IPv6 subnetting

IPv6 subnetting is the same prefix arithmetic as IPv4, on 128-bit addresses written in hex. This page covers notation, the /64 rule, nibble-aligned plans for a /48 site, point-to-point links and EUI-64, with worked examples you can open in the calculator.

01Address format and RFC 5952 short form

An IPv6 address is 128 bits, written as eight 16-bit groups separated by colons. Each group, a hextet, is four hex digits.

2001:0db8:0000:0000:0001:0000:0000:0001
  1    2    3    4    5    6    7    8    hextet

RFC 4291 allows several text forms for one address. RFC 5952 defines a single canonical form, so configs, logs and tools print the same string:

  1. Drop leading zeros in each hextet. 0db8 becomes db8, and 0000 becomes 0.
  2. Replace one run of two or more zero hextets with ::. Only once: with two, the length of each gap would be ambiguous.
  3. Compress the longest run. If two runs are equally long, compress the first.
  4. Do not use :: for a single zero hextet. Write 0.
  5. Write the hex digits a to f in lowercase.

Worked example. Start with 2001:0db8:0000:0000:0001:0000:0000:0001. Dropping leading zeros gives 2001:db8:0:0:1:0:0:1. Two runs of zeros remain, hextets 3–4 and 6–7. They are equally long, so the first is compressed: 2001:db8::1:0:0:1.

Full formRFC 5952 formRule applied
2001:0db8:0000:0000:0000:ff00:0042:83292001:db8::ff00:42:8329Leading zeros, one run of three
2001:0db8:0000:0000:0001:0000:0000:00002001:db8:0:0:1::The run of three wins over the run of two
2001:0db8:0000:0001:0001:0001:0001:00012001:db8:0:1:1:1:1:1A single zero hextet stays 0
2001:DB8::A2001:db8::aLowercase

To expand, fill :: with as many zero hextets as are missing from eight. 2001:db8:abcd:12::1 shows five hextets, so :: stands for three: 2001:0db8:abcd:0012:0000:0000:0000:0001. The IPv6 tools page compresses and expands addresses. With a port, use brackets: [2001:db8::1]:443.

02Prefix lengths and the /64 rule

As in IPv4, /n means the first n bits identify the network. There is no dotted netmask; you always write the prefix length.

A LAN is a /64: a 64-bit network prefix, then a 64-bit interface identifier (IID) that names one interface on the link.

2001:0db8:abcd:0012:0000:0000:0000:0001
|---- 64 bits ----| |---- 64 bits ----|
  network prefix       interface ID

The address 2001:db8:abcd:12::1/64 sits in 2001:db8:abcd:12::/64. That network runs from 2001:db8:abcd:12:: to 2001:db8:abcd:12:ffff:ffff:ffff:ffff: 264 = 18,446,744,073,709,551,616 addresses. There is no broadcast address, and this site counts every address in the prefix as usable.

Why 64? RFC 4291 requires 64-bit interface IDs for unicast addresses, except those that start with binary 000. The practical reason is SLAAC, stateless address autoconfiguration (RFC 4862). A router advertises a prefix, and each host appends its own 64-bit interface ID, with no DHCP server. RFC 4862 tells a host to ignore the prefix if prefix length plus interface ID length is not 128 bits. On Ethernet the interface ID is 64 bits, so SLAAC only works on a /64.

RFC 7421 analyses the 64-bit boundary and lists what would break if LANs used longer prefixes. Longer prefixes are normal where hosts do not autoconfigure: /127 on router links and /128 on loopbacks, covered in section 07.

03A typical hierarchy

Address space is delegated in blocks, each carved from the one above it:

/32  2001:0db8:0000:0000:0000:0000:0000:0000   ISP allocation from an RIR
/48  2001:0db8:abcd:0000:0000:0000:0000:0000   one site
/56  2001:0db8:abcd:1200:0000:0000:0000:0000   one building, or one home
/64  2001:0db8:abcd:1234:0000:0000:0000:0000   one LAN

In RFC 5952 form these are 2001:db8::/32, 2001:db8:abcd::/48, 2001:db8:abcd:1200::/56 and 2001:db8:abcd:1234::/64. A regional internet registry (RIR) allocates an ISP a /32 or more. The ISP assigns a /48 to each business site and usually a /56 or /60 to a home. RFC 6177 dropped the older rule that every end site gets a /48, but kept its goal: an end site should get room for many subnets and for growth.

The table shows how many /64 LANs each prefix holds. Every 4 bits added to the prefix length divide the count by 16: a /32 holds 4,294,967,296 /64s, a /48 holds 65,536, a /56 holds 256 and a /60 holds 16. /112 and /126 are listed because they still appear in existing configs.

Prefix/64 subnetsAddressesCommon use
/324,294,967,296296Typical RIR allocation to an ISP
/4016,777,216288Large customer or regional block
/441,048,576284Mid-size organisation
/4865,536280One site (RFC 6177 guidance)
/524,096276Building or campus zone
/56256272Home or small office from an ISP
/6016268Smallest common delegation to a home
/641264One LAN / VLAN (SLAAC needs /64)
/112—65,536Sometimes used to save space on infrastructure
/126—4Point-to-point (avoid; prefer /127)
/127—2Point-to-point link (RFC 6164)
/128—1Single address (loopback, anycast)

04Subnetting on nibble boundaries

One hex digit is 4 bits, a nibble. A prefix length that is a multiple of 4 ends between two hex digits, so the boundary is visible in the text. /48, /52, /56, /60 and /64 are nibble boundaries, and a plan built from them reads without binary.

Worked example: split 2001:db8:abcd::/48 into /52s. Going from /48 to /52 borrows 4 bits, the first hex digit of the fourth hextet. 24 = 16 subnets, one per value of that digit:

2001:db8:abcd:1000::/52 runs from 2001:db8:abcd:1000:: to 2001:db8:abcd:1fff:ffff:ffff:ffff:ffff and holds 4,096 /64s. Borrow two digits and the same /48 gives 256 /56s, from 2001:db8:abcd::/56 to 2001:db8:abcd:ff00::/56. The pattern continues to the /64:

2001:0db8:abcd:X000::/52   X = 0-f               16 subnets
2001:0db8:abcd:XY00::/56   XY = 00-ff           256 subnets
2001:0db8:abcd:XYZ0::/60   XYZ = 000-fff      4,096 subnets
2001:0db8:abcd:XYZW::/64   XYZW = 0000-ffff  65,536 subnets

The prefix splitter on the IPv6 tools page lists up to 65,536 subnets per split, exactly the number of /64s in a /48.

Prefixes that are not a multiple of 4 are legal. A /50 borrows 2 bits, so the /48 splits into four: 2001:db8:abcd::/50, 2001:db8:abcd:4000::/50, 2001:db8:abcd:8000::/50 and 2001:db8:abcd:c000::/50. The boundary now falls inside a hex digit, so the range is no longer visible: 2001:db8:abcd:4000::/50 ends at 2001:db8:abcd:7fff:ffff:ffff:ffff:ffff. Reverse DNS also works per nibble, since ip6.arpa has one label per hex digit; a /50 needs four /52 zones.

The documentation block 3fff::/20 (RFC 9637) ends on a nibble inside the second hextet. 3fff:0 is fixed, so it runs from 3fff:: to 3fff:fff:ffff:ffff:ffff:ffff:ffff:ffff.

05Planning a site

Take 2001:db8:abcd::/48. The provider fixes the first three hextets. The fourth is yours: 16 bits, or 65,536 /64s. Give each nibble a meaning and the address tells you where it lives. A campus scheme:

2001:0db8:abcd:0110::/64
               |||
               ||+-- VLAN 10, written as the digits 1 and 0 (00-99)
               |+--- building 1 (1-f; 0 = campus core)
               +---- purpose: 0 = LANs, f = infrastructure
Network4th hextetPrefix
Building 1, VLAN 10 (staff)01102001:db8:abcd:110::/64
Building 1, VLAN 20 (voice)01202001:db8:abcd:120::/64
Building 1, VLAN 99 (management)01992001:db8:abcd:199::/64
Building 2, VLAN 10 (staff)02102001:db8:abcd:210::/64
All of building 10100–01ff2001:db8:abcd:100::/56
All LANs0000–0fff2001:db8:abcd::/52
Router loopbacksf0002001:db8:abcd:f000::/64
Point-to-point linksf0012001:db8:abcd:f001::/64
All infrastructuref000–ffff2001:db8:abcd:f000::/52
  • Leading zeros vanish in RFC 5952 form. You plan 0110; routers and this calculator show 2001:db8:abcd:110::/64.
  • VLAN 10 is written as the digits 1 and 0, not converted to hex (0a), so the address matches the VLAN ID. The cost: a to f never appear in those digits, so each building uses 100 of its 256 /64s.
  • Each building is a /56 and each purpose a /52. One route summarises a building, and one ACL entry matches all infrastructure. Purpose digits 1 to e stay free for growth.
  • With VLAN IDs above 99, a single-building site can use the full VLAN ID, 1 to 4094, as the four digits: VLAN 1010 becomes 2001:db8:abcd:1010::/64. Decimal digits never reach f, so f000 and up stays free.

06Address types you will meet

TypePrefixDefined inNotes
Global unicast (GUA)2000::/3RFC 4291Routed on the internet. IANA allocates from this block.
Unique local (ULA)fc00::/7RFC 4193Private use. Only fd00::/8 is in use.
Link-localfe80::/10RFC 4291On every interface. Never routed.
Multicastff00::/8RFC 4291One to many. Replaces broadcast.
Loopback::1RFC 4291Same role as 127.0.0.1.
Unspecified::RFC 4291Source address before a host has one.
IPv4-mapped::ffff:0:0/96RFC 4291IPv4 inside an IPv6 socket, such as ::ffff:192.0.2.1.
Documentation2001:db8::/32RFC 3849For examples. Never routed.
Documentation3fff::/20RFC 9637Larger block for examples. Never routed.

ULAs are the IPv6 private space. RFC 4193 splits fc00::/7 on its eighth bit, L. L = 1 gives fd00::/8, the half in use; fc00::/8 (L = 0) is not yet defined. After fd come 40 random bits, the Global ID, which gives each site its own /48:

fd5c:8e2f:419d:0110:0000:0000:0000:0001
fd                                        prefix fd00::/8, L = 1    8 bits
  5c:8e2f:419d                            Global ID, random        40 bits
               0110                       subnet ID                16 bits
                    0000:0000:0000:0001   interface ID             64 bits

The random Global ID makes it unlikely that two ULA prefixes overlap when networks merge or connect over a VPN. Do not use fd00::/48; the IPv6 tools page generates a random ULA /48 in your browser. Inside the /48, subnetting works as with a global prefix: building 1, VLAN 10 is fd5c:8e2f:419d:110::/64.

Link-local addresses, in fe80::/64 on every interface, are never routed. Router Advertisements and OSPFv3 use them as next hops, written with the interface, as in fe80::1%eth0.

Multicast replaces broadcast. ff02::1 reaches all nodes on a link and ff02::2 all routers. Neighbor Discovery uses solicited-node groups in ff02::1:ff00:0/104 where IPv4 sends an ARP broadcast.

07Point-to-point links and loopbacks

A link between two routers needs two addresses. Three prefix lengths are in use:

  • /64. Consistent with other links, but RFC 6164 lists two problems. On routers without the RFC 4443 fix, a packet to an unused address can bounce between the two ends until its hop limit expires. A scan of the /64 can fill the neighbor cache.
  • /127. Two addresses, both used, nothing to scan. RFC 6164 requires routers to support /127 on point-to-point links and to disable the Subnet-Router anycast address there.
  • /126. Four addresses, an IPv4 /30 habit. With no broadcast to set aside, it has no advantage over /127.

Worked example, using 2001:db8:abcd:f001::/64 from the site plan:

The calculator shows 2 usable addresses for each and no broadcast. 2001:db8:abcd:f001::/127 is skipped on purpose: its lower address has an all-zero interface ID, which RFC 4291 reserves as the Subnet-Router anycast address of the /64. RFC 6164 section 5.1 covers this case, and many operators skip that pair. Some operators instead reserve a /64 per link and configure a /127 inside it, so the link can later move to a /64.

Loopbacks are /128s, taken from one reserved /64: router 1 is 2001:db8:abcd:f000::1/128, router 2 is 2001:db8:abcd:f000::2/128. The IGP carries them as host routes, and they serve as stable source addresses for BGP sessions and management.

08Interface IDs and EUI-64

SLAAC needs a 64-bit interface ID. The original method, modified EUI-64 (RFC 4291 appendix A), builds it from the 48-bit MAC address. Worked example with 00:1a:2b:3c:4d:5e:

  1. Split the MAC into halves: 00:1a:2b and 3c:4d:5e.
  2. Insert ff:fe between them: 00:1a:2b:ff:fe:3c:4d:5e, 64 bits.
  3. Flip the universal/local (U/L) bit, the second-lowest bit of the first byte: 00 (0000 0000) becomes 02 (0000 0010).
  4. Group into hextets: 021a:2bff:fe3c:4d5e.
2001:0db8:abcd:0110:021a:2bff:fe3c:4d5e   /64 prefix + EUI-64 interface ID
fe80:0000:0000:0000:021a:2bff:fe3c:4d5e   link-local, same interface ID

On 2001:db8:abcd:110::/64 the address is 2001:db8:abcd:110:21a:2bff:fe3c:4d5e/64, and the link-local address is fe80::21a:2bff:fe3c:4d5e. RFC 5952 drops the leading zero of 021a. The IPv6 tools page computes this for any MAC and /64.

The flip is deliberate: in an interface ID the bit's meaning is inverted, so hand-configured IDs such as ::1 keep it at 0, which marks them as local.

An EUI-64 address exposes the MAC, so a device can be tracked from network to network. Hosts now use temporary addresses (RFC 8981) or stable, opaque IDs (RFC 7217) for global addresses; RFC 8064 recommends RFC 7217 as the default. EUI-64 remains common on network devices, for link-local addresses and in commands such as ipv6 address 2001:db8:abcd:110::/64 eui-64 on Cisco IOS.

09FAQ

How many /64s are in a /48?

65,536. A /48 leaves 16 bits before the /64 boundary, and 216 = 65,536. The same /48 holds 256 /56s of 256 /64s each. 2001:db8:abcd::/48

Can I use a /80 or /96 on a LAN?

The router will accept it, but SLAAC will not work: RFC 4862 makes hosts ignore a prefix when prefix length plus the 64-bit interface ID is not 128 bits. Hosts then need DHCPv6 or static addresses, and some operating systems do not take an address from DHCPv6 at all. Use a /64 on every LAN.

Does IPv6 have a broadcast address?

No. Multicast replaces it: ff02::1 reaches all nodes on a link, and Neighbor Discovery uses solicited-node multicast instead of ARP broadcasts. This site counts every address in a prefix as usable. The all-zero interface ID is the Subnet-Router anycast address (RFC 4291 section 2.6.1), so do not give it to a host.

What is the IPv6 equivalent of 192.168.0.0/16?

Unique local addresses in fd00::/8 (RFC 4193). A random 40-bit Global ID gives you a /48, such as fd5c:8e2f:419d::/48, which you subnet into /64s like any other. ULAs are not routed on the internet. Hosts usually have a global address as well, so using ULA does not imply NAT.

How many addresses are in a /64?

264 = 18,446,744,073,709,551,616. No LAN fills it. The size lets hosts choose their own interface IDs, including random ones, with a negligible chance of collision. 2001:db8:abcd:110::/64