Candid photograph of a Linux server terminal with a soft olive-green glow against a dark slate background, conveying a calm technical atmosphere.

Step-by-step guides for system administrators — covering command-line basics, web server setup, and preparation material for technical interviews.

Browse Tutorials

Configuring IPv6 on RHEL 9 Network Interfaces

IPv6 has shifted from a future-proofing exercise to a routine part of Linux administration in Australia. The National Broadband Network now ships with IPv6 enabled on most retail providers, and the Australian Government mandates dual-stack readiness across agencies, which means RHEL 9 servers in Canberra data centres, Brisbane branch offices, and even small Perth studios regularly need an IPv6 configuration applied during deployment. ACMA reporting has shown steady year-on-year growth in IPv6 allocation, and AARNet hands out routable blocks to research customers, so the addresses themselves are rarely the obstacle.

RHEL 9 standardises on NetworkManager for interface management, and the older ifcfg scripts are no longer the default. Administrators approaching a fresh server therefore need fluency with nmcli, nmtui, and the /etc/NetworkManager/system-connections/ profile files. The same workflow handles wired Ethernet, bonded interfaces, and VLAN-tagged connections, which matters when integrating with Australian campus networks that commonly segment traffic for research, teaching, and admin subnets.

This walkthrough covers verification of IPv6 support, dynamic and static assignment through NetworkManager, firewall adjustments with firewalld, and a quick troubleshooting checklist.

Verifying kernel and NetworkManager readiness

Before changing any configuration, confirm the kernel has IPv6 enabled and that NetworkManager owns the relevant interface. The first check is whether the device has a link-local address, which the kernel auto-assigns even without a global address. Refer to the linuxcommands catalog for more nmcli examples, or simply run ip -6 addr show to list fe80:: entries for every active NIC.

A second check confirms the global routing table and whether the interface is managed by NetworkManager:

nmcli device status
nmcli connection show --active

If the device shows as unmanaged, NetworkManager will not write IPv6 settings to it, and any nmcli changes will be ignored. Run nmcli device set <iface> managed yes and reload the connection. The kernel parameter ipv6.disable=1 on the command line will silently break everything, so check cat /proc/cmdline | grep ipv6 before going further.

Configuring IPv6 through NetworkManager

NetworkManager accepts both automatic and manual IPv6 configuration. Most Australian broadband connections from Telstra, Optus, or Aussie Broadband deliver a prefix through DHCPv6-PD or SLAAC, so ipv6.method auto suits edge servers. For a server with a static range, the configuration is just as straightforward:

nmcli connection modify ens192 ipv6.method manual \
  ipv6.addresses "2001:db8:abcd:0012::10/64" \
  ipv6.gateway "2001:db8:abcd:0012::1" \
  ipv6.dns "2001:dc6:2001::1,2001:dc6:2001::2"
nmcli connection up ens192

The connection profile lives in /etc/NetworkManager/system-connections/ens192.nmconnection once saved. Edits made by hand must respect the INI-like format and ownership (root:root, mode 600), or NetworkManager will refuse to load them.

Method Tool Best for Persistence
nmcli Command line Scripts, automation, remote servers Stored in profile files
nmtui Text UI Quick edits, local consoles, kiosks Same profile files
Manual edit Text editor Bulk changes, Ansible templates Direct file write
Kickstart Anaconda Automated RHEL 9 deployments Built into image

Headless servers in a Melbourne colocation rack almost always benefit from nmcli in a shell script, whereas nmtui is friendlier during a single session in front of a console.

Static address, SLAAC, and DNS choices

SLAAC works well when the upstream router advertises a prefix and the host only needs one address. Servers that host services in production usually want stable addresses that survive a router change, which means fixed entries in the connection profile. RHEL 9 also supports ipv6.method dhcp for networks that rely on DHCPv6 with prefix delegation, common in Australian university networks built around AARNet.

Choosing IPv6 DNS is its own decision. Quad9, Cloudflare's 2606:4700:4700::1111, and the locally hosted 2001:dc6:2001::1 operated by auDA-affiliated resolvers all serve Australian users well. Always pair the DNS lines with ipv6.dns-search so short names resolve against the correct domain, particularly when hosts are members of different AD realms split across Sydney and Adelaide offices.

After editing, restart only the connection rather than the whole NetworkManager service to avoid dropping unrelated sessions on the host. A useful confirm is ip -6 route show to verify the default route points at the configured gateway.

Securing IPv6 with firewalld and the kernel

A freshly configured IPv6 address is reachable from the public internet, so firewall rules must be applied at the same time. RHEL 9 ships with firewalld as the default zone manager, and the kernel's ip6tables backend is active alongside iptables. Rules written for IPv4 do not automatically cover IPv6, which is a common oversight during migrations.

Lock down the public zone to the services actually needed:

firewall-cmd --zone=public --add-service=http
firewall-cmd --zone=public --add-service=https
firewall-cmd --zone=public --add-rich-rule='rule family=ipv6 source address="2001:db8:abcd:0012::/64" service name=ssh accept'
firewall-cmd --runtime-to-permanent

SELinux policy remains the same regardless of address family, but nftables-backed rules benefit from family inet6 clauses when used directly. Restrict ICMPv6 to router-advert and neighbour-advert types where feasible, and disable router advertisements on hosts that are not routers through sysctl -w net.ipv6.conf.<iface>.accept_ra=0.

Operational recommendations for RHEL 9 IPv6 rollouts

Practical habits make IPv6 deployments predictable, especially when the same playbook is applied across dozens of hosts. The points below cover the most common mistakes observed on RHEL 9 rollouts in Australian environments.

Tightening SSH alongside these changes is wise, and key-based authentication on RHEL is a strong match for IPv6-only administration consoles. Locking down the SSH path before exposing IPv6 addresses to the wider network is the safer order of operations on any internet-facing host.

A practical baseline for any Australian deployment is to confirm the prefix, document the gateway, set a sensible firewall zone, and keep a rollback plan to revert the nmcli connection profile. With those four points in place, IPv6 on RHEL 9 stops being a special project and becomes a routine part of every server build.