Apart from the longer addresses, what are the main design differences between IPv6 and IPv4?
answer
- what routers stopped doing
- header shape and where options went
- who fragments, who resolves addresses
- no broadcast, no translation by design
basics
~20 sIPv6 widens addresses to 128 bits and moves work off routers: a fixed 40-byte header with extension headers, no header checksum, source-only fragmentation, multicast instead of broadcast, Neighbor Discovery instead of ARP, built-in autoconfiguration, and no NAT in its base design.
solid answer
~50 sThe headline is 128-bit addresses, but the design changes matter more. The base header is a fixed 40 bytes; options moved into extension headers chained by `Next Header`, and transit routers examine none of them except, when configured to, Hop-by-Hop Options. The header checksum is gone, so routers no longer recompute it after decrementing `Hop Limit`; integrity rests on the link layer and on upper-layer checksums. Routers never fragment: only the source does, with a Fragment header, and every link must carry at least 1,280 bytes. There is no broadcast, multicast does that job, and Neighbor Discovery over ICMPv6 replaces ARP, ICMP Router Discovery and ICMP Redirect. Hosts can configure themselves with SLAAC as well as DHCPv6 and usually hold several addresses. And because addresses are plentiful, the base design has no NAT: hosts are globally reachable, so filtering must be an explicit policy.
go deeper
Recall the list beyond address length: fixed 40-byte header, no checksum, source-only fragmentation, no broadcast, Neighbor Discovery instead of ARP, SLAAC, no NAT by design.
Explain why each change was made: removing per-hop checksum work, pushing fragmentation to the source with a 1,280-byte floor, replacing broadcast with multicast groups.
Translate each difference into an operational consequence: explicit inbound filtering, never blocking Packet Too Big, extension headers that middleboxes may drop.
Frame the contrast as a cost shift from routers to endpoints and policy, and say where that shift creates new failure modes an organisation must own.
## The short version **IPv6** (specified by RFC 8200, which obsoletes RFC 2460) is not "IPv4 with longer addresses". Its designers used the address change as a chance to remove per-packet work from routers, move rarely used features out of the common path, and fold several separate IPv4 helper protocols into one. RFC 8200 itself groups the changes as expanded addressing, header simplification, better support for extensions and options, flow labelling, and authentication and privacy extensions. | Aspect | IPv4 | IPv6 | |---|---|---| | Address size | 32 bits | 128 bits (RFC 4291 architecture) | | Base header | 20 to 60 bytes, options inline | fixed 40 bytes, options in **extension headers** | | Header checksum | yes, recomputed at every hop | none | | Who fragments | the source or any router (unless DF is set) | only the **source** | | Minimum link MTU | a router must forward 68-byte datagrams; hosts must accept 576 | **1,280 bytes** on every link | | One-to-all on a link | broadcast | **multicast** (no broadcast at all) | | Address resolution | ARP | **Neighbor Discovery** over ICMPv6 | | Host configuration | DHCP or manual | **SLAAC** and/or DHCPv6 | | Address translation | NAT is common at network edges | not part of the base design | ## What changed for routers Three things that every IPv4 router does per packet are gone or rare in IPv6: - **No header checksum.** In IPv4 the checksum covers the header, and because the TTL changes at every hop, every router has to verify and recompute it. IPv6 drops the field. Corruption is caught by the link layer's frame check and by the **upper-layer checksum**, which covers a pseudo-header containing both 128-bit addresses. - **No router fragmentation.** A router that cannot forward a packet because the next link is too small drops it and returns an **ICMPv6 Packet Too Big** message. Only the sending host may fragment, using a **Fragment extension header**. To make that workable, RFC 8200 requires every link to carry at least **1,280 bytes**. - **No options in the base header.** IPv4 options sit inside the header every router parses. IPv6 puts them in extension headers linked by the `Next Header` field. Transit nodes do not process them, with one exception: **Hop-by-Hop Options**, which RFC 8200 now expects routers to examine only if they are configured to. ## What changed on the link - **No broadcast.** RFC 4291: "There are no broadcast addresses in IPv6, their function being superseded by multicast addresses." Hosts listen only to the groups that concern them, rather than every host processing every broadcast. - **Neighbor Discovery replaces ARP.** RFC 4861 describes Neighbor Discovery as the combination of the IPv4 protocols ARP, ICMP Router Discovery and ICMP Redirect. It runs over ICMPv6, so it is an IP-layer protocol, not a separate EtherType like ARP. It also adds Neighbor Unreachability Detection, for which IPv4 has no generally agreed mechanism. - **Autoconfiguration is built in.** With **SLAAC** (RFC 4862) a host builds its own global address from a prefix that routers advertise, without a server. DHCPv6 (RFC 8415) still exists for networks that want managed assignment. ## What changed for addressing and reachability - **128-bit addresses** allow every device a globally unique address, and an interface normally carries several at once: a link-local address (always) plus one or more global ones. - **No NAT in the base design.** IPv4 ran out of addresses and NAT became the default edge. IPv6 has no shortage, so the architecture assumes end-to-end addressing. The consequence for operators is that the accidental "no unsolicited inbound" behaviour of a NAT disappears: protection must come from an explicit **stateful filter**. ## What did not change 1. Delivery is still best effort and connectionless; TCP, UDP and the applications above them work the same way. 2. The hop counter remains. IPv4's TTL was nominally in seconds; RFC 8200 renamed it **Hop Limit** because IPv6 does not require enforcing a packet lifetime, and IPv4 implementations had treated TTL as a hop count anyway. 3. DNS keeps working, with **AAAA** records (RFC 3596) carrying IPv6 addresses. 4. **IPsec** is not mandatory. Early IPv6 node requirements mandated implementing it; RFC 6434 made it a SHOULD and RFC 8504 keeps that, and implementing it never meant traffic was protected without configuration. ## How to use this in an interview Lead with what changes for a running service: hosts become reachable without NAT, so firewall policy must be deliberate; ICMPv6 Packet Too Big becomes essential because routers no longer fragment; there is no broadcast and no ARP to reason about on the link. Then name the mechanisms behind each point. That framing shows you understand the protocol as a design, not as a list of field widths.
- Is IPv6 more secure than IPv4 because IPsec is built in?No. Early IPv6 node requirements mandated implementing IPsec; RFC 6434 relaxed that to a SHOULD and RFC 8504 keeps it. Implementing is not using: packets are protected only where IPsec is configured. IPv6's real security differences are global reachability without NAT, so filtering must be explicit, and a new link-layer attack surface in Neighbor Discovery and Router Advertisements.
- Does IPv6 still have a time-to-live field?Yes, as `Hop Limit`. Each forwarding node decrements it by one and discards the packet when it reaches zero, sending ICMPv6 Time Exceeded. RFC 8200 renamed it because IPv6 does not require enforcing a maximum packet lifetime in seconds, and IPv4 implementations had treated TTL as a hop count in practice.
- Do TCP and UDP behave differently over IPv6?The protocols are the same, but their checksums cover a pseudo-header with the 128-bit addresses, which is now the only integrity check over those addresses. Because of that, the UDP checksum is required by default over IPv6, and ICMPv6, unlike ICMPv4, also includes the pseudo-header.
saying these in an interview costs you the question
- IPv6 is just IPv4 with longer addresses.
- IPv6 routers fragment oversized packets the way IPv4 routers can.
- IPv6 hosts resolve neighbours by broadcasting, just as ARP does.
- IPv6 is secure by default because every packet uses IPsec.
- An IPv6 network still needs NAT to protect its hosts.