Lesson 087 · AWS Learning Path

AWS 087: IPv6 networking

· Published · 9 min read

A dual-stack VPC carries separate IPv4 and IPv6 paths to public, outbound-only, and private destinations

The real problem

A team recognizes the name IPv6 networking but has not connected the feature to a real requirement, identity boundary, network or data path, failure mode, price dimension, and cleanup owner. A plausible configuration could still fail the workload.

Final outcome

The learner will produce a requirement-led artifact for IPv6 networking, inspect the matching AWS control plane in the Management Console, run a matching CloudShell or AWS CLI query, interpret the output, diagnose one failure, defend one architecture choice, and prove cleanup or approved retained state.

The practical outcome is not a command transcript. It must show what was expected, what happened, what the result proves, what it does not prove, and which evidence would change the decision.

Learning objectives

By the end of this lesson, the learner can:

  • explain ipv6 addresses are globally unique;
  • explain vpc and subnet sizes are standardized;
  • explain dual-stack means two independent paths;
  • explain internet gateways permit eligible two-way routing;
  • explain egress-only igw blocks inbound initiation;
  • connect control-plane state to the real data, network, identity, or application behavior;
  • identify cost and cleanup ownership before any optional mutation;
  • troubleshoot from evidence without opening broad access or adding broad permissions.

Relationship model

Requirement
   |
   v
Identity and policy -> AWS configuration -> network or data path -> workload behavior
        |                    |                      |                    |
        +--------------------+----------------------+--------------------+
                                      |
                                      v
                         monitoring, cost, recovery, cleanup

Use this model to separate an AWS object that exists from a result that actually works. Every arrow is a verification boundary.

Prerequisites, permissions, Region, and safety

  • Learning baseline: This sequence assumes practical Linux knowledge but no prior cloud-computing or AWS knowledge. Cloud, networking, security, data, automation, and architecture concepts must come from completed earlier lessons. If a prerequisite checkpoint is incomplete, return to its linked lesson before continuing.
  • Confirm a non-root caller with aws sts get-caller-identity and keep the account number private.
  • Use ap-south-1 unless this lesson explicitly names a second Region.
  • Confirm the intended profile and Region with aws configure list before interpreting an empty result.
  • Use read-only List, Get, and Describe permissions for the named services. Design exercises run locally and require no resource-creation permission.
  • This is a no-create lesson. Console and CLI work is read-only, and every design artifact is created locally.
  • Never publish account IDs, public addresses, ARNs containing private account data, session IDs, presigned URLs, object data, credentials, or KMS material.
  • Do not use root, world-open SSH or RDP, disabled TLS verification, unowned resources, or irreversible retention controls in a training exercise.

Core model

ConceptWhat the learner must understand
IPv6 addresses are globally uniqueAWS VPC IPv6 does not use RFC1918-style private addressing. A resource is not publicly reachable unless routing and security controls allow the path.
VPC and subnet sizes are standardizedAn Amazon-provided VPC IPv6 block is normally /56 and IPv6 subnets are /64. AWS also reserves addresses at the start and end of each subnet range.
Dual-stack means two independent pathsA dual-stack resource has IPv4 and IPv6. DNS, routes, security groups, NACLs, firewalls, load balancers, and application listeners must cover both protocols.
Internet gateways permit eligible two-way routingA ::/0 route to an internet gateway enables internet routing for IPv6, subject to security. There is no public-to-private IPv6 NAT mapping.
Egress-only IGW blocks inbound initiationIt is a stateful VPC component for outbound-initiated IPv6 internet connections. Response traffic returns, while unsolicited internet initiation is not allowed.
DNS64 and NAT64 bridge IPv6-only clients to IPv4Route 53 Resolver can synthesize AAAA answers from A records, and NAT Gateway translates the resulting IPv6 destination to IPv4.

How it works

Adding IPv6 can create a second security path. A workload protected by an IPv4-only allow list may still be reachable over IPv6 if ::/0 routes and IPv6 security rules are broader. Include IPv6 in asset inventory, logging, WAF, firewall, DNS, and incident procedures.

Read the result in layers:

  1. Scope: account, Region, VPC, bucket, AZ, endpoint, principal, object version, or resource ARN.
  2. Control plane: the requested configuration exists and reached an expected state.
  3. Behavior: the request, connection, health check, replication, restore, or application result meets the requirement.
  4. Operations: monitoring, failure owner, cost, retention, rollback, and cleanup are known.

Control-plane success is necessary but not sufficient. A resource can be available while policy, routing, DNS, health, data, or application behavior remains wrong.

Architecture decision table

RequirementPreferred directionWhy
Public dual-stack applicationIPv4 and IPv6 DNS, routes, listeners, and controlsBoth protocols must reach equivalent protected entry points.
Private IPv6 workload needs outbound internet onlyEgress-only internet gatewayIt preserves outbound initiation without NAT address conservation.
IPv6-only client needs an IPv4 serviceDNS64 plus NAT64 through NAT GatewayThe resolver synthesizes and the gateway translates the protocol path.
Dependency does not support IPv6Keep dual-stack during migrationThe workload can prefer IPv6 while retaining IPv4 compatibility.

Professional questions normally contain several valid services. State the requirement that selects one option, why the nearest alternative fails it, and what changed requirement would reverse the choice.

AWS Management Console guided practice

Before opening a service page, write the expected account, Region, starting state, and evidence. Do not choose Create, Save, Purchase, Lock, or Delete unless the lesson explicitly authorizes the live track.

  1. Open VPC Your VPCs and inspect the IPv6 CIDR association.
  2. Open Subnets and verify the /64 association and automatic IPv6 assignment setting.
  3. Open route tables, security groups, and network ACLs and inspect IPv6 entries separately, including ::/0 to an internet or egress-only internet gateway.

For each step, capture the field name and value in text. A screenshot may support the record but does not replace the explanation. Console labels can evolve, so use the service search and current documentation if a navigation label differs.

CloudShell and AWS CLI practice

CloudShell is the default browser-based command environment taught in AWS 028. AWS 029 and AWS 030 cover local CLI installation and authentication. This lesson therefore does not assume that an unconfigured local shell is ready.

Start every session with:

export AWS_DEFAULT_REGION="ap-south-1"
aws sts get-caller-identity --query Arn --output text
aws configure list

Redact the account portion of the ARN before sharing. Then perform the topic query:

Inventory IPv6 assignment and every ::/0 route before calling a subnet private.

aws ec2 describe-subnets --subnet-ids subnet-0123456789abcdef0 --query 'Subnets[0].{Ipv6:Ipv6CidrBlockAssociationSet[].Ipv6CidrBlock,AutoAssign:AssignIpv6AddressOnCreation,Dns64:EnableDns64}'
aws ec2 describe-route-tables --filters Name=association.subnet-id,Values=subnet-0123456789abcdef0 --query 'RouteTables[0].Routes[?DestinationIpv6CidrBlock!=null]'

Expected interpretation:

A subnet can be private for IPv4 and internet-routed for IPv6. Evaluate protocol-specific routes and rules separately.

Replace every replace-with-... sample value before running its command, and use only an explicitly owned resource. Explain each option first. These queries are read-only; a successful response does not authorize a later create or delete operation.

Practical work

Create p05-ipv6-plan.md. Allocate a hypothetical Amazon-provided IPv6 CIDR, assign one /64 to each P05 subnet, define public ::/0 through an internet gateway and private outbound-only ::/0 through an egress-only internet gateway, then add separate SG, NACL, DNS, logging, and client evidence. Explain why NAT Gateway is not the ordinary IPv6 egress design.

The evidence package must contain:

  • the problem and final requirement in the learner's own words;
  • caller type and Region with private identifiers redacted;
  • exact planned values, ownership, and cost class;
  • one Console observation and matching CLI or API evidence;
  • one behavior result or supplied data-plane record;
  • one denied, failed, or counterexample result and evidence-led diagnosis;
  • one architecture choice plus the rejected alternative;
  • cleanup proof or explicit retained-state owner, expiry, and next lesson.

Verification standard

Use expected state before observed state. Record timestamps in UTC and preserve the original failure before changing anything. A passing submission answers all four questions:

  1. What exact requirement was tested?
  2. Which evidence proves the AWS configuration?
  3. Which evidence proves the workload behavior?
  4. What remains unproven or requires later monitoring?

If AWS returns no rows, verify account, Region, permission, filters, pagination, resource type, and deletion state before concluding that nothing exists.

Common failures and troubleshooting

SymptomEvidence firstLikely boundarySmallest safe response
object appears missingcaller, Region, filters, pagination, tagsscope or read permissionalign scope before creating a duplicate
state remains pending or unavailableservice state, events, dependencies, quotasdependency or capacitycorrect the named dependency and wait with a bound
AccessDeniedprincipal, action, resource, explicit-deny contextidentity, resource, endpoint, organization, or KMS policychange only the proven policy layer
configuration exists but behavior failsroute, DNS, security, listener, health, logs, object versiondata path or applicationtest the next boundary and change one control
bill is higher than expectedhours, bytes, requests, AZs, addresses, retentioncost model or retained resourcestop optional work and reconcile the ledger
cleanup is blockeddependency inventory and owning servicedeletion order or immutable stateremove owned dependants in reviewed reverse order

Do not troubleshoot by attaching administrator access, opening administration ports to the internet, disabling encryption, retrying uncontrolled creation, deleting unknown resources, or weakening retention.

Cost, cleanup, and retained state

No AWS resource is created. Close CloudShell and remove or redact downloaded evidence.

Cleanup evidence requires terminal state and an after-inventory. Search related ENIs, public IPv4 addresses, EBS volumes and snapshots, load balancers, target groups, Auto Scaling instances, endpoints, logs, S3 versions and delete markers, backup recovery points, and global IAM roles when they apply. Billing data can lag, so schedule a later review.

Architecture and certification decisions

  • Certification coverage: SAA-C03; SOA-C03; SAP-C02; DOP-C02.
  • Exam mapping: SAA D1-D3.
  • Explain service scope, failure boundary, consistency, recovery, security, operations, and price rather than matching a keyword.
  • Treat availability and durability, encryption and authorization, routing and filtering, health and lifecycle, backup and replication, and discount and capacity as separate concepts.
  • Do not reproduce protected certification questions.

Knowledge check

  1. Does an IPv6 address make an instance publicly reachable by itself?

Expected direction: No. Routing, security groups, NACLs, and the listening service must permit inbound access.

  1. What route represents default IPv6?

Expected direction: ::/0.

  1. Does an egress-only internet gateway perform NAT?

Expected direction: No. It controls initiation direction while preserving IPv6 addresses.

  1. What two features let IPv6-only clients reach IPv4-only destinations?

Expected direction: DNS64 synthesizes the IPv6 answer and NAT64 on NAT Gateway translates the traffic.

Completion gate and assessment

AreaPointsPassing evidence
Requirement and model15Correct scope, terminology, and final outcome
Console evidence15Current path and interpreted fields
CLI or API evidence15Scoped command, expected result, and limitations
Behavior or decision exercise20Reproducible result or defensible architecture reasoning
Troubleshooting15Original symptom, hypothesis, one change, retest, rollback
Security and cost10Least privilege, data protection, current price dimensions
Cleanup and handoff10Terminal-state proof or approved retained-state record

Pass at 80 out of 100 with no critical safety failure. A missing practical artifact, unexplained output, unsafe access, destructive action outside the owned scope, unplanned billed resource, or false cleanup claim requires remediation and a changed retest.

Official sources

Advertisement