Worked example · IPv6 · nibble aligned
IPv6 /48 → /56 → /64 Example
One /48 split into 256 /56 site blocks, each holding 256 /64 LANs. The table lists the first and last /64 of every site, so each site can be delegated as its own block.
The hierarchy
Showing the first 16 of 256 sites. Last site: 2001:db8:acad:ff00::/56.
How the split works
A /48 has 80 host bits, 16 of which are before the /64 boundary: 216 = 65,536 /64 LANs. Choosing /56 for the site level splits those 16 bits into 8 for the site and 8 for the LAN, giving 256 sites of 256 LANs. Every boundary is a multiple of 4, so the plan reads directly from the hex digits:
2001:0db8:acad:0000:0000:0000:0000:0000 site 0, /56 2001:0db8:acad:0000:0000:0000:0000:0000 first /64 of site 0 2001:0db8:acad:00ff:0000:0000:0000:0000 last /64 of site 0 2001:0db8:acad:ff00:0000:0000:0000:0000 last site, /56
- Site 0 is
2001:db8:acad::/56, holding2001:db8:acad::/64through2001:db8:acad:ff::/64. - The last site is
2001:db8:acad:ff00::/56, holding the final 256 /64s up to2001:db8:acad:ffff::/64. - Reverse DNS delegates in 4-bit steps: the /48 is one
ip6.arpazone, and each /56 or /64 can be delegated from it without splitting a nibble.
Ordinary LANs stay at /64 because SLAAC assumes a 64-bit interface ID (RFC 4862, analysed in RFC 7421). Router links can use /127 (RFC 6164) and loopbacks /128, but those are separate small blocks, not part of the site plan. RFC 6177 is the reason the site level here is /56 rather than handing each site a single /64.
Inspect a block in the IPv6 tools, or read the full walk-through in IPv6 subnetting. For IPv4 planning with host counts, see the AWS three-tier example.
Questions
How many /64 LANs are in a /48?
65,536. A /48 leaves 16 bits before the /64 boundary, and 216 = 65,536. Splitting the same /48 into /56 sites gives 256 sites with 256 /64s each.
Why use /56 for a site instead of /48?
RFC 6177 recommends giving an end site at least a /56 rather than a single /64. A /56 holds 256 /64 LANs, which fits most buildings and homes, and it stays on a nibble boundary for reverse DNS delegation.
Why must a LAN stay at /64?
SLAAC assumes a 64-bit interface ID, and RFC 7421 lists the features that break with other LAN sizes. Routed links can be /127 and loopbacks /128, but ordinary LANs are /64.
What is the reverse DNS zone for this plan?
Write the /48 as nibbles, reverse them and add ip6.arpa: 2001:db8:acad::/48 becomes d.c.a.8.b.d.0.1.0.0.2.ip6.arpa. Each /56 or /64 site delegates its own zone from that point because every level is nibble aligned.