Why you should move to IPv6, and how to do it

IPv6 dual stack is the safe approach, and the most widely recommended and used, for migrating networks to IPv6 — but it is only an interim step toward the end goal of IPv6 single stack, or IPv6-only. Many IPv4-only systems still exist on the internet today, so do we have to wait for the whole internet to move to dual stack before moving our own systems to single stack? And what is the answer for migrating to IPv6-only?

1. What is IPv6-only?

IPv4 and IPv6 differ in more than address length (32 bits versus 128 bits) — they differ in message structure, operating mechanics and technical features. Systems running IPv4 cannot be moved to IPv6 simply by swapping IPv4 addresses for IPv6 ones; the change requires study, planning, and upgrades to equipment, protocols and applications. Migrating to IPv6 takes significant effort, time and investment. A number of technical approaches have been proposed to simplify it, falling into three main groups: tunneling, address translation (NAT) and dual stack.

Dual-Stack is the most widely used solution in practice because it requires no changes to existing systems, causes no service disruption, can be rolled out in phases, and lets technical teams adopt IPv6 with ease. Migrating systems from Dual-Stack to IPv6-only is also considered simpler and more convenient than other approaches.

Figure 1: The stages of migrating from IPv4 to IPv6

Figure 1: The stages of migrating from IPv4 to IPv6

There are three phases in the transition from IPv4 to full IPv6. The approaches described above are typically deployed during the middle stage, as shown in the diagram. Experts do not want that stage to drag on; the aim is to move quickly into the late stage, running IPv6 alone. The middle stage is also called the IPv6 introduction stage, because IPv4 remains in place while IPv6 is rolled out. The late stage is also called the IPv6-only stage. Moving to IPv6-only is the best — and the only — way to remove the limitations of IPv4 and take advantage of what IPv6 offers.

IPv4 range used in an IPv6-only network

Figure 2: IPv4 range used in an IPv6-only network

Many networks on the internet are still IPv4-only, and some networks still contain IPv4-only devices, so even after migrating to IPv6-only a network will still have equipment running IPv4. For example, the border routers of an IPv6-only network will handle both IPv4 and IPv6 through NAT64; and when a mobile device shares Wi-Fi with other devices (tethering), if those devices are IPv4-only then NAT46 has to be used.

2. Why move to IPv6-only?

IPv4 address exhaustion was the original reason for IPv6, the protocol described in RFC 1883 in December 1995. As IPv6 was refined and extended, related protocols developed alongside it: ICMPv6, NDP, SLAAC, MLD, DHCPv6, NPTv6, DNS64, NAT64, 6LoWPAN and others. Together these gave IPv6 a range of capabilities that IPv4 does not have.

Figure 3: Comparing the IPv4 and IPv6 packet headers

Figure 3: Comparing the IPv4 and IPv6 packet headers

The IPv6 packet structure is leaner and better optimized — fewer fields and a fixed 40-byte header — so IPv6 packets are processed considerably faster. With 128-bit addressing, the address ranges allocated to agencies and organizations are larger, which keeps the global routing table smaller and removes the need for NAT. The extension header structure also improves IPv6's security capabilities.

Here are the benefits IPv6 offers over IPv4.

Figure 4: Benefits of the IPv6 protocol

Figure 4: Benefits of the IPv6 protocol

Beyond the benefits of IPv6 itself, moving from dual-stack to IPv6-only brings further significant benefits:

  • Ending IPv4 dependency: Running both IPv4 and IPv6 keeps a system dependent on IPv4 addresses. IPv4 addresses are increasingly exhausted, and this shortage will prevent a system from scaling or growing, and can even bring it to a halt. Moving to IPv6-only resolves all of IPv4's limitations completely and immediately.
  • Simpler operations and system management: instead of managing both protocols at once, running IPv6 alone significantly reduces complexity in planning, management, monitoring and troubleshooting. Operational errors are also reduced.
  • Optimizing performance and device resources: once IPv4 entries are no longer needed, routing tables become leaner, the mechanisms for converting between the two protocols are no longer used, and protocols and services become lighter overall. With all of a device's resources dedicated to IPv6, performance improves and processing is faster.
  • Improved security: instead of managing security for both IPv4 and IPv6, security work focuses on IPv6 alone. IPv4-related security issues are eliminated entirely, and IPv6's own security mechanisms can be put to use.
  • Ready for the Internet's growth: beyond solving today's problems, a full move to IPv6 prepares the network for the next generation of the Internet, in which IPv4 becomes obsolete and can no longer meet demand. IPv6 not only expands the address space but also supports the growth of technologies such as IoT, 5G/6G, blockchain and other emerging services.

3. IPv6-only deployment worldwide: the reality and the trend

The points above address only the technical side of IPv6-only. On the policy side, in November 2016 the Internet Architecture Board (IAB) announced that new technologies would no longer be required to support IPv4. On 1 June 2016, Apple began requiring apps submitted to the App Store to support IPv6-only operation. On the technology side, several newer technologies work only over IPv6 — SRv6, and the Matter and Thread standards for IoT, among others.

Retiring IPv4 and moving to IPv6-only is therefore an inevitable direction and an important step in modernizing the network infrastructure of organizations, businesses and the Internet as a whole.

Figure 5: Introducing IPv6+

Figure 5: Introducing IPv6+

It did not stop there: in 2020 a new concept emerged — IPv6+, or IPv6 Enhanced. Where IPv6 expands the address space, streamlines operation and improves network performance, IPv6+ builds on IPv6 and combines it with newer technologies to simplify operations, improve network quality (SLA), reduce latency and increase network programmability. Segment Routing over IPv6 (SRv6), for example, makes IPv6 networks more automated and more intelligent.

Figure 6: Goals of IPv6+

Figure 6: Goals of IPv6+

IPv6+ is regarded as an upgrade to IPv6, intended to modernize IP networks for the era of 5G, cloud and IoT. Moving to IPv6-only is the precondition for deploying IPv6+ solutions.

In practice, a number of organizations and companies have already led the way on IPv6-only, notably the operators T-Mobile (US), Jio (India), Sunrise (Switzerland), SK Telecom (Korea), Telstra (Australia) and NTT DOCOMO (Japan), along with companies including Cisco, LinkedIn, Facebook and Microsoft. Several countries have also set plans to retire IPv4. In the United States, the government has required all public agencies to complete at least 80% of their IPv6-only deployment plans by the end of 2025. The Chinese government has likewise planned to move all domestic networks entirely to IPv6-only by the end of 2030.

4. Which technical solutions exist for IPv6-only?

Moving to IPv6-only is not straightforward. It requires careful preparation and planning, including infrastructure upgrades, engineering training, updates to software, applications and management policies, and contingency plans for connectivity problems with IPv4-only systems. The migration approach also has to fit each organization's existing systems and service types. In practice, a number of technical approaches have been deployed, focused on three main groups: enterprises, fixed broadband (FBB) operators and mobile broadband (MBB) operators. Even so, real-world deployment has shown that only a few of these approaches are well regarded and widely adopted.

Figure 7: Technologies for moving fixed networks to IPv6-only

Figure 8: Technologies for migrating mobile networks to IPv6-only

Figure 8: Technologies for migrating mobile networks to IPv6-only

The technical solutions businesses favor are DNS64 and NAT64. Mobile operators deploy Dual-Stack in the initial phase and apply 464XLAT when migrating to IPv6-only. Fixed-line operators have more options for IPv6-only, such as 6RD or DS-Lite, with DS-Lite being the most widely used — particularly on cable networks running DOCSIS technology.

The next section gives an overview of the common technical approaches to migrating networks to IPv6-only operation.

DNS64/NAT64 technique:

A DNS64 server resolves domain names and can modify the result returned to the DNS client. When an IPv6-only host sends a name resolution request for an AAAA record to DNS64, the server forwards the IPv6 address query to external DNS; if no IPv6 address comes back, it then queries for the IPv4 address (the A record). On receiving an IPv4 address, the DNS64 server converts it to hexadecimal and synthesizes it with a predefined NAT64 prefix to form a synthesized IPv6 address, which it returns to the host. The host then sends its packets to the NAT64 device, where both the source and destination IPv6 addresses are translated to IPv4 for forwarding to the external IPv4-only destination.

Figure 9: How DNS64/NAT64 works

Figure 9: How DNS64/NAT64 works

Dual-Stack Lite technique (DS Lite):

This solution is widely used by fixed-line network operators, where the operator's infrastructure runs entirely on IPv6-only. Two key devices are involved: a customer-premises device with B4 (Basic Bridging Broadband) capability, and an edge router supporting AFTR (Address Family Translation Router).

The B4 CPE assigns private IPv4 and IPv6 addresses to devices on the customer's home network and establishes an IPv6 tunnel to the AFTR. All IPv4 packets are encapsulated in IPv6 and sent through the tunnel to the AFTR router. The AFTR then translates the private IPv4 source address to a public IPv4 address and forwards the traffic to external IPv4-only devices. The B4 CPE also acts as a DNS proxy for name resolution.

Figure 10: How DS-Lite works

Figure 10: How DS-Lite works

464XLAT technique:

In some cases DNS64/NAT64 cannot be used. For example, some applications address an IPv4 destination directly (an IPv4 literal) instead of a domain name, so DNS64 is never involved. On mobile networks, when a phone acts as a Wi-Fi hotspot it hands out only IPv4 addresses to the connecting devices, so NAT64 is not used either, because the source addresses of those devices are IPv4. 464XLAT was developed to overcome the limitations of DNS64/NAT64 and is typically deployed on mobile operator networks; some fixed-line operators use it as well.

The 464XLAT solution has two main components: CLAT (customer-side translator) and PLAT (provider-side translator). CLAT translates private IPv4 source addresses to IPv6 (NAT46) on a 1:1 basis, which is why it is called stateless NAT. PLAT translates both IPv6 source and destination addresses to IPv4 (NAT64) on an N:1 basis, mapping many IPv6 source addresses to a single IPv4 address, which is why it is called stateful NAT.

Figure 11: How 464XLAT works

Figure 11: How 464XLAT works

464XLAT operates as follows:
– IPv6-to-IPv6 connections: the end device does not need CLAT or PLAT.

– IPv6-to-IPv4 connections: CLAT translates the destination IPv4 address into an embedded IPv6 address (via the NAT64 Prefix) without needing DNS64. The DNS64 server here is used only to automatically advertise the NAT64 Prefix to CLAT (by sending an AAAA query for “ipv4only.arpa” to the DNS64 server). PLAT translates both the source and destination addresses from IPv6 to IPv4.

– IPv4-to-IPv4 connections: the end device is normally assigned a /64 IPv6 prefix rather than a single IPv6 address. From that /64, CLAT derives a /96 range used to translate the private IPv4 source address into IPv6. CLAT also uses the NAT64 prefix to translate the IPv4 destination address into IPv6 before forwarding the packet to PLAT. PLAT then translates both the source and destination IPv6 addresses back to IPv4.

There are therefore several different approaches to migrating networks to IPv6-only. All of them still allow connectivity to IPv4-only networks, and some even support IPv4-only devices. The IPv4 retained in these approaches is usually private IPv4, so very little public IPv4 space is consumed and dependence on public IPv4 is reduced.

5. IPv6-Only city model

Xiong'an New Area reflects the Chinese government's determination to build a model city of the future along modern, technology-first lines. The city was designed around IoT, artificial intelligence, big data and cloud computing, and notably deployed IPv6-only network infrastructure from the outset. One of its stated goals, for example, is to design and deploy roughly one million IoT devices per square kilometer.

The city has eliminated the complexity and limitations of the Dual-Stack mechanism by deciding to deploy IPv6-only entirely. To ensure connectivity with external IPv4-only systems, a centralized IPv4-IPv6 transition system has been deployed at the edge of the city's network infrastructure.

Figure 12: The IPv6-only network infrastructure model in Xiong'an

SRv6 technology is also applied to 5G networks and citywide optical network infrastructure to optimize operations and enable virtual private networks (VPN) or network slicing without relying on the overlay network technologies in use today, such as MPLS, RSVP, and VXLAN.

Data center, cloud computing and edge computing systems all run IPv6 exclusively. Externally facing services still run dual-stack.

Because the entire system uses IPv6 and nothing else, deploying IPSec to strengthen security is more straightforward. This matters particularly where there are millions of IoT devices per square kilometer, and securing data transmission is a mandatory requirement.

For address planning purposes, the city of Hung An was allocated an IPv6 /28 block, equivalent to more than 1 million /48 subnets or more than 256 million /56 subnets. That address supply is enough for every device to be assigned an IPv6 address, so NAT is no longer needed, network and service quality improve, and the system is easier to expand later.
Having decided to deploy IPv6-Only across its network infrastructure from the outset, Hùng An is a model worth learning from and replicating elsewhere. Its success will hopefully do a great deal to drive IPv6-Only deployment worldwide in the period ahead.

6. Conclusion

Taken together, the points above show that the move to IPv6-only is now gathering real momentum worldwide. The benefits and simplicity of IPv6-only are the main drivers, alongside expectations for what IPv6+ will make possible. The shift is expected to accelerate sharply between 2025 and 2030, driven by government commitments, by the maturity of the technology, and by organizations' confidence in the effectiveness of IPv6-only and in the infrastructure it provides for future technologies and services.

In Vietnam, the “National Digital Transformation Program to 2025, with orientation to 2030” under Decision No. 749/QĐ-TTg sets out a clear task: “convert the entire Vietnamese internet to the new-generation Internet Protocol (IPv6)”. Under Decision No. 38/QĐ-BTTTT, the IPv6 For Gov program also requires state agencies to complete their IPv6 migration, trial pure IPv6 (IPv6-only) technology, and be ready to deploy IPv6-only from 2025.

Vietnam's approach to IPv6 migration is broadly in step with the rest of the world: many domestic organizations and companies have moved, or are moving, to dual stack, and some infrastructure and services are already IPv6-only ready. To prepare for commercial 5G, 6G research and development, and wider adoption of IoT and cloud computing, Vietnam needs to concentrate on researching and trialling IPv6-only and IPv6+, and to set a roadmap for the move to IPv6-only in the 2026–2030 period.

Similar Posts