AWS Builder Center

๐ŸŒ IPv6 Fundamentals on AWS: Understanding CIDR Blocks and VPC Routes

Learn to read IPv6 addresses, divide an AWS-provided range into subnets, and understand how IPv6 route tables direct traffic.

Sr Consultant, Cloud&Network Security
IPv6 addresses can look intimidating. Once you understand their structure and prefix lengths, planning an AWS network becomes much easier.
Letโ€™s explore three building blocks: IPv6 addresses, CIDR allocations, and route table entries.
๐Ÿ’ก Key highlight: An address identifies a network interface. A CIDR describes an address range. A route determines the next hop toward a destination. Security rules determine whether traffic is permitted.

๐Ÿ”ข 1. Reading an IPv6 address

IPv4 uses 32-bit addresses. IPv6 uses 128-bit addresses, written in hexadecimal.
PropertyIPv4IPv6
Address length32 bits128 bits
Example10.20.1.102001:db8:1234:ab01::10
FormatDecimal groups separated by dotsHexadecimal groups separated by colons
Default route0.0.0.0/0::/0
A full IPv6 address has eight groups, each representing 16 bits.
These three representations describe the same address:
RepresentationAddress
Expanded2001:0db8:1234:ab01:0000:0000:0000:0010
Leading zeros removed2001:db8:1234:ab01:0:0:0:10
Zero groups compressed2001:db8:1234:ab01::10
Two rules make addresses easier to read:
  • Remove leading zeros within a group.
  • Replace one consecutive sequence of zero groups with ::.
Use :: only once in an address, so the missing groups can be reconstructed unambiguously.
๐Ÿ“Œ Remember: Hexadecimal uses 0โ€“9 and aโ€“f. The ending 10 above is hexadecimal, not decimal ten.
The 2001:db8::/32 addresses throughout this post are documentation examples. Use your actual AWS-assigned range when configuring resources.

๐Ÿงฎ 2. What does an IPv6 CIDR prefix mean?

Consider:
1
2001:db8:1234:ab00::/56
The /56 means the first 56 bits identify the network prefix. The remaining bits identify addresses within that range.
PrefixFixed prefix bitsRemaining bitsMeaning
/565672VPC allocation in our example
/646464Subnet allocation in our example
/1281280One exact address
/00128All IPv6 addresses
๐Ÿ’ก CIDR highlight: A larger prefix number describes a smaller address range. A /64 is smaller than a /56.

Visual: dividing a /56 into /64 ranges

First 48 bitsNext 8 bitsNext 8 bitsFinal 64 bits
2001:db8:1234ab00 through ffAddress within the subnet
Fixed VPC prefixFixed VPC prefixSelects a /64 subnet rangeInterface address space
Moving from /56 to /64 provides eight subnet-selection bits:
\[ 2^{64-56}=256 \]
So one /56 contains 256 possible /64 ranges. AWS subnet quotas separately determine how many subnets you can create.

โ˜๏ธ 3. Understanding Amazon-provided IPv6 CIDRs

A straightforward starting point is to request an Amazon-provided IPv6 CIDR for your VPC. In the standard allocation workflow, AWS assigns a /56; you do not select the actual address range yourself.
AWS also supports allocation through IPAM and IPv6 ranges you bring to AWS.
Avoid treating /56 and /64 as universal requirements. Current AWS documentation supports VPC IPv6 sizes from /44 to /60, and subnet sizes from /44 to /64, in increments of four, subject to allocation constraints. We use a /56 VPC with /64 subnets for this example. Amazon Virtual Private Cloudย 

๐Ÿ—๏ธ Visual: VPC โ†’ subnets โ†’ instance address

Each subnet must fit inside the VPC allocation and must not overlap another subnet.
AWS reserves the first four and last IPv6 addresses in each subnet range. Although a /64 mathematically contains \(2^{64}\) addresses, not every address is assignable to EC2. Amazon Virtual Private Cloudย 

๐Ÿšฆ 4. Understanding IPv6 route table entries

Every route has two essential parts:
FieldQuestion it answers
DestinationWhich destination address range matches?
TargetWhere should matching traffic go?

๐Ÿ  The local route

For our VPC allocation, the local entry is:
DestinationTarget
2001:db8:1234:ab00::/56local
AWS creates the local route when you associate the IPv6 range with the VPC. It covers the VPC range, rather than requiring a local entry for each subnet.
In this basic design, traffic between the VPCโ€™s subnets uses that route. Security rules still determine whether communication is allowed.

๐ŸŒ Public IPv6 internet connectivity

A public-subnet route table can contain:
DestinationTarget
2001:db8:1234:ab00::/56local
::/0Internet gateway
The internet gateway supports inbound and outbound IPv6 connectivity. Actual inbound access also requires suitable security rules and a listening application.

๐Ÿ”’ Outbound-only IPv6 internet connectivity

A private-subnet route table can contain:
DestinationTarget
2001:db8:1234:ab00::/56local
::/0Egress-only internet gateway
The egress-only gateway permits outbound connections and their responses, while preventing internet-initiated connections through that gateway.
These are alternative route table designs. Choose one target for the ::/0 destination in each table.

Visual: two internet paths

Responses to the private resourceโ€™s outbound connections are allowed. Both designs remain subject to security controls.
๐Ÿ’ก Gateway highlight: An egress-only internet gateway does not translate IPv6 addresses. It controls connection initiation.

๐ŸŽฏ 5. Which route wins?

AWS generally selects the most specific matching route, known as longest prefix match. IPv4 and IPv6 routes are evaluated independently. Amazon Virtual Private Cloudย 
Consider this table, with an active IPv6-capable peering connection:
DestinationTarget
2001:db8:1234:ab00::/56local
2001:db8:5678:cd00::/56VPC peering connection
::/0Egress-only internet gateway
Here is how packets are routed:
Packet destinationSelected route
2001:db8:1234:ab01::10Local VPC /56
2001:db8:5678:cd01::20Remote VPC /56 through peering
Any other IPv6 destinationDefault route ::/0
The remote /56 is more specific than /0, so matching packets use peering. Peering also requires appropriate reverse routes and security rules.
๐Ÿ“Œ Remember: 0.0.0.0/0 never substitutes for a missing IPv6 default route.

๐Ÿ›ก๏ธ 6. Routing and security work together

An Amazon-provided globally routable IPv6 address does not automatically make an instance accessible from the internet.
Check four layers:
  1. Address: Does the interface have an IPv6 address?
  2. Route: Does its subnet have the correct route table?
  3. Security: Do security groups, ACLs, and the host firewall allow traffic?
  4. Application: Does the service listen on IPv6?
For outbound HTTPS, separate security group rules might be:
DirectionProtocol/portDestination
OutboundTCP 4430.0.0.0/0
OutboundTCP 443::/0
The first permits IPv4 HTTPS; the second permits IPv6 HTTPS.
Security groups are stateful. Custom network ACLs are stateless, so account for return traffic. Preserve necessary ICMPv6 messages, including Packet Too Big, for Path MTU Discovery.

Three similar-looking expressions

ExpressionMeaning
::Unspecified IPv6 address
::1Loopback address
::/0CIDR matching every IPv6 address

๐Ÿ› ๏ธ 7. Try it in the AWS console

  1. Add an Amazon-provided IPv6 CIDR to a VPC.
  2. Record the actual assigned allocation.
  3. Allocate distinct /64 ranges to two subnets.
  4. Inspect the automatically created IPv6 local route.
  5. For public connectivity, add ::/0 targeting an attached internet gateway.
  6. For outbound-only connectivity, use a separate table with ::/0 targeting an egress-only internet gateway.
  7. Verify each subnetโ€™s route table association.
  8. If testing EC2, assign an IPv6 address and review its security rules.
On a Linux instance:
1
2
3
ip -6 addr show scope global
ip -6 route show
curl -6 -I --connect-timeout 10 https://www.google.com
The first two commands show guest addresses and routes. They do not display the AWS VPC route table.
A successful HTTPS response demonstrates IPv6 connectivity to that destination.
๐Ÿ“ธ Suggested screenshots: VPC IPv6 allocation, subnet allocations, local route, and the two alternative default routes.

โš ๏ธ 8. Common mistakes

MistakeCorrection
Deploying documentation addressesUse your AWS-assigned allocation
Assuming every AWS IPv6 subnet must be /64Check current supported sizing
Expecting an IPv4 default route to carry IPv6Configure ::/0
Editing the wrong route tableCheck subnet associations
Assuming IPv4 rules permit IPv6Add appropriate IPv6 rules
Expecting egress-only gateway to reach IPv4-only destinationsUse IPv4 or evaluate DNS64/NAT64
Assuming address assignment guarantees accessCheck routes, security, and application support

โœ… Key takeaways

  • IPv6 uses 128-bit addresses.
  • Prefix lengths describe address ranges.
  • A /56 contains 256 /64 ranges.
  • The local route covers the VPCโ€™s IPv6 allocation.
  • ::/0 is the IPv6 default route.
  • Its target determines the internet path.
  • Addressing, routing, security, and application support must work together.
Any opinions in this article are those of the individual author and may not reflect the opinions of AWS.
Enjoyed reading this content? Let the author know!

Your likes, comments, shares, and saves help creators reach more builders.

Loading recommendations

Loading article