How to Configure IPv6 on a VPS (Ubuntu Netplan, Debian, Rocky Linux, Windows Server)

15 min read 2 views 0
On this page

Every JUSTG cloud server comes with a free IPv6 address in addition to its IPv4. IPv6 gives you a second, independent way to reach your VPS, makes your websites reachable for IPv6-only mobile networks and is a free alternative when you need another address. This tutorial explains how to check and configure IPv6 on a VPS running Debian, Ubuntu (Netplan), CentOS, Rocky Linux or AlmaLinux and Windows Server 2016/2019/2022, how to test the connection with ping -6 and curl -6, how to SSH over IPv6 and how to protect the new address with an IPv6 firewall.

Step 1: Find your IPv6 address and gateway

Log in to the JUSTG client area and open your VPS under My Products & Services. The assigned IPv6 address, prefix length and IPv6 gateway are shown in the server details. If you cannot find them, open a ticket and support will send them to you. In this guide we use documentation values: address 2001:db8::10/64, gateway 2001:db8::1, IPv4 203.0.113.50. Replace them with your real values.

Changing network settings can disconnect your SSH or RDP session. Keep the VNC console from the client area open as a fallback and back up the configuration file before editing it.

Step 2: Check whether IPv6 is already configured

Some images configure IPv6 automatically. On Linux run:

ip -6 addr show
ip -6 route show
ip link

If you see a line inet6 2001:db8::10/64 scope global and a default route via your gateway, IPv6 already works and you can jump to Step 6. An address starting with fe80:: is only link-local and is not enough. Note your interface name from ip link (for example eth0 or ens3).

Step 3: Configure static IPv6 on Ubuntu with Netplan

Ubuntu 18.04 and later use Netplan. Open the YAML file in /etc/netplan/ (often 50-cloud-init.yaml or 01-netcfg.yaml) and add the IPv6 address and route next to your existing IPv4 settings. Indentation must use spaces:

network:
  version: 2
  ethernets:
    eth0:
      addresses:
        - 203.0.113.50/24
        - "2001:db8::10/64"
      routes:
        - to: default
          via: 203.0.113.1
        - to: "::/0"
          via: "2001:db8::1"
      nameservers:
        addresses: [1.1.1.1, 8.8.8.8]

Validate and apply. netplan try rolls back automatically after 120 seconds if you lose the connection and do not confirm:

sudo netplan generate
sudo netplan try
sudo netplan apply

If the file was generated by cloud-init, stop it from overwriting your changes on reboot:

echo "network: {config: disabled}" | sudo tee /etc/cloud/cloud.cfg.d/99-disable-network-config.cfg

Step 4: Configure IPv6 on Debian (/etc/network/interfaces) or CentOS/Rocky (nmcli)

Debian with ifupdown: add an inet6 block for your interface in /etc/network/interfaces, below the existing IPv4 block:

iface eth0 inet6 static
    address 2001:db8::10/64
    gateway 2001:db8::1
sudo systemctl restart networking

CentOS Stream, Rocky Linux and AlmaLinux use NetworkManager. List the connections, then set the IPv6 method to manual on the one bound to your interface (the name may be System eth0, eth0 or Wired connection 1):

nmcli connection show
sudo nmcli connection modify "System eth0" ipv6.method manual \
    ipv6.addresses 2001:db8::10/64 ipv6.gateway 2001:db8::1
sudo nmcli connection up "System eth0"

Step 5: Configure IPv6 on Windows Server

Open Command Prompt as Administrator, find the interface name (usually Ethernet) and add the address and default route:

netsh interface ipv6 show interfaces
netsh interface ipv6 add address "Ethernet" 2001:db8::10/64
netsh interface ipv6 add route ::/0 "Ethernet" 2001:db8::1

Prefer the GUI? Open Control Panel > Network and Sharing Center > Change adapter settings, right-click the adapter, choose Properties > Internet Protocol Version 6 (TCP/IPv6), select Use the following IPv6 address and enter the address, subnet prefix length 64 and default gateway.

Step 6: Test IPv6 connectivity with ping -6 and curl -6

# Linux
ping -6 -c 4 www.google.com
curl -6 https://ifconfig.co

# Windows (PowerShell)
ping -6 www.google.com

A reply to ping and your server's IPv6 address returned by curl confirm that outbound IPv6 works. To test inbound access, ping your VPS's IPv6 from another IPv6-enabled machine.

Step 7: Connect over SSH using IPv6

From a computer with IPv6 connectivity you can now log in directly to the IPv6 address. OpenSSH listens on IPv6 by default; if it does not, check that AddressFamily in /etc/ssh/sshd_config is any or inet6.

ssh root@2001:db8::10
ssh -6 root@2001:db8::10

Step 8: Set up an IPv6 firewall (ufw, firewalld, ip6tables)

A common mistake is to lock down IPv4 while leaving IPv6 wide open. ufw and firewalld handle both protocols with one rule:

# Debian / Ubuntu: make sure /etc/default/ufw contains IPV6=yes
sudo ufw allow 22/tcp
sudo ufw allow 80,443/tcp
sudo ufw enable
sudo ufw status verbose

# CentOS / Rocky / AlmaLinux (firewalld covers IPv4 and IPv6)
sudo firewall-cmd --permanent --add-service=ssh
sudo firewall-cmd --permanent --add-service=http --add-service=https
sudo firewall-cmd --reload

If you manage rules by hand with ip6tables, remember that ICMPv6 must be allowed, otherwise neighbor discovery breaks and IPv6 stops working:

ip6tables -A INPUT -i lo -j ACCEPT
ip6tables -A INPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT
ip6tables -A INPUT -p ipv6-icmp -j ACCEPT
ip6tables -A INPUT -p tcp --dport 22 -j ACCEPT
ip6tables -A INPUT -p tcp -m multiport --dports 80,443 -j ACCEPT
ip6tables -P INPUT DROP

# Debian / Ubuntu: save the rules
apt install iptables-persistent
netfilter-persistent save

On Windows Server, rules in Windows Defender Firewall apply to IPv4 and IPv6 at the same time unless you restrict the address scope.

FAQ

Is IPv6 really free on JUSTG cloud servers?

Yes. All JUSTG cloud servers in Johannesburg, Moscow, Tokyo and Seoul include IPv6 at no extra cost.

After applying the configuration I lost my connection. What should I do?

Open the VNC console in the client area, restore your backup of the network file or fix the indentation (Netplan) or connection name (nmcli), then apply again.

Can IPv6 replace an extra IPv4 address?

For visitors and services that support IPv6, yes. If your IPv4 becomes blocked because of your own usage, the free IPv6 can still be used for connections, or you can buy another IPv4 through the upgrade options in the client area.

If IPv6 still does not work on your VPS, please submit a ticket to JUSTG technical support with the output of ip -6 addr and ip -6 route.

Was this answer helpful?