๐ IPv6 Fundamentals on AWS: Understanding CIDR Blocks and VPC Routes
Learn to read IPv6 addresses, divide an AWS-provided range into subnets, and understand how IPv6 route tables direct traffic.
IPv6 addresses can look intimidating. Once you understand their structure and prefix lengths, planning an AWS network becomes much easier.
Letโs explore three building blocks: IPv6 addresses, CIDR allocations, and route table entries.
๐ก Key highlight: An address identifies a network interface. A CIDR describes an address range. A route determines the next hop toward a destination. Security rules determine whether traffic is permitted.
๐ข 1. Reading an IPv6 address
IPv4 uses 32-bit addresses. IPv6 uses 128-bit addresses, written in hexadecimal.
| Property | IPv4 | IPv6 |
|---|---|---|
| Address length | 32 bits | 128 bits |
| Example | 10.20.1.10 | 2001:db8:1234:ab01::10 |
| Format | Decimal groups separated by dots | Hexadecimal groups separated by colons |
| Default route | 0.0.0.0/0 | ::/0 |
A full IPv6 address has eight groups, each representing 16 bits.
These three representations describe the same address:
| Representation | Address |
|---|---|
| Expanded | 2001:0db8:1234:ab01:0000:0000:0000:0010 |
| Leading zeros removed | 2001:db8:1234:ab01:0:0:0:10 |
| Zero groups compressed | 2001:db8:1234:ab01::10 |
Two rules make addresses easier to read:
- Remove leading zeros within a group.
- Replace one consecutive sequence of zero groups with
::.
Use
:: only once in an address, so the missing groups can be reconstructed unambiguously.๐ Remember: Hexadecimal uses0โ9andaโf. The ending10above is hexadecimal, not decimal ten.
The
2001:db8::/32 addresses throughout this post are documentation examples. Use your actual AWS-assigned range when configuring resources.๐งฎ 2. What does an IPv6 CIDR prefix mean?
Consider:
1
2001:db8:1234:ab00::/56The
/56 means the first 56 bits identify the network prefix. The remaining bits identify addresses within that range.| Prefix | Fixed prefix bits | Remaining bits | Meaning |
|---|---|---|---|
| /56 | 56 | 72 | VPC allocation in our example |
| /64 | 64 | 64 | Subnet allocation in our example |
| /128 | 128 | 0 | One exact address |
| /0 | 0 | 128 | All IPv6 addresses |
๐ก CIDR highlight: A larger prefix number describes a smaller address range. A/64is smaller than a/56.
Visual: dividing a /56 into /64 ranges
| First 48 bits | Next 8 bits | Next 8 bits | Final 64 bits |
|---|---|---|---|
| 2001:db8:1234 | ab | 00 through ff | Address within the subnet |
| Fixed VPC prefix | Fixed VPC prefix | Selects a /64 subnet range | Interface address space |
Moving from
/56 to /64 provides eight subnet-selection bits:\[ 2^{64-56}=256 \]
So one
/56 contains 256 possible /64 ranges. AWS subnet quotas separately determine how many subnets you can create.โ๏ธ 3. Understanding Amazon-provided IPv6 CIDRs
A straightforward starting point is to request an Amazon-provided IPv6 CIDR for your VPC. In the standard allocation workflow, AWS assigns a
/56; you do not select the actual address range yourself.AWS also supports allocation through IPAM and IPv6 ranges you bring to AWS.
Avoid treating
/56 and /64 as universal requirements. Current AWS documentation supports VPC IPv6 sizes from /44 to /60, and subnet sizes from /44 to /64, in increments of four, subject to allocation constraints. We use a /56 VPC with /64 subnets for this example. Amazon Virtual Private Cloudย ๐๏ธ Visual: VPC โ subnets โ instance address
Each subnet must fit inside the VPC allocation and must not overlap another subnet.
AWS reserves the first four and last IPv6 addresses in each subnet range. Although a
/64 mathematically contains \(2^{64}\) addresses, not every address is assignable to EC2. Amazon Virtual Private Cloudย ๐ฆ 4. Understanding IPv6 route table entries
Every route has two essential parts:
| Field | Question it answers |
|---|---|
| Destination | Which destination address range matches? |
| Target | Where should matching traffic go? |
๐ The local route
For our VPC allocation, the local entry is:
| Destination | Target |
|---|---|
| 2001:db8:1234:ab00::/56 | local |
AWS creates the local route when you associate the IPv6 range with the VPC. It covers the VPC range, rather than requiring a local entry for each subnet.
In this basic design, traffic between the VPCโs subnets uses that route. Security rules still determine whether communication is allowed.
๐ Public IPv6 internet connectivity
A public-subnet route table can contain:
| Destination | Target |
|---|---|
| 2001:db8:1234:ab00::/56 | local |
| ::/0 | Internet gateway |
The internet gateway supports inbound and outbound IPv6 connectivity. Actual inbound access also requires suitable security rules and a listening application.
๐ Outbound-only IPv6 internet connectivity
A private-subnet route table can contain:
| Destination | Target |
|---|---|
| 2001:db8:1234:ab00::/56 | local |
| ::/0 | Egress-only internet gateway |
The egress-only gateway permits outbound connections and their responses, while preventing internet-initiated connections through that gateway.
These are alternative route table designs. Choose one target for the
::/0 destination in each table.Visual: two internet paths

Responses to the private resourceโs outbound connections are allowed. Both designs remain subject to security controls.
๐ก Gateway highlight: An egress-only internet gateway does not translate IPv6 addresses. It controls connection initiation.
๐ฏ 5. Which route wins?
AWS generally selects the most specific matching route, known as longest prefix match. IPv4 and IPv6 routes are evaluated independently. Amazon Virtual Private Cloudย
Consider this table, with an active IPv6-capable peering connection:
| Destination | Target |
|---|---|
| 2001:db8:1234:ab00::/56 | local |
| 2001:db8:5678:cd00::/56 | VPC peering connection |
| ::/0 | Egress-only internet gateway |
Here is how packets are routed:
| Packet destination | Selected route |
|---|---|
| 2001:db8:1234:ab01::10 | Local VPC /56 |
| 2001:db8:5678:cd01::20 | Remote VPC /56 through peering |
| Any other IPv6 destination | Default route ::/0 |
The remote
/56 is more specific than /0, so matching packets use peering. Peering also requires appropriate reverse routes and security rules.๐ Remember:0.0.0.0/0never substitutes for a missing IPv6 default route.
๐ก๏ธ 6. Routing and security work together
An Amazon-provided globally routable IPv6 address does not automatically make an instance accessible from the internet.

Check four layers:
- Address: Does the interface have an IPv6 address?
- Route: Does its subnet have the correct route table?
- Security: Do security groups, ACLs, and the host firewall allow traffic?
- Application: Does the service listen on IPv6?
For outbound HTTPS, separate security group rules might be:
| Direction | Protocol/port | Destination |
|---|---|---|
| Outbound | TCP 443 | 0.0.0.0/0 |
| Outbound | TCP 443 | ::/0 |
The first permits IPv4 HTTPS; the second permits IPv6 HTTPS.
Security groups are stateful. Custom network ACLs are stateless, so account for return traffic. Preserve necessary ICMPv6 messages, including Packet Too Big, for Path MTU Discovery.
Three similar-looking expressions
| Expression | Meaning |
|---|---|
| :: | Unspecified IPv6 address |
| ::1 | Loopback address |
| ::/0 | CIDR matching every IPv6 address |
๐ ๏ธ 7. Try it in the AWS console
- Add an Amazon-provided IPv6 CIDR to a VPC.
- Record the actual assigned allocation.
- Allocate distinct
/64ranges to two subnets. - Inspect the automatically created IPv6 local route.
- For public connectivity, add
::/0targeting an attached internet gateway. - For outbound-only connectivity, use a separate table with
::/0targeting an egress-only internet gateway. - Verify each subnetโs route table association.
- If testing EC2, assign an IPv6 address and review its security rules.
On a Linux instance:
1
2
3
ip -6 addr show scope global
ip -6 route show
curl -6 -I --connect-timeout 10 https://www.google.comThe first two commands show guest addresses and routes. They do not display the AWS VPC route table.
A successful HTTPS response demonstrates IPv6 connectivity to that destination.
๐ธ Suggested screenshots: VPC IPv6 allocation, subnet allocations, local route, and the two alternative default routes.
โ ๏ธ 8. Common mistakes
| Mistake | Correction |
|---|---|
| Deploying documentation addresses | Use your AWS-assigned allocation |
| Assuming every AWS IPv6 subnet must be /64 | Check current supported sizing |
| Expecting an IPv4 default route to carry IPv6 | Configure ::/0 |
| Editing the wrong route table | Check subnet associations |
| Assuming IPv4 rules permit IPv6 | Add appropriate IPv6 rules |
| Expecting egress-only gateway to reach IPv4-only destinations | Use IPv4 or evaluate DNS64/NAT64 |
| Assuming address assignment guarantees access | Check routes, security, and application support |
โ Key takeaways
- IPv6 uses 128-bit addresses.
- Prefix lengths describe address ranges.
- A
/56contains 256/64ranges. - The local route covers the VPCโs IPv6 allocation.
::/0is the IPv6 default route.- Its target determines the internet path.
- Addressing, routing, security, and application support must work together.
Enjoyed reading this content? Let the author know!
Your likes, comments, shares, and saves help creators reach more builders.
Loading recommendations
Loading article