Skip to main content
IPv6

The newer internet addresses, guarded the same as the old ones

The world ran out of old-style IP addresses, so most internet providers now hand out IPv6 too. Firecradle sets it up for you — and blocks it by default, the same as everything else, so it never becomes the door nobody remembered to lock.

SLAAC · DHCPv6 · prefix delegation · default deny

Why IPv6 exists, and how Firecradle handles it

IPv4 addresses ran out years ago. IPv6 is the much larger replacement, and it needs to be set up and protected, not just switched on.

Room for everything
IPv6 has so many addresses that every device on Earth could have billions each. Nobody needs to share one address between several devices anymore.
Devices that set themselves up
With SLAAC, a device can build its own IPv6 address the moment it joins the network. No server has to hand one out.
DHCPv6, when you want more control
Prefer to hand out addresses centrally and keep a record of who has what? DHCPv6 works the same way regular DHCP does, just for IPv6.
A block of your own
With prefix delegation, your internet provider hands Firecradle a whole block of addresses, which it then shares out across your network.

The most common IPv6 mistake

A firewall that carefully blocks IPv4 but leaves IPv6 wide open is not rare. It happens because IPv6 gets switched on quietly, and nobody writes rules for it.

Firecradle treats IPv6 exactly like IPv4 from the start. Default deny applies to both. A device does not get reachable from the internet just because it picked up an IPv6 address nobody noticed. Rules, logs, and reports cover both address types on the same screen, so there is no second firewall to remember.

What it runs on

SLAAC + DHCPv6
Both address handout methods supported
Prefix delegation
Take a block from your provider automatically
Default deny
Applied to IPv6 exactly as it is to IPv4
Dual stack
Run IPv4 and IPv6 side by side

How people actually use this

A firewall that only guards half the front door

The problem: An office locks down every IPv4 port carefully, but nobody thought about IPv6. Devices with a public IPv6 address sit wide open to the internet.

What Firecradle does:
Firecradle applies the same default-deny rules to IPv6 as it does to IPv4
Nothing reaches an internal device on IPv6 unless a rule allows it
The same firewall screen manages both address types together
No separate IPv6 policy for staff to forget about

A new internet provider only gives an IPv6 line

The problem: A branch office is moved to a connection that hands out IPv6 addresses instead of the usual IPv4 ones, and none of the office equipment has been tested on it.

What Firecradle does:
Firecradle takes the IPv6 prefix from the provider automatically
Router advertisements and DHCPv6 hand addresses to office devices
Existing firewall rules carry over instead of starting from scratch
Staff notice nothing different day to day

Everything here is included

No add-on licence, no extra box

Full IPv6 addressing alongside IPv4, on the same interfaces
SLAAC for devices that set themselves up
DHCPv6 for centrally managed address handout
Prefix delegation, so a provider block gets shared automatically
Router advertisements sent to your own network
Default-deny firewall rules applied to IPv6, not just IPv4
One set of rules, logs, and reports for both address types

Common questions

Do I need to turn IPv6 on, or does it just appear?

Most internet providers now hand out an IPv6 connection alongside your regular one. Firecradle can pick it up automatically, but you stay in control of whether it is turned on.

If I do not use IPv6 on purpose, can it still be a risk?

Yes, and this is the biggest IPv6 mistake. Many devices turn on IPv6 by default even if nobody set it up. Firecradle blocks IPv6 traffic by default, the same as IPv4, so an unused IPv6 line is not an open door.

What is the difference between SLAAC and DHCPv6?

SLAAC lets a device build its own address with no server involved. DHCPv6 hands addresses out from a central point instead, which suits networks where you want a record of which device has which address.

Will my existing firewall rules keep working once IPv6 is on?

Yes. Firecradle manages IPv4 and IPv6 rules from the same screen, and a default-deny stance applies to both from the start, so IPv6 never quietly bypasses rules you already trust.

Cover the whole front door, not just half of it

IPv6 support and default-deny protection are part of every Firecradle appliance. Try it free for 30 days.

No credit card required · Cancel anytime · 30-day free trial