 recommends one output form. Software SHOULD generate it, and every implementation MUST still accept any legal RFC 4291 form as input. | Rule (RFC 5952 section) | Correct | Not canonical | |---|---|---| | Leading zeros MUST be suppressed (4.1) | `2001:db8::1` | `2001:0db8::0001` | | A zero group is written `0` (4.1) | `2001:db8:0:1:1:1:1:1` | `2001:db8:0000:1:1:1:1:1` | | `::` is used to its maximum (4.2.1) | `2001:db8::2:1` | `2001:db8::0:2:1` | | `::` MUST NOT shorten a single zero group (4.2.2) | `2001:db8:0:1:1:1:1:1` | `2001:db8::1:1:1:1:1` | | The longest zero run gets `::` (4.2.3) | `2001:db8:0:1::1` | `2001:db8::1:0:0:0:1` | | On a tie, the first run gets `::` (4.2.3) | `2001:db8::1:0:0:1` | `2001:db8:0:0:1::1` | | Hex letters are lowercase (4.3) | `2001:db8::c0de` | `2001:DB8::C0DE` | Note the difference between "not canonical" and "invalid". `2001:db8::1:1:1:1:1` is a perfectly legal RFC 4291 address (the `::` hides one group); RFC 5952 only says a program must not print it that way. ## Worked compressions 1. `2001:0db8:0000:0000:0000:0000:0002:0001`: drop leading zeros, then one run of four zero groups becomes `::`, giving `2001:db8::2:1`. 2. `2001:0db8:0000:0001:0000:0000:0000:0001`: two zero runs, of one and three groups. The run of three wins, and the lone zero stays as `0`: `2001:db8:0:1::1`. 3. `2001:0db8:0000:0000:0001:0000:0000:0001`: two runs of two tie, so the first is compressed: `2001:db8::1:0:0:1`. 4. Expanding `2001:db8::8:800:200c:417a`: six groups are written, so `::` stands for two, giving `2001:0db8:0000:0000:0008:0800:200c:417a`. 5. The all-zero address is `::` (the unspecified address) and `0:0:0:0:0:0:0:1` is `::1` (loopback). A reliable method for expanding: count the written groups, subtract from eight, insert that many `0000` groups where `::` sits, then left-pad every group to four digits. ## Mixed notation, prefixes and ports - Addresses that embed an IPv4 address in their low 32 bits may end in dotted decimal. RFC 5952 section 5 recommends this for well-known embedding prefixes, with the leading hex part still canonical: `::ffff:192.0.2.1`, not `0:0:0:0:0:ffff:192.0.2.1`. - A **prefix** is written `address/prefix-length`, and the address part may use any legal form. The compression rules still bite: `2001:db8::cd30/60` puts `cd30` in the last group, not the fourth. - With a port number, RFC 5952 section 6 says the bracket style from URIs SHOULD be used: `[2001:db8::1]:443`. The form `2001:db8::1:443` is NOT RECOMMENDED, because the port reads as the last group. ## Why it matters in practice Treat addresses as 128-bit values and compare them as values. Canonical form is for what software writes: - **Logs**: one spelling per address means a plain text search finds every line about it. - **Configuration and inventories**: diffs show only real changes, not someone's preferred padding. - **Audits and joins across systems**: two tools that both emit RFC 5952 text agree without a custom parser. It is not a substitute for parsing what a user or a peer typed: input can arrive in any legal RFC 4291 form, and a program that compares raw strings will treat `2001:db8::1` and `2001:DB8:0:0:0:0:0:1` as different hosts.

  • Is 2001:db8::1:1:1:1:1 a valid IPv6 address, given that RFC 5952 forbids :: for a single zero group?
    Yes. RFC 4291 defines `::` as one or more zero groups, so it parses to `2001:db8:0:1:1:1:1:1`. RFC 5952 governs output: software should not generate that spelling, but it MUST accept any legal RFC 4291 form as input. Rejecting it would be a parser bug.
  • How do you write an IPv6 address together with a transport port number?
    Put the address in square brackets, as in `[2001:db8::1]:443`; RFC 5952 section 6 says this URI style SHOULD be used. Without brackets, `2001:db8::1:443` is ambiguous, because `443` reads as a final hex group and the `::` expands differently.
  • Does compressing an address with :: make IPv6 packets smaller?
    No. The source and destination fields in the IPv6 header are always 128 bits each. `::` and dropped leading zeros exist only in the text form that people and configuration files use; the binary address is identical however it is spelled.

saying these in an interview costs you the question

  • You can use :: twice if each zero run is short enough.
  • Trailing zeros in a group can be dropped just like leading zeros.
  • Canonical form compresses the first zero run even when a later run is longer.
  • A single zero group should become :: to save characters.
  • An address written in uppercase hex is invalid and must be rejected.
open as a page

What are the three IPv6 address types, how is a packet sent to each one delivered, and why is there no broadcast?

level: juniorimportance: must knowfreq 58%

basics

~20 s

IPv6 has unicast (delivered to one interface), multicast (delivered to every member of a group, ff00::/8) and anycast (delivered to the nearest of a set, using unicast-format addresses). Broadcast was dropped; scoped multicast groups such as all-nodes ff02::1 replace it.

open as a page

In IPv6, what replaces ARP for finding a neighbour's MAC address, and why does no broadcast take part?

level: juniorimportance: must knowfreq 50%

basics

~20 s

IPv6 Neighbor Discovery (RFC 4861) replaces ARP: a host sends an ICMPv6 Neighbor Solicitation to the target's solicited-node multicast address, and the target answers with a unicast Neighbor Advertisement carrying its MAC. IPv6 has no broadcast.

open as a page

Why can an IPv6-only host not talk directly to an IPv4-only host, and which three families of transition mechanism bridge the gap?

level: juniorimportance: must knowfreq 42%

basics

~20 s

IPv4 and IPv6 are separate protocols with different headers and address sizes, so neither stack can read the other's packets. Coexistence comes from dual stack (run both), tunnelling (carry IPv6 inside IPv4) or translation (NAT64 rewriting headers).

open as a page

Apart from the longer addresses, what are the main design differences between IPv6 and IPv4?

level: juniorimportance: must knowfreq 60%

basics

~20 s

IPv6 widens addresses to 128 bits and moves work off routers: a fixed 40-byte header with extension headers, no header checksum, source-only fragmentation, multicast instead of broadcast, Neighbor Discovery instead of ARP, built-in autoconfiguration, and no NAT in its base design.

open as a page

Reading only the leading bits of an IPv6 address, how do you tell loopback, link-local, unique local and global unicast apart?

level: middleimportance: must knowfreq 52%

basics

~20 s

The high-order bits identify the type: ::1 is loopback, fe80::/10 (fe80 to febf) is link-local, fc00::/7 (fc or fd, in practice fd00::/8) is unique local, and 2000::/3 (first digit 2 or 3) is where global unicast is allocated today.

open as a page

What are the eight fields of the fixed 40-byte IPv6 base header, and what job does each one do?

level: middleimportance: must knowfreq 45%

basics

~20 s

The IPv6 base header is always 40 bytes: Version, Traffic Class, Flow Label, Payload Length, Next Header and Hop Limit fill the first 8 bytes, and the 128-bit Source and Destination addresses fill the other 32.

open as a page

The IPv6 base header has no header checksum and no fragmentation fields, so what took over each of those jobs?

level: middleimportance: must knowfreq 40%

basics

~20 s

Error detection moved to link-layer frame checks and to TCP, UDP and ICMPv6 checksums over a pseudo-header with both addresses. Fragmentation moved into a Fragment extension header that only the source adds; routers send Packet Too Big instead of splitting.

open as a page

When a laptop joins an IPv6 LAN without DHCPv6, how does SLAAC give it a global address and a default router?

level: middleimportance: must knowfreq 45%

basics

~20 s

Under SLAAC (RFC 4862) the laptop forms a link-local address, proves it unique with duplicate address detection, solicits a Router Advertisement, then combines the advertised prefix with its own interface identifier; the advertising router becomes its default router.

open as a page

On an IPv6-only mobile network, how do NAT64 and DNS64 together let a phone reach a server that has only an IPv4 address?

level: seniorimportance: must knowfreq 33%

basics

~20 s

DNS64 answers the phone's AAAA query with a synthetic address that embeds the server's IPv4 address in a NAT64 prefix such as 64:ff9b::/96; the stateful NAT64 translates packets to that address into IPv4 from a shared address pool.

open as a page

Why is /64 the standard IPv6 subnet size, and how many /64 subnets does a /48 or a /56 site prefix contain?

level: middleimportance: should knowfreq 38%

basics

~20 s

RFC 4291 fixes a 64-bit interface ID for most unicast addresses, so a LAN subnet is /64. A site prefix holds 2 to the power (64 minus its length) of them: 65,536 in a /48, 256 in a /56.

open as a page

How is an IPv6 solicited-node multicast address derived from a unicast address, and why does such a group usually reach just one node?

level: middleimportance: should knowfreq 34%

basics

~10 s

Append the low-order 24 bits of the unicast or anycast address to ff02::1:ff00:0/104. Those bits come from the interface identifier, so normally only the node holding that address has joined the group.

open as a page

An IPv6 host interface holds a link-local, a stable global and a temporary global address; how does it pick a packet's source address?

level: middleimportance: should knowfreq 26%

basics

~20 s

RFC 6724's ordered rules run over the outgoing interface's addresses: match the destination's scope (link-local for link-scoped destinations, global for global ones), avoid deprecated addresses, then prefer the temporary over the stable address by default; longest matching prefix is the late tiebreaker.

open as a page

How does an IPv6 SLAAC host choose its interface identifier, and why did MAC-derived EUI-64 identifiers give way to stable-privacy and temporary addresses?

level: middleimportance: should knowfreq 30%

basics

~20 s

A SLAAC host chooses the low 64 bits itself. Legacy modified EUI-64 copied the MAC address, making the host trackable across networks; RFC 8064 now recommends RFC 7217's stable hashed identifiers, often alongside RFC 8981's short-lived random temporary addresses.

open as a page

In an IPv6 Router Advertisement, what do the M and O flags and the prefix option's A and L flags each tell a host?

level: middleimportance: should knowfreq 35%

basics

~20 s

In an IPv6 Router Advertisement, M says addresses are available from DHCPv6 and O says other settings such as DNS are; in each Prefix Information option, A permits SLAAC on that prefix and L says the prefix is on-link.

open as a page

When a dual-stack client resolves a name to both IPv6 and IPv4 addresses, how does Happy Eyeballs decide which one it connects over?

level: middleimportance: should knowfreq 30%

basics

~10 s

Happy Eyeballs v2 (RFC 8305) queries AAAA and A together, gives IPv6 a short head start, and then starts staggered connection attempts every ~250 ms across interleaved addresses, keeping the first that completes.

open as a page

How do the IPv6-over-IPv4 tunnels 6in4, 6to4, Teredo and ISATAP differ in finding the far end and crossing IPv4 networks?

level: middleimportance: should knowfreq 24%

basics

~20 s

6in4 is a manually configured tunnel over IP protocol 41; 6to4 derives the tunnel endpoint from a 2002::/16 address and needs relays; Teredo puts IPv6 in UDP to cross NAT; ISATAP tunnels inside one site.

open as a page

What changes in a service's own code and stored data when it starts accepting clients over IPv6?

level: middleimportance: should knowfreq 38%

basics

~20 s

Address handling: 16-byte addresses and longer text forms, bracketed literals before a port, and binary rather than string comparison. Client identity: no NAT, but rotating temporary addresses, so limits key on prefixes. Outbound calls may switch to IPv6 by default.

open as a page

A service blocks internal destinations with an IPv4-only deny list (127.0.0.0/8, 10.0.0.0/8, 169.254.0.0/16); which IPv6 address forms slip past it, and how should the check work?

level: seniorimportance: should knowfreq 24%

basics

~10 s

IPv6 loopback ::1, the unspecified ::, link-local fe80::/10, unique local fc00::/7 and IPv4-mapped forms such as ::ffff:127.0.0.1 all bypass it. Parse the address to 128 bits, unwrap mapped IPv4, then test the IPv6 blocks.

open as a page

IPv6 anycast addresses look exactly like unicast ones; how does the network deliver a packet to one, and what risks does a stateful TCP service behind one carry?

level: seniorimportance: should knowfreq 23%

basics

~20 s

An anycast address is a unicast-format address configured on several interfaces; routing delivers each packet to the nearest holder by its own metric. If routing changes mid-connection, later TCP segments can reach a holder with no state, which resets the connection.

open as a page

How does the IPv6 Next Header field chain extension headers together, and in what order does RFC 8200 recommend placing them?

level: seniorimportance: should knowfreq 20%

basics

~20 s

Each IPv6 header ends its job by naming the next one in its Next Header byte, until a value names the upper layer. RFC 8200 recommends Hop-by-Hop, Destination Options, Routing, Fragment, AH, ESP, Destination Options, then the upper layer.

open as a page

A device on an IPv6 LAN starts sending its own Router Advertisements; what happens to the other hosts, and how do RA Guard and SEND each stop it?

level: seniorimportance: should knowfreq 25%

basics

~20 s

Hosts trust any on-link Router Advertisement, so a rogue one can become their default router, add prefixes and push DNS servers. RA Guard (RFC 6105) drops RAs at switch ports; SEND (RFC 3971) signs them but is rarely deployed.

open as a page

Why can an IPv4-only firewall policy miss IPv6 traffic carried by 6in4, 6to4 or Teredo tunnels, and how would you bring it under control?

level: seniorimportance: should knowfreq 18%

basics

~20 s

Tunnels wrap IPv6 inside IPv4, so an IPv4 filter sees only protocol 41 or a UDP flow, never the inner IPv6 addresses and ports. Control means filtering those outer markers and giving IPv6 a policy of its own.

open as a page

When a service that sat behind an IPv4 NAT gains IPv6 addresses, what becomes reachable, and what must the design review add?

level: seniorimportance: should knowfreq 34%

basics

~20 s

IPv6 gives each host globally routable addresses with no translation, so every socket listening on all addresses becomes reachable from the internet. The review must add an explicit default-deny stateful policy for IPv6 and matching host rules for both families.

open as a page

How do IPv6's ban on router fragmentation and its 1,280-byte minimum MTU change path MTU handling compared with IPv4?

level: seniorimportance: should knowfreq 30%

basics

~20 s

IPv4 routers fragment oversized packets unless DF is set; IPv6 routers never do, so the sender alone must size packets from Packet Too Big feedback or probing. In return, every IPv6 link carries 1,280 bytes, a size that always fits.

open as a page

Since RFC 7872 measured widespread drops of IPv6 packets carrying extension headers, how would you set a border policy toward them, and should a new design rely on them?

level: principalimportance: should knowfreq 8%

basics

~20 s

Drop IPv6 extension headers only by deliberate per-type policy, as RFC 7045 requires: permit fragments and Destination Options, drop Routing type 0, limit transit Hop-by-Hop. A new design should use them only inside networks you control.

open as a page

Why does an IPv6 unique local prefix carry a pseudo-random 40-bit Global ID, and what goes wrong when every site simply uses fd00::/48?

level: middleimportance: nice to knowfreq 16%

basics

~20 s

RFC 4193 gives each site a pseudo-random 40-bit Global ID after fd so two sites' prefixes almost never match. Everyone choosing fd00::/48 recreates the ambiguity of deprecated site-local: merged networks and VPNs collide and must renumber.

open as a page

In an IPv6 multicast address, what do the flags and scope fields after the leading ff mean, and why do routers never forward ff02::1?

level: middleimportance: nice to knowfreq 18%

basics

~20 s

After ff come 4 flag bits (T=0 marks a permanent, IANA-assigned group) and 4 scope bits: 1 interface, 2 link, 5 site, 8 organization, e global. Routers must not forward multicast beyond its scope, so ff02 stays on-link.

open as a page

What is the 20-bit IPv6 Flow Label for, and what does RFC 6437 require of sources and forwarding nodes?

level: seniorimportance: nice to knowfreq 12%

basics

~20 s

The IPv6 Flow Label lets a source tag a flow so routers can recognise it from label and addresses, without parsing ports. RFC 6437: sources pick uniform-looking values or zero; forwarders leave non-zero labels alone and never hash on the label alone.

open as a page

On an IPv6-only network with NAT64 and DNS64, why do apps that use IPv4 literals still fail, and how does 464XLAT fix them?

level: seniorimportance: nice to knowfreq 12%

basics

~20 s

An IPv4 literal or IPv4-only socket never asks DNS, so DNS64 cannot help and the device has no IPv4 route. 464XLAT adds a stateless translator (CLAT) on the device that turns IPv4 into IPv6 for the network's stateful NAT64 (PLAT).

open as a page