IPv6

Version 6 of the Internet Protocol (RFC 8200), with 128-bit addresses written in hexadecimal, no broadcast, and a simpler base header, designed to replace the exhausted IPv4 space.

IPv6 is the successor to IPv4, specified in RFC 8200. Its addresses are 128 bits long and written as eight groups of four hexadecimal digits separated by colons; leading zeros can be dropped, and one run of all-zero groups can be shortened to a double colon, as in 2001:db8::1. The address space is large enough that shortage stops being a design constraint, so network address translation is no longer needed to conserve addresses.

The protocol also changes how a network behaves. There is no broadcast: IPv6 uses multicast and anycast instead. Neighbour discovery, carried in ICMPv6 messages, replaces ARP, and hosts can configure their own addresses from router advertisements. IPsec support was once required of every IPv6 node but has been a recommendation since RFC 6434 (2011), a position RFC 8504 keeps, so IPv6 traffic is not encrypted by default.

These changes create security work. Many operating systems enable IPv6 automatically, so a network that monitors only IPv4 can carry IPv6 traffic nobody is watching, and IPv6 tunnelled inside IPv4 can slip past filters. Forged router advertisements are the IPv6 counterpart of ARP spoofing.

Exam relevance: a scenario is likely to turn on address size, the absence of broadcast, or unmonitored IPv6 in a dual-stack network. Candidates are expected to reject the idea that IPv6 is secure because it was designed with IPsec in mind.