explainer
IPv6 Crossed 50%: A Practical Subnetting Guide for the Dual-Stack Era
By Uttam Regmi · Published 2026-07-07 · Updated 2026-07-07 · 6 min read · Fact-checked, sources cited
IPv6 stopped being the future in March 2026, when it crossed 50% of user traffic to Google, and subnetting it is genuinely easier than IPv4, once you unlearn one habit: stop counting hosts and start counting subnets. Every LAN is a /64, always; your job is only to decide how the bits between your allocation and /64 divide into networks. Do the math with the IPv6 subnet calculator, which handles the full 128 bits exactly.
The milestone, and why it matters for your network
Google has published the share of its users connecting over IPv6 since 2008. In late March 2026 that measurement crossed 50%, eighteen years from under 1% to majority, as the Internet Society noted. Mobile networks drove much of it: many carriers are IPv6-only internally, translating to reach legacy IPv4 services.
For anyone running a network, the practical consequence is that dual-stack is no longer optional hygiene, a misconfigured IPv6 subnet is now a majority-of-traffic problem, and “we’ll deal with v6 later” means ignoring how most of your users actually connect.
How an IPv6 address is structured
An IPv6 address is 128 bits, written as eight colon-separated groups of hex. In a typical global unicast address, the bits split into three jobs:
| Bits | Part | Who controls it |
|---|---|---|
| First 48 | Global routing prefix | Your ISP / RIR, identifies your site |
| Next 16 | Subnet ID | You, 65,536 possible LANs |
| Last 64 | Interface identifier | The device, via SLAAC, DHCPv6 or manually |
The last row of that table is the key fact: the interface identifier is always 64 bits, because SLAAC, the mechanism that lets devices configure their own addresses from router advertisements, requires it. That’s why the /64 is the indivisible unit of IPv6 networking. A “small” segment with two routers on it gets a /64. A point-to-point link gets a /64 (or /127 by some operators’ convention, a deliberate exception, not a habit). Your Wi-Fi with 40 devices gets a /64. There is no host-count math, ever.
Subnetting is just slicing the middle bits
If your ISP delegates a /56 to your home or small office, you own bits 57-64: eight bits, 256 possible /64s. A business /48 gives sixteen bits: 65,536 LANs. Planning a network is choosing how those bits split:
| You receive | Subnet bits to /64 | You can build |
|---|---|---|
| /48 (site) | 16 | 65,536 LANs |
| /52 | 12 | 4,096 LANs |
| /56 (typical home delegation) | 8 | 256 LANs |
| /60 (some home ISPs) | 4 | 16 LANs |
| /64 | 0 | exactly one LAN |
Two working rules keep plans sane:
- Subnet on nibble boundaries. Each hex digit is 4 bits, so prefixes at /52, /56, /60
align with whole digits, subnets then differ by one visible character
(
2001:db8:ab:10::/60,:20::,:30::), which humans can read and DNS can delegate cleanly. - Assign meaning to the subnet digits. With 65,536 subnets in a /48 there’s room for structure: a digit for the building, a digit for the VLAN type. Address plans can encode topology instead of rationing scraps, the IPv6 subnet calculator shows exactly how many /64s each choice yields.
A worked example: carving up a /48
Say a campus is assigned 2001:db8:abcd::/48. That leaves 16 subnet bits, four hex digits, between the prefix and the fixed /64. Instead of allocating those 65,536 LANs one at a time,
split the digits by meaning. A common scheme dedicates the first nibble to the site or building
and the remaining three to networks within it:
| Field | Hex digits | Example value | Meaning |
|---|---|---|---|
| Global prefix | , | 2001:db8:abcd | Assigned to the campus (/48) |
| Building | 1 | 1 | Building 1 of up to 16 |
| VLAN / purpose | 3 | 020 | Network 0x020 inside the building |
| Interface ID | , | ::/64 | 64 host bits, filled by SLAAC |
That yields addresses such as 2001:db8:abcd:1020::/64 for one LAN. Building 2’s matching network
is 2001:db8:abcd:2020::/64. You change a single readable character. Because every boundary sits
on a nibble, the prefixes stay legible, reverse-DNS zones delegate cleanly, and firewall rules can
match a whole building with one summarized prefix like 2001:db8:abcd:1000::/52. Compare that to
the IPv4 equivalent, where fitting the same structure into a private /16 means juggling
variable-length masks and constantly re-checking usable-host counts.
The habits to unlearn from IPv4
Conserving addresses. IPv4 scarcity trained everyone to squeeze: /30s on links, /28s for small VLANs, VLSM everywhere. In IPv6 that instinct produces broken networks (sub-/64 LANs break SLAAC) and unreadable plans. The address space is the one resource you genuinely have in excess, spend it on structure.
Equating NAT with security. IPv6 restores end-to-end addressing; there is no NAT to hide behind, and none is needed. The security NAT appeared to provide was really its side effect of statefulness, which your firewall does explicitly. Block unsolicited inbound by default, allow what you mean to allow.
Trusting text comparison. 2001:db8::1, 2001:0db8:0:0:0:0:0:1 and 2001:DB8::0001 are
the same address. Scripts that grep logs or diff ACLs against configs break on this constantly.
RFC 5952 defines one canonical form, lowercase,
longest zero-run compressed to ::, and the
expand/compress tool normalizes whole lists either way in one paste.
Side by side, the mindset shift is easy to summarize:
| Question | IPv4 answer | IPv6 answer |
|---|---|---|
| What’s the LAN size? | Whatever you can spare (/24, /28, /30…) | Always a /64 |
| What do you count? | Usable hosts per subnet | Subnets between your prefix and /64 |
| How do you get more room? | Beg for space, reuse RFC 1918, apply VLSM | Ask for a shorter prefix (/56, /48) |
| Where does inbound security live? | Often NAT plus a firewall | A stateful firewall alone |
| Text form of an address | One obvious form | Many spellings; normalize to RFC 5952 |
What stays the same
The v4 half of a dual-stack network still runs on classic subnet math, masks, usable-host counts, CIDR blocks, and it isn’t going anywhere soon: private RFC 1918 space, container networking and VPN configs are all heavy CIDR users. Keep the IPv4 subnet calculator and CIDR-to-range converter in reach for that half; the bit-exact answers matter precisely because subnet arithmetic is where mental math and language-model guesses go quietly wrong.
Quick summary
IPv6 crossing 50% of Google’s user traffic makes dual-stack the operating norm, and its subnetting model is simpler than IPv4’s once inverted: the /64 LAN is fixed, so planning is purely about slicing your delegated prefix (/48 → 65,536 LANs, /56 → 256) into readable, nibble-aligned subnets. Unlearn address conservation, let the firewall do the security NAT never really did, normalize addresses to RFC 5952 before comparing, and keep the v4 bit math for the other half of the stack. All of it computes exactly, in your browser, with the network tools.
Sources: APNIC, Google hits 50% IPv6 · Internet Society Pulse, IPv6 reaches majority · RFC 5952 (canonical text form) · Google IPv6 statistics
Frequently asked questions
How much of the internet actually uses IPv6 now?
As of 2026, more than half of user traffic to Google arrives over IPv6, the 50% milestone was crossed in March 2026, about 18 years after Google began measuring. Adoption varies widely by country: some ISPs and mobile networks are effectively IPv6-first, while others still lag.
Why is every IPv6 LAN a /64?
The 64-bit interface identifier is baked into the standards: SLAAC, the mechanism devices use to configure their own addresses, requires exactly 64 host bits. Subnetting a LAN smaller than /64 breaks address autoconfiguration, so the /64 is the universal unit of an IPv6 network segment.
How many subnets do I get from a /56 or /48?
Count the bits between your prefix and /64: a /56 has 8 subnet bits, so 256 possible /64 LANs; a /48 has 16, so 65,536. Nobody counts hosts per LAN in IPv6, every /64 already holds 18.4 quintillion addresses.
Do I still need NAT with IPv6?
No, every device can have a globally routable address, which restores end-to-end connectivity. Security is handled where it belongs, at the firewall: a stateful firewall that blocks unsolicited inbound traffic gives the same protection people wrongly attribute to NAT.
Why do the same IPv6 addresses look different in different tools?
IPv6 text notation allows dropping leading zeros and compressing runs of zero groups with ::, so one address has many spellings. RFC 5952 defines a single canonical form (lowercase, longest zero-run compressed). Normalize both sides before comparing address lists.
Should I abandon IPv4 subnetting skills?
No, dual-stack means running both. IPv4 subnet math (masks, usable hosts, CIDR splits) still governs the v4 half of every network, and container platforms and VPNs are heavy CIDR users. The skill set is additive: keep the v4 bit math, add the v6 mindset of counting subnets instead of hosts.