LogicGates.org Open the simulatorSimulator

IPv6 expand and compress

Paste an IPv6 address in any form to get it written out in full and in the one canonical short form of RFC 5952, with every rule that changed it, all 128 bits, its prefix and what kind of address it is.

Any case, with or without leading zeros and ::. A /prefix, a %zone, an IPv4 tail such as ::ffff:192.0.2.1 and square brackets with a port are all understood.

Compressed (RFC 5952) 2001:db8::8:800:200c:417a/64
Expanded 2001:0db8:0000:0000:0008:0800:200c:417a/64

You typed 2001:0DB8:0000:0000:0008:0800:200C:417A, which is not the canonical form. Documentation (2001:db8::/32).

How the short form is made

Each group as typed, written in full, then as it appears in the short form.

  1. Group 1 typed: 2001 in full: 2001 short form: 2001
  2. Group 2 typed: 0DB8 in full: 0db8 short form: db8
  3. Group 3 typed: 0000 in full: 0000 short form: in ::
  4. Group 4 typed: 0000 in full: 0000 short form: in ::
  5. Group 5 typed: 0008 in full: 0008 short form: 8
  6. Group 6 typed: 0800 in full: 0800 short form: 800
  7. Group 7 typed: 200C in full: 200c short form: 200c
  8. Group 8 typed: 417A in full: 417a short form: 417a
  1. Lower case (section 4.3). The letters a to f are written in lower case.
  2. Drop leading zeros (section 4.1). 0DB8 → db8, 0000 → 0, 0000 → 0, 0008 → 8, 0800 → 800. A group of all zeros keeps one 0.
  3. Replace the longest run of zeros with ::. The run of zeros, groups 3 to 4, becomes ::, covering the whole run (section 4.2.1).

All 128 bits

The first 64 bits are the network prefix (bold, solid underline); the other 64 identify the address inside it (dotted underline).

The /64 network

Network prefix
2001:db8::/64
First address
2001:db8::
Last address
2001:db8::ffff:ffff:ffff:ffff
Addresses
2to the power 64 = 18,446,744,073,709,551,616
/64 networks
2to the power 0 = 1
Mask
ffff:ffff:ffff:ffff::

The address has bits set after the first 64, so it is one address inside the network rather than the network itself.

Address type: Documentation

2001:db8::/32, RFC 3849. Reserved for examples in books, manuals and RFCs, like 192.0.2.0/24 in IPv4, so an example can never be someone’s real address. It is never routed.

MAC address to EUI-64 interface identifier

Stateless autoconfiguration (SLAAC) traditionally built the last 64 bits of an address from the network card's 48-bit MAC address, using the modified EUI-64 format of RFC 4291: split the MAC in half, put ff:fe in the middle, and flip one bit.

Six bytes in hex, written 00:1a:2b:3c:4d:5e, 00-1A-2B-3C-4D-5E, 00 1a 2b 3c 4d 5e, 001a.2b3c.4d5e or with no separators.

  1. Split the MAC in half 001a2b3c4d5e
  2. Insert ff:fe in the middle 001a2bfffe3c4d5e
  3. Flip the universal/local bit (the seventh bit of the first byte) 00000000 00000010 00 XOR 02 = 02
  4. Group into four hextets: the interface identifier 021a:2bff:fe3c:4d5e
  5. Put fe80::/64 in front: the link-local address fe80::21a:2bff:fe3c:4d5e

This MAC is a universally administered, manufacturer-assigned one (the bit was 0), so the identifier's bit becomes 1, meaning "globally unique". The flip is there so that hand-numbered identifiers such as ::1 and ::2 read as local without anyone having to set that bit. On a global prefix the same identifier follows the prefix, for example 2001:db8:1:2:21a:2bff:fe3c:4d5e.

Many systems now pick the interface identifier at random instead (RFC 8981 temporary addresses, RFC 7217 stable ones), because an EUI-64 identifier reveals the MAC address and follows a device from network to network.

How IPv6 addresses are written

An IPv6 address is 128 bits, written as eight groups of 16 bits, each group as four hex digits separated by colons. One hex digit is four bits, so a group is four digits and the whole address is 32 of them. Written out in full, that is long, so RFC 4291 allows two shorthands:

  • Leading zeros in a group can go. 0db8 can be written db8, 0042 as 42 and 0000 as 0. Trailing zeros stay: db80 is a different number.
  • One run of zero groups can become ::. The reader counts the groups that are written and fills the gap with as many zero groups as it takes to make eight, which is why :: may appear only once.

Those rules allow many spellings of the same address, which makes searching logs and comparing configurations unreliable. RFC 5952 therefore picks one canonical form, the one this page produces:

  1. Lower case hex digits (section 4.3).
  2. No leading zeros; a zero group is a single 0 (section 4.1).
  3. :: must be used to its full extent: it covers the whole run of zeros it replaces (section 4.2.1).
  4. :: is not used for a single zero group (section 4.2.2).
  5. :: replaces the longest run of zero groups; if two runs are equally long, the first one (section 4.2.3).
  6. IPv4-mapped addresses keep their last 32 bits in dotted decimal (section 5). RFC 5952 recommends that for other formats that carry an IPv4 address too, such as NAT64's 64:ff9b::192.0.2.33; this tool, like glibc's inet_ntop, writes those in hex and shows the IPv4 address under the address type.

The rules on real examples

Each row worked out by the same code as the tool above. Select one to see its steps.

Written asCanonicalWhy
2001:0db8:0000:0000:0000:0000:0002:0001 2001:db8::2:1 Leading zeros dropped and groups 3 to 6 become ::
2001:db8::0:1 2001:db8::1 The :: did not cover the whole run of zeros, so it grows to groups 3 to 7 (section 4.2.1)
2001:db8:0:1:1:1:1:1 2001:db8:0:1:1:1:1:1 A single zero group stays 0
2001:0:0:1:0:0:0:1 2001:0:0:1::1 The longer run, groups 5 to 7, becomes ::
2001:db8:0:0:1:0:0:1 2001:db8::1:0:0:1 2 runs of 2 zero groups tie, so the first, groups 3 to 4, becomes ::
FE80:0:0:0:0:0:0:1 fe80::1 Letters in lower case and groups 2 to 7 become ::
0:0:0:0:0:ffff:c000:0201 ::ffff:192.0.2.1 Groups 1 to 5 become :: and the last 32 bits are written as the IPv4 address 192.0.2.1

IPv6 address types

The ranges the tool recognises, checked from the most specific down: an address takes the first range it falls in. Every address the tool does not place in one of these is outside 2000::/3 and reserved.

Range Type Example What it is for
::/128 Unspecified
RFC 4291
:: All zeros: no address at all. A host uses it as its source before it has an address, and a server listening on :: accepts connections to any of its addresses.
::1/128 Loopback
RFC 4291
::1 The machine itself, like 127.0.0.1 in IPv4. Packets sent to it never leave the host.
::ffff:0.0.0.0/96 IPv4-mapped
RFC 4291
::ffff:192.0.2.1 An IPv4 address in IPv6 clothing, so one IPv6 socket can serve IPv4 clients too: the IPv4 client 192.0.2.1 shows up as ::ffff:192.0.2.1. The last 32 bits are the IPv4 address.
64:ff9b::/96 NAT64 well-known prefix
RFC 6052
64:ff9b::c000:221 Lets an IPv6-only host reach an IPv4 server through a NAT64 translator. The last 32 bits are the IPv4 address it stands for.
2001::/32 Teredo
RFC 4380
2001:0:4136:e378:8000:63bf:3fff:fdd2 Teredo tunnelled IPv6 over UDP through IPv4 NAT. The next 32 bits are the Teredo server's IPv4 address; the last 48 bits are the client's public port and IPv4 address with every bit inverted.
2001:db8::/32 Documentation
RFC 3849
2001:db8::1 Reserved for examples in books, manuals and RFCs, like 192.0.2.0/24 in IPv4, so an example can never be someone’s real address. It is never routed.
2002::/16 6to4
RFC 3056
2002:c000:204::1 6to4 tunnelling gave every public IPv4 address its own /48: the 32 bits after 2002 are the IPv4 address of the site’s tunnel end.
fe80::/10 Link-local unicast
RFC 4291
fe80::1 Valid only on one link, such as one Ethernet segment or Wi-Fi network; routers never forward it. Every IPv6 interface has one, and since every interface is on fe80::/64, a zone ID such as %eth0 says which link is meant.
fec0::/10 Site-local (deprecated)
RFC 3879
fec0::1 The original private range, deprecated because "site" was never well defined. Unique local addresses replaced it.
fc00::/7 Unique local
RFC 4193
fd12:3456:789a::1 Private addresses, the IPv6 counterpart of 10.0.0.0/8. Not routed on the internet. In practice they start fd, followed by a random 40-bit global ID so that two private networks are unlikely to clash when joined.
ff00::/8 Multicast
RFC 4291
ff02::1 One to many: a packet sent to a multicast group reaches every interface that has joined it. IPv6 has no broadcast; it uses multicast groups such as ff02::1 (every node on the link) instead.
2000::/3 Global unicast
RFC 4291
2606:4700:4700::1111 An ordinary public address, routed on the internet. Every address from 2000:: to 3fff:ffff:… is in this range; a network usually gets a /48 or /56 and splits it into /64s.

Prefix lengths and how much they hold

The prefix length says how many leading bits name the network; the rest number the addresses in it. Each bit fewer doubles the size. These are the sizes that come up most:

Prefix Addresses /64 networks Typical use
/32 2to the power 96 4,294,967,296 A typical allocation to an internet provider or large organisation
/48 2to the power 80 65,536 A site, such as an office or campus
/56 2to the power 72 256 A common size for a home connection
/64 2to the power 64 1 One network (a LAN or VLAN); SLAAC needs exactly /64
/127 2to the power 1 – A point-to-point link between two routers (RFC 6164)
/128 2to the power 0 – A single address, such as a loopback or one host route

IPv6 subnetting splits on these boundaries, often on whole hex digits (4 bits) so that subnets line up with the written groups. For the IPv4 version, with every mask and host count, see the subnet calculator and the VLSM calculator.

Common mistakes

  • Using :: twice. 2001:db8::1::1 is invalid, because there is no telling how the four missing zero groups are shared between the gaps: it could be 2001:db8:0:1:0:0:0:1, 2001:db8:0:0:1:0:0:1, 2001:db8:0:0:0:1:0:1.
  • Dropping trailing zeros. Only leading zeros may go: 2001:db8:1:: and 2001:db8:1000:: are different addresses.
  • Shortening a single zero group to ::. Allowed by RFC 4291 but not canonical: 2001:db8::1:1:1:1:1 should be written 2001:db8:0:1:1:1:1:1.
  • Putting a port straight after the address. In 2001:db8::1:443 the 443 is read as one more hex group, which makes a valid but different address. With a port, wrap the address in brackets: [2001:db8::1]:443, as URLs do.
  • An IPv4 tail in the middle. A dotted IPv4 part stands for the last 32 bits, so it can only come at the end: ::ffff:192.0.2.1, never 192.0.2.1::1.
  • Converting the IPv4 part as one decimal number. Each of the four numbers is a byte, two hex digits: 192.0.2.1 is c0.00.02.01, so the groups are c000:0201. The hex to decimal converter does the byte conversions, and the hex to binary converter shows the bits behind each digit.

Questions

How do I expand an IPv6 address?

Put back what the two shorthands removed. Pad every group with leading zeros to four hex digits, then replace :: with as many 0000 groups as it takes to make eight. ::1 has one written group, so the :: stands for seven, and the full form is 0000:0000:0000:0000:0000:0000:0000:0001.

What is the correct way to compress an IPv6 address?

RFC 5952 fixes one canonical form: lower case letters, no leading zeros in any group, and :: in place of the longest run of two or more zero groups, the first one if two runs are equally long. A single zero group stays as 0. So 2001:db8:0:0:1:0:0:1 is written 2001:db8::1:0:0:1.

Why can :: only appear once in an address?

Because the reader works out how many zero groups :: stands for by counting the groups that are written. With two of them the zeros could be shared out more than one way: 2001:db8::1::1 could be 2001:db8:0:1::1, 2001:db8::1:0:0:1, 2001:db8::1:0:1, three different addresses.

How many addresses are in a /64?

A /64 leaves 64 bits for the interface identifier, so it holds 2 to the power 64, which is 18,446,744,073,709,551,616 addresses. A /48 holds 65,536 of those /64 networks.

What does %eth0 after an address mean?

It is a zone ID (RFC 4007). Every interface has a link-local address in fe80::/10, and the same fe80 address can be valid on more than one link at once, so the zone names the interface to use: fe80::1%eth0 on Linux, or a number such as %12 on Windows. It is not part of the 128 bits and never appears in a packet.

What is an IPv4-mapped IPv6 address?

An IPv4 address written inside ::ffff:0.0.0.0/96 (the IANA registry writes it ::ffff:0:0/96), such as ::ffff:192.0.2.1 (0000:0000:0000:0000:0000:ffff:c000:0201 in full). Programs that use one IPv6 socket for both protocols see IPv4 clients this way. RFC 5952 recommends keeping the IPv4 part in dotted decimal.

Should IPv6 addresses be upper or lower case?

Software must accept both, since hex digits mean the same in either case. When writing an address out, RFC 5952 says lower case, so that the same address always looks the same in logs, configuration files and searches.