IPv6 On or Off? A Complete Ubuntu Guide With Commands and Security Facts

Rahma Rashad

Last Updated:

hero-image

If you’re looking to disable IPv6 on Ubuntu, keep in mind that turning it off usually doesn’t make your system more secure. Ubuntu enables IPv6 because many modern networks rely on it, and turning it off can cause issues if your services need IPv6.

Sometimes you might need to turn off IPv6, either temporarily or permanently. For example, you could be fixing issues on an older network, solving a routing problem, or using equipment that doesn’t handle IPv6 well. This guide will help you decide when to keep IPv6 on, when it’s okay to turn it off, and how to safely disable or re-enable it using sysctl, GRUB, and Netplan.

What Is IPv6? Quick Definitions Before You Decide

IPv6—short for Internet Protocol version 6—is the latest standard meant to solve the address shortage of IPv4. With 128-bit addresses, it supports automatic configuration, multicast, and modern routing, all without relying on the address-saving tricks IPv4 needed.

IPv6 vs IPv4: What Actually Changed

IPv4 uses 32-bit addresses, while IPv6 uses 128-bit addresses. The larger address space is the most visible change, but IPv6 also replaces ARP with Neighbor Discovery Protocol and supports SLAAC for automatic addressing.

IPv4 and IPv6 can work side by side in a dual-stack network, allowing a server to use both protocols. This is the most common way networks handle the transition today.

Google continuously measures IPv6 connectivity among users accessing its services. In March 2026, native IPv6 access to Google exceeded 50% for the first time, according to Internet Society Pulse.

 

Dual-Stack, SLAAC, and Other Terms You Will See

Term

Plain-English definition

IPv6

The 128-bit version of the Internet Protocol used for network addressing and routing.

IPv4

The older 32-bit IP standard still widely used across the internet.

Dual-stack

A network where IPv4 and IPv6 operate at the same time.

SLAAC

Stateless Address Autoconfiguration, which lets an IPv6 device configure an address automatically.

NDP

Neighbor Discovery Protocol, used for functions such as neighbor and router discovery in IPv6.

ULA

Unique Local Address, an IPv6 address intended for private internal communication.

/64 subnet

A common IPv6 subnet where the first 64 bits identify the network prefix.

sysctl

A Linux interface for viewing and changing kernel parameters.

GRUB

The bootloader that can pass parameters to the Linux kernel during startup.

Netplan

Ubuntu’s network configuration layer for defining interface settings.

 

If you are working with another Linux distribution, see HostSailor’s guide to disabling IPv6 on a CentOS server.

Why Does Ubuntu Enable IPv6 by Default?

How IPv6 Fits Into Modern Networking and Cloud Infrastructure

Ubuntu supports IPv6 by default because IPv6 is now a normal part of modern network infrastructure. Google tracks IPv6 deployment continuously, while Internet Society reported that native IPv6 access to Google crossed 50% on March 28, 2026.

Turning off IPv6 affects more than just unused addresses. It can change how apps find destinations, pick routes, discover nearby devices, and work with dual-stack services.

Why Most Hosting Providers Assign IPv6 Automatically

Hosting providers now often give you IPv6 addresses along with IPv4 because IPv6 allows for much larger address blocks. For example, a /64 block is common for VPS setups and gives administrators plenty of space for modern servers and apps.

HostSailor’s current KVM plans, for example, list a /64 IPv6 allocation alongside IPv4 connectivity.

IPv6 On or Off: How to Decide for Your Server

There is no reason to disable IPv6 simply because your current website primarily uses IPv4. Base the decision on the server’s applications, network design, security controls, and compatibility requirements.

When Disabling IPv6 Makes Sense

If you are asking, "Should I disable IPv6?" reasonable cases include temporary troubleshooting, legacy applications with broken IPv6 behavior, or an environment intentionally designed as IPv4-only. It also makes sense to disable IPv6 if you never use it and can’t monitor or secure it. Still, document your decision and confirm no services need IPv6 before turning it off.

When You Should Keep IPv6 Enabled

Keep IPv6 enabled when the server actively uses dual-stack networking, receives IPv6 traffic, or depends on services that expect IPv6 support. You should also keep it when your security tools already monitor both protocols. IPv6 should receive the same access controls and segmentation policies as IPv4. See HostSailor’s guide to Zero Trust security for servers for wider server security principles.

 

Factor

IPv6 On

IPv6 Off

Security posture

Secure when firewall rules and monitoring cover IPv6

Removes IPv6 connectivity but does not replace security controls

Performance / speed

Uses IPv6 paths where available

No guaranteed performance improvement

Legacy network compatibility

Some old systems may require extra configuration

Can simplify specific IPv4-only legacy environments

Cloud and IoT readiness

Better suited to modern dual-stack infrastructure

May restrict IPv6-dependent workloads

Windows Server / Exchange dependency

Preserves expected IPv6 functionality

Can cause compatibility problems

Ongoing maintenance effort

Requires IPv6 firewalling and monitoring

Requires tracking dependencies and future re-enablement

Microsoft specifically recommends against entirely disabling IPv6 in modern Windows Server environments because some Windows components can stop functioning correctly.

Common Myths About Disabling IPv6 for Security

Myth: Turning Off IPv6 Automatically Makes a Server Safer

Disabling IPv6 removes one protocol from the server, but that alone does not create a secure environment. Firewalls, patching, access controls, monitoring, and network segmentation still matter.

NIST’s IPv6 deployment guidance focuses on understanding IPv6-specific risks and applying suitable security controls rather than treating the protocol itself as the vulnerability.

Myth: Disabling IPv6 Speeds Up Your Internet Connection

Disabling IPv6 does not automatically make an Ubuntu server faster. Network performance depends on routing, latency, congestion, peering, application behavior, and upstream connectivity.

A poorly functioning IPv6 path can cause individual connectivity problems. Diagnose that rather than treating it as proof that IPv6 itself reduces performance.

Myth: IPv6 Is Optional for Cloud and IoT Workloads

Not every cloud or IoT workload requires IPv6, but support for it is increasingly widespread. Disabling IPv6 without reviewing dependencies can limit compatibility and create extra work in the future. For an IPv6 Ubuntu server, keeping dual-stack support is usually more flexible unless the environment has a documented reason to operate IPv4-only.

Testing an IPv6 configuration before changing a live server is much safer when you have full root access. HostSailor’s KVM VPS NVMe plans provide that level of server control with IPv6 support.

How to Check If IPv6 Is Enabled on Ubuntu

Check the current state before changing anything. You need to know whether the server has IPv6 addresses, listening services, and kernel-level IPv6 enabled.

Checking IPv6 Status With the ip Command

Start with:

ip a

For IPv6 addresses only:

ip -6 addr show

You can also check which TCP and UDP services are listening on IPv6:

ss -6 -tuln

If global or link-local IPv6 addresses appear, IPv6 networking is active on at least one interface.

Checking Kernel Parameters With sysctl

Check the kernel’s global IPv6 disable state:

cat /proc/sys/net/ipv6/conf/all/disable_ipv6

A value of 0 means IPv6 is enabled. A value of 1 means IPv6 has been disabled through that kernel parameter.

This check is useful before and after using the sysctl disable_ipv6 methods below.

How to Disable IPv6 on Ubuntu

These methods also apply when researching how to disable IPv6 Ubuntu 24.04. Choose the method based on whether you need a temporary test, a persistent server-wide change, a kernel-level disable, or a one-interface change.

Method 1: Disable IPv6 Temporarily With sysctl

Use this approach for testing because the settings do not persist after a reboot.

sudo sysctl -w net.ipv6.conf.all.disable_ipv6=1

sudo sysctl -w net.ipv6.conf.default.disable_ipv6=1

sudo sysctl -w net.ipv6.conf.lo.disable_ipv6=1

The net.ipv6.conf.all.disable_ipv6 parameter disables IPv6 on current interfaces. The default setting affects interfaces created afterward.

Since this method is temporary, it is useful when you need to confirm whether IPv6 is actually causing an application or connectivity problem.

Method 2: Disable IPv6 Permanently With sysctl.conf

To disable IPv6 permanently on Ubuntu, create a dedicated sysctl configuration file:

sudo tee /etc/sysctl.d/99-disable-ipv6.conf <<EOF

net.ipv6.conf.all.disable_ipv6 = 1

net.ipv6.conf.default.disable_ipv6 = 1

net.ipv6.conf.lo.disable_ipv6 = 1

EOF

sudo sysctl --system

This persists after reboot but remains easier to reverse than a kernel boot parameter. If you really need to turn off IPv6 across your whole Ubuntu server, this is the easiest long-term method.

Method 3: Disable IPv6 at Boot With GRUB

For a complete kernel-level disable, pass ipv6.disable=1 during boot.

sudo nano /etc/default/grub

# Change: GRUB_CMDLINE_LINUX_DEFAULT=""

# To: GRUB_CMDLINE_LINUX_DEFAULT="ipv6.disable=1"

sudo update-grub

sudo reboot

If GRUB_CMDLINE_LINUX_DEFAULT already contains parameters, append ipv6.disable=1 rather than removing the existing values.

This method needs a reboot. Only use it if you want IPv6 to be completely unavailable from the moment the system starts.

Method 4: Disable IPv6 for a Single Interface With Netplan

Disabling IPv6 with Netplan is best if you only want to turn it off for one network interface.

First, identify the relevant YAML file under /etc/netplan/. For an interface such as ens3, the configuration can include:

network:

 version: 2

 ethernets:

   ens3:

     dhcp4: true

     dhcp6: false

     accept-ra: false

     link-local: []

accept-ra: false prevents automatic IPv6 configuration through Router Advertisements. link-local: [] prevents link-local addresses from being created.

Remove any static IPv6 addresses from that interface’s existing configuration as well. Then apply the modified Netplan configuration:

sudo netplan apply

Netplan’s official documentation uses accept-ra: false with an empty link-local list to disable automatic IPv6 configuration on an interface.

Be cautious when applying network changes over SSH. A configuration mistake can terminate your remote session.

Method

Persists after reboot

Reversible without reboot

Best use case

sysctl runtime

No

Yes

Quick testing

sysctl.conf

Yes

Yes

Most production servers

GRUB

Yes

No

Full kernel-level disable

Netplan

Yes

Depends on configuration

Disable IPv6 on one interface

How to Re-Enable IPv6 on Ubuntu

Disabling IPv6 is reversible. You do not need to reinstall Ubuntu if testing shows that your applications work better with IPv6 enabled.

Reversing sysctl Changes

To enable IPv6 Ubuntu kernel settings again:

sudo sysctl -w net.ipv6.conf.all.disable_ipv6=0

sudo sysctl -w net.ipv6.conf.default.disable_ipv6=0

sudo sysctl -w net.ipv6.conf.lo.disable_ipv6=0

sudo rm /etc/sysctl.d/99-disable-ipv6.conf

sudo sysctl --system

If you changed Netplan, restore the previous IPv6 settings and apply the configuration again.

Reversing GRUB Changes

Open the GRUB configuration:

sudo nano /etc/default/grub

# Remove ipv6.disable=1 from GRUB_CMDLINE_LINUX_DEFAULT

sudo update-grub

sudo reboot

After rebooting, run ip -6 addr show to make sure IPv6 addresses are back.

Securing IPv6 Instead of Disabling It

For many servers, the better answer is to secure IPv6 properly. Treat it as part of the production network rather than as an unused secondary protocol.

Setting Up UFW Rules for IPv6 Traffic

Check that UFW processes IPv6 rules:

sudo nano /etc/default/ufw

# Confirm: IPV6=yes

sudo ufw allow ssh

sudo ufw enable

sudo ufw status verbose

Allow SSH before enabling UFW on a remote server. Otherwise, an incorrect rule can lock you out.

Apply equivalent protections to IPv4 and IPv6. This includes service-specific firewall rules, logging, access control, and DDoS protection and mitigation where appropriate.

Filtering ICMPv6 Without Breaking Connectivity

Do not blindly block all ICMPv6 traffic. IPv6 relies on ICMPv6 for important functions, including Neighbor Discovery and Path MTU Discovery.

NIST recommends treating IPv6 security as a planned deployment issue with controls suited to the protocol. Firewall policies should allow required ICMPv6 messages while filtering traffic that does not serve an operational purpose.

Watching for Shadow IPv6 Activity

A common security problem appears when IPv6 is active but excluded from monitoring or firewall policy. Services may become reachable over IPv6 even though administrators only review IPv4 exposure.

A 2026 global IPv6 measurement study identified more than 281 million active IPv6 network periphery devices. It also found exposed services and millions of devices affected by routing-loop behavior.

The main takeaway is simple: keep track of your IPv6 interfaces and services, set up firewall rules, and include IPv6 in your vulnerability scans and logs.

IPv6 on VPS, Cloud, and Dedicated Servers

Why HostSailor VPS Plans Include a /64 IPv6 Block

A VPS is a useful environment for testing dual-stack networking because administrators have root-level control over interfaces, firewalling, DNS, and server services. HostSailor’s KVM NVMe plans currently list both IPv4 and a /64 IPv6 allocation. They also provide KVM virtualization and full server control.

If you are migrating from shared to VPS hosting, review IPv6 firewall rules and application bindings during the migration rather than copying only the IPv4 configuration.

IPv6 Considerations for Dual-Stack Dedicated Servers

A dual-stack dedicated server needs the same operational discipline as a VPS. Confirm IPv6 routes, DNS AAAA records, listening services, firewall rules, monitoring coverage, and upstream filtering.

The larger address space does not remove the need for access control. Administrators using Netherlands dedicated servers should document both IPv4 and IPv6 network paths as part of normal server management.

IPv6 On or Off: Quick Decision Checklist

Disable IPv6 if…

Keep IPv6 enabled if…

You are temporarily isolating an IPv6-specific fault

Your server actively accepts IPv6 traffic

A confirmed legacy dependency cannot operate correctly with IPv6

You operate a normal dual-stack environment

The server is intentionally IPv4-only and dependencies are documented

Cloud, application, or security services expect IPv6

You have verified no IPv6-only DNS or service dependency exists

Your firewall and monitoring already support IPv6

You have a tested rollback plan

You want to avoid unnecessary future migration work

 

The Bottom Line

For most Ubuntu servers, IPv6 should stay enabled and receive the same firewalling, monitoring, and security attention as IPv4. Disabling it makes sense for specific compatibility tests or deliberately IPv4-only environments, not as a general security shortcut.

When disabling IPv6 is necessary, choose the least disruptive method and verify that applications, DNS, SSH, and routing still work afterward. For an Ubuntu-ready environment with root-level network control, you can explore HostSailor VPS plans or talk to the support team.

 

Frequently Asked Questions About IPv6 Pros and Cons

Will disabling IPv6 break SSH access to my Ubuntu server?

It depends on how you connect. If SSH is available over IPv4 and you use an IPv4 address or an A record, access should continue. If your client connects through an IPv6 address or AAAA-only hostname, disabling IPv6 will terminate that route and may lock you out.

Do I need to disable IPv6 on both the VPS and my local router?

No. Disabling IPv6 on your Ubuntu VPS only affects that server, not your whole local network. Change your router settings only if you want to remove IPv6 from the entire network. Always check the problem’s scope before changing several devices at once.

Does disabling IPv6 affect Docker or containerized applications?

It can. Containers, overlay networks, DNS, or published services might use IPv6 if set up that way. Check your Docker and app network settings first. Turning off IPv6 on the host can break container connections, even if the main app seems to use only IPv4.

Is it safe to disable IPv6 on a live production server without testing first?

It’s not recommended. Disabling IPv6 can affect remote management, DNS, monitoring, containers, or outside services. Test your method on a non-production server first. Make sure you have console access and rollback steps ready before changing networking on a live VPS.

 

Reliable Hosting You Can Trust

Experience lightning-fast, secure hosting that easily scales as your business grows, empowering you to succeed online effortlessly.

Start Hosting Now

Join Our Newsletter

Your information will never be Shared with third parties, and you can unsubscribe from our updates at any time.