All guided builds

Guided buildcore7 steps~22 min4 devices

Your first IPv6 ping

Address two routers and their LANs with IPv6, ping across the link between them, then route between the sites with a static route and a ::/0 default.

What you'll be able to do: Two IPv6 sites joined by a routed link: every interface carries a /64 global address, the link has readable link-local addresses, HQ holds a static route to the remote LAN, and Remote a ::/0 default route home — with IPv6 pings answering in both directions.

Topics: IPv6 · Static routing · Default routes · WAN links

What you'll build

Step by step

  1. 1. Place HQ and switch IPv6 routing on

    Drag a router onto the canvas, name it, and type one global command: `ipv6 unicast-routing`. It goes in first, before a single address, because it decides what kind of IPv6 device this box is.

    On HQ — Name the router and enable IPv6 forwarding

    enable
    configure terminal
    hostname HQ
    ipv6 unicast-routing
    end

    Check: run show running-config on HQ and look for ipv6 unicast-routing.

    Why: `ipv6 unicast-routing` is what lets a router forward IPv6 packets from one interface to another. Without it a router can still own IPv6 addresses and answer pings to them, but it behaves like a host and passes nobody else's traffic along.

  2. 2. Give the HQ LAN its /64

    Drag in a switch for the HQ LAN, cable HQ's Gi0/0 to the switch's Gi0/1, and give Gi0/0 the address 2001:db8:acad:1::1/64. NetForge's PCs don't take IPv6 addresses yet, so every address in this build lives on a router — the switch is the LAN a host would join, and its cable is what brings Gi0/0 up.

    • Cable HQ Gi0/0 ↔ SW-HQ Gi0/1

    On SW-HQ — Name the switch — it needs nothing else to carry IPv6 frames

    enable
    configure terminal
    hostname SW-HQ
    end

    On HQ — Put the HQ LAN's first address on Gi0/0 and bring the port up

    enable
    configure terminal
    interface Gi0/0
    ipv6 address 2001:db8:acad:1::1/64
    no shutdown
    exit
    end

    Check: run show ipv6 interface brief on HQ and look for Gi0/0 [up/up].

    Why: An IPv6 address is 128 bits written as eight groups of four hex digits: 2001:db8:acad:1::1 is short for 2001:0db8:acad:0001:0000:0000:0000:0001 — leading zeros drop, and one run of all-zero groups becomes ::, which may appear only once. The /64 splits the address in half: the first 64 bits name the network, the last 64 identify the interface, and /64 is the size every IPv6 LAN is given.

  3. 3. Build the remote site the same way

    Repeat for the second site: a router named Remote with IPv6 routing on, a switch for its LAN on Gi0/1, and a different /64 — 2001:db8:acad:2::/64. The two LANs differ only in the fourth group, the part of the prefix that numbers subnets.

    • Cable Remote Gi0/0 ↔ SW-Remote Gi0/1

    On SW-Remote — Name the remote LAN switch

    enable
    configure terminal
    hostname SW-Remote
    end

    On Remote — Name the router, enable IPv6 forwarding, and address its LAN

    enable
    configure terminal
    hostname Remote
    ipv6 unicast-routing
    interface Gi0/0
    ipv6 address 2001:db8:acad:2::1/64
    no shutdown
    exit
    end

    Check: run show ipv6 interface brief on Remote and look for 2001:db8:acad:2::1.

    Why: With a /48 for the whole organisation — 2001:db8:acad::/48 here — the fourth group's 16 bits can number 65,536 /64 subnets. Giving each one a number that means something (1 for HQ, 2 for Remote, 12 for the link between them) is what keeps an IPv6 plan readable.

  4. 4. Join the sites and send your first IPv6 ping

    Cable the two Se0/0/0 ports with a serial cable and give the link its own /64, 2001:db8:acad:12::/64 — HQ is ::1, Remote is ::2. Then ping Remote's end from HQ: your first IPv6 ping, and it comes back.

    • Cable HQ Se0/0/0 ↔ Remote Se0/0/0 (serial)

    On HQ — Take the HQ end of the link

    enable
    configure terminal
    interface Se0/0/0
    ipv6 address 2001:db8:acad:12::1/64
    no shutdown
    exit
    end

    On Remote — Take the remote end of the same link

    enable
    configure terminal
    interface Se0/0/0
    ipv6 address 2001:db8:acad:12::2/64
    no shutdown
    exit
    end

    On HQ — Ping across the link

    enable
    ping 2001:db8:acad:12::2

    Check: run show ipv6 route on HQ and look for C 2001:db8:acad:12::/64 [0/0].

    Why: Read `show ipv6 route`: every address produces two entries — a C route for the /64 it sits in, and an L route, a /128 that matches that one address, for the interface itself. The link's /64 is connected on both routers, so this ping needs no route at all.

  5. 5. Give the link readable link-local addresses

    Every IPv6 interface carries a second, link-local address from fe80::/10 that is valid on its own link only. Set them by hand on the WAN link — fe80::1 on HQ, fe80::2 on Remote — so they are as easy to read as the global ones.

    On HQ — Give HQ's end of the link the link-local address fe80::1

    enable
    configure terminal
    interface Se0/0/0
    ipv6 address fe80::1 link-local
    exit
    end

    On Remote — Give Remote's end the link-local address fe80::2

    enable
    configure terminal
    interface Se0/0/0
    ipv6 address fe80::2 link-local
    exit
    end

    Check: run show ipv6 interface Se0/0/0 on HQ and look for IPv6 is enabled, link-local address is fe80::1.

    Why: Link-local addresses are how IPv6 neighbours find each other and how routing protocols talk to the router next door, and a router never forwards a packet sent to or from one. A router would otherwise build its link-local address from the interface's MAC — correct, but a long string nobody reads at a glance.

  6. 6. Route to the remote LAN — from HQ only

    `ipv6 route 2001:db8:acad:2::/64 2001:db8:acad:12::2` has the same shape as an IPv4 static route, with the prefix length where the mask used to be. HQ can now ping the remote LAN's gateway — but from Remote, a ping to 2001:db8:acad:1::1 still fails with no IPv6 route: Remote has never heard of the HQ LAN.

    On HQ — Point HQ at the remote LAN, via Remote's end of the link

    enable
    configure terminal
    ipv6 route 2001:db8:acad:2::/64 2001:db8:acad:12::2
    end
    ping 2001:db8:acad:2::1

    On Remote — Try the other direction and watch it fail

    enable
    ping 2001:db8:acad:1::1

    Check: run show ipv6 route on HQ and look for S 2001:db8:acad:2::/64 [1/0].

    Why: IPv6 routing works exactly like IPv4 routing: each router forwards by longest-prefix match on its own table, and a static route programs one router in one direction. HQ's ping gets its answer because it leaves from 2001:db8:acad:12::1, an address on a link Remote is plugged into.

  7. 7. Give Remote a default route home

    Remote is a stub — its only way out is the link to HQ — so one default route covers everything: `ipv6 route ::/0 2001:db8:acad:12::1`. Repeat the ping that failed, and both routers now reach each other's LAN.

    On Remote — Send everything that is not local to HQ, then retry the failed ping

    enable
    configure terminal
    ipv6 route ::/0 2001:db8:acad:12::1
    end
    ping 2001:db8:acad:1::1

    Check: run show ipv6 route on Remote and look for S ::/0 [1/0].

    Why: ::/0 is the IPv6 default route, the twin of 0.0.0.0/0: a prefix length of zero matches every address, so it is used only when nothing longer does. A stub never needs more than that one line.

The theory behind it

Build it for real

The lab walks you through these steps and ticks each one off as your network starts working.

Open in the lab
Your first IPv6 ping — step-by-step network lab · NetForge-AI