IPv6 Overview: The Protocol Already Running on Your Devices

IPv6 is already running on your devices — most people just don’t know it yet. It carries a large and growing share of internet traffic, your phone and laptop almost certainly have an IPv6 address right now, and most security programs still treat it as someone else’s problem. That gap is exactly where attackers live. This Cover6 Community session covers IPv6 from the ground up — and IPv6 is in our name for a reason, so this one is close to home.

Use this post as your read-ahead, then come back to it when you need to read an address or remember an attack.

YouTube thumbnailYouTube icon

Why IPv6 exists

IPv4 has about 4.3 billion addresses. The internet ran out. IPv6 replaces the 32-bit address with a 128-bit one — enough space that address exhaustion stops being a concern for any timeframe worth planning around. That’s the “why.” The “so what” is that IPv6 is on by default on modern systems, which means it’s part of your attack surface whether you’ve thought about it or not.

Reading a 128-bit address

A full IPv6 address looks intimidating until you learn the two shortening rules, and then it’s quick:

  • Drop leading zeros in each group (0db8 becomes db8).
  • Collapse one run of all-zero groups to :: (used once per address).

So 2001:0db8:0000:0000:0000:0000:0000:0001 shortens to 2001:db8::1. The session walks through this until reading and shortening an address is second nature — it’s the single skill that makes everything else about IPv6 approachable.

Three ways IPv6 communicates

IPv6 drops the broadcast model and uses three address types instead:

  • Unicast — one-to-one, a single interface.
  • Multicast — one-to-many, everyone subscribed to the group.
  • Anycast — one-to-nearest, the same address on many nodes, routed to the closest.

No more broadcast is a real change from IPv4, and it reshapes how discovery and attacks work on the wire.

SLAAC: addresses configure themselves

One of the biggest differences from IPv4: with SLAAC (Stateless Address Autoconfiguration), a device can build its own routable address from the network prefix it hears and its own interface — historically derived from the MAC address. No DHCP server required. DHCPv6 still exists for networks that want stateful control, but the default experience is a device that addresses itself the moment it joins. Convenient — and a thing defenders need to account for.

The security story: no NAT, and new attacks

IPv6 changes the defender’s assumptions:

  • IPSec was designed in, not bolted on — encryption and authentication are native to the protocol.
  • No NAT. The address-translation layer many people quietly relied on as a firewall-by-accident isn’t there. Addresses are globally routable by default.
  • RA Spoofing — forged Router Advertisements can redirect traffic, and the THC-IPv6 toolkit is where you’ll see this demonstrated.
  • Tunneling attacks — IPv6 tunneled over IPv4 (and the reverse) can carry traffic straight past monitoring that only speaks IPv4.
  • Transition mechanisms — Dual Stack, tunneling, and NAT64 are how the two protocols coexist, and each one is its own set of things to watch.

The through-line: if your monitoring, your scans, and your firewall rules only cover IPv4, you have a blind spot the size of the other half of the internet.

See it on your own machine

The session ends with a live demo on Kali Linux you can run yourself — these are the commands that make IPv6 real:

ip a          # see the IPv6 addresses already on your interfaces
ping6         # test IPv6 connectivity
dig AAAA      # look up a host's IPv6 DNS record
nmap -6       # scan over IPv6

Then visit test-ipv6.com to grade your own connectivity. Running ip a and finding an address you didn’t know you had is the moment IPv6 stops being theoretical.

Practice on a live lab, free

IPv6 shows up on both sides of the house — as an attack surface to scan and as traffic to monitor. First Shell gives you an authorized target to scan, free, where nmap -6 and address enumeration become muscle memory: https://www.cover6solutions.com/product/cover6-first-shell-free-access/

Prefer the defender’s seat? First Watch gives you a live Splunk lab and your first SOC shift, free — where IPv6 traffic is one more thing an analyst learns to see: https://www.cover6solutions.com/product/cover6-first-watch-free-access/

Where this path leads

Networking fundamentals like IPv6 sit under both the SOC Analyst and Penetration Tester paths on Chrysalus. Build your free profile and track your progress.

Watch the replay

We ran this live in the Cover6 Community — why IPv6 exists, reading and shortening addresses, the three communication types, SLAAC, the security differences and attacks, and a full Kali demo with ip a, ping6, dig AAAA, and nmap -6. Planning to attend a future meetup? Use this post as your read-ahead, and catch the replay above.

The 6 — Free Newsletter

Job openings, new courses, free workshops, and what’s working in cyber careers right now — straight to your inbox.

Free forever. Confirm by email, unsubscribe any time. We never share your address.

Shopping Cart
Scroll to Top