Configuring IPv6 on RHEL 9 Network Interfaces
IPv6 has shifted from a future-proofing exercise to a routine part of Linux administration in Australia. The National Broadband Network now ships with IPv6 enabled on most retail providers, and the Australian Government mandates dual-stack readiness across agencies, which means RHEL 9 servers in Canberra data centres, Brisbane branch offices, and even small Perth studios regularly need an IPv6 configuration applied during deployment. ACMA reporting has shown steady year-on-year growth in IPv6 allocation, and AARNet hands out routable blocks to research customers, so the addresses themselves are rarely the obstacle.
RHEL 9 standardises on NetworkManager for interface management, and the older ifcfg scripts are no longer the default. Administrators approaching a fresh server therefore need fluency with nmcli, nmtui, and the /etc/NetworkManager/system-connections/ profile files. The same workflow handles wired Ethernet, bonded interfaces, and VLAN-tagged connections, which matters when integrating with Australian campus networks that commonly segment traffic for research, teaching, and admin subnets.
This walkthrough covers verification of IPv6 support, dynamic and static assignment through NetworkManager, firewall adjustments with firewalld, and a quick troubleshooting checklist.
Verifying kernel and NetworkManager readiness
Before changing any configuration, confirm the kernel has IPv6 enabled and that NetworkManager owns the relevant interface. The first check is whether the device has a link-local address, which the kernel auto-assigns even without a global address. Refer to the linuxcommands catalog for more nmcli examples, or simply run ip -6 addr show to list fe80:: entries for every active NIC.
A second check confirms the global routing table and whether the interface is managed by NetworkManager:
nmcli device status
nmcli connection show --active
If the device shows as unmanaged, NetworkManager will not write IPv6 settings to it, and any nmcli changes will be ignored. Run nmcli device set <iface> managed yes and reload the connection. The kernel parameter ipv6.disable=1 on the command line will silently break everything, so check cat /proc/cmdline | grep ipv6 before going further.
Configuring IPv6 through NetworkManager
NetworkManager accepts both automatic and manual IPv6 configuration. Most Australian broadband connections from Telstra, Optus, or Aussie Broadband deliver a prefix through DHCPv6-PD or SLAAC, so ipv6.method auto suits edge servers. For a server with a static range, the configuration is just as straightforward:
nmcli connection modify ens192 ipv6.method manual \
ipv6.addresses "2001:db8:abcd:0012::10/64" \
ipv6.gateway "2001:db8:abcd:0012::1" \
ipv6.dns "2001:dc6:2001::1,2001:dc6:2001::2"
nmcli connection up ens192
The connection profile lives in /etc/NetworkManager/system-connections/ens192.nmconnection once saved. Edits made by hand must respect the INI-like format and ownership (root:root, mode 600), or NetworkManager will refuse to load them.
| Method | Tool | Best for | Persistence |
|---|---|---|---|
| nmcli | Command line | Scripts, automation, remote servers | Stored in profile files |
| nmtui | Text UI | Quick edits, local consoles, kiosks | Same profile files |
| Manual edit | Text editor | Bulk changes, Ansible templates | Direct file write |
| Kickstart | Anaconda | Automated RHEL 9 deployments | Built into image |
Headless servers in a Melbourne colocation rack almost always benefit from nmcli in a shell script, whereas nmtui is friendlier during a single session in front of a console.
Static address, SLAAC, and DNS choices
SLAAC works well when the upstream router advertises a prefix and the host only needs one address. Servers that host services in production usually want stable addresses that survive a router change, which means fixed entries in the connection profile. RHEL 9 also supports ipv6.method dhcp for networks that rely on DHCPv6 with prefix delegation, common in Australian university networks built around AARNet.
Choosing IPv6 DNS is its own decision. Quad9, Cloudflare's 2606:4700:4700::1111, and the locally hosted 2001:dc6:2001::1 operated by auDA-affiliated resolvers all serve Australian users well. Always pair the DNS lines with ipv6.dns-search so short names resolve against the correct domain, particularly when hosts are members of different AD realms split across Sydney and Adelaide offices.
After editing, restart only the connection rather than the whole NetworkManager service to avoid dropping unrelated sessions on the host. A useful confirm is ip -6 route show to verify the default route points at the configured gateway.
Securing IPv6 with firewalld and the kernel
A freshly configured IPv6 address is reachable from the public internet, so firewall rules must be applied at the same time. RHEL 9 ships with firewalld as the default zone manager, and the kernel's ip6tables backend is active alongside iptables. Rules written for IPv4 do not automatically cover IPv6, which is a common oversight during migrations.
Lock down the public zone to the services actually needed:
firewall-cmd --zone=public --add-service=http
firewall-cmd --zone=public --add-service=https
firewall-cmd --zone=public --add-rich-rule='rule family=ipv6 source address="2001:db8:abcd:0012::/64" service name=ssh accept'
firewall-cmd --runtime-to-permanent
SELinux policy remains the same regardless of address family, but nftables-backed rules benefit from family inet6 clauses when used directly. Restrict ICMPv6 to router-advert and neighbour-advert types where feasible, and disable router advertisements on hosts that are not routers through sysctl -w net.ipv6.conf.<iface>.accept_ra=0.
Operational recommendations for RHEL 9 IPv6 rollouts
Practical habits make IPv6 deployments predictable, especially when the same playbook is applied across dozens of hosts. The points below cover the most common mistakes observed on RHEL 9 rollouts in Australian environments.
- Keep IPv6 enabled at boot, but disable it per-interface only when a deliberate reason exists.
- Document the prefix in
/etc/hostsalongside IPv4 entries so service owners see both records. - Add an
ip -6 addr showline to nightly configuration audit logs. - Avoid mixing
ipv6.method ignorewith stateful firewall rules, as dropped traffic is hard to diagnose later. - When using VLANs, declare both
ipv4.methodandipv6.methodexplicitly per VLAN profile. - Pin DNS to Australian resolvers for latency-sensitive applications in Sydney and Melbourne.
- Validate changes through staged application of
nmcli connection upafter every modification.
Tightening SSH alongside these changes is wise, and key-based authentication on RHEL is a strong match for IPv6-only administration consoles. Locking down the SSH path before exposing IPv6 addresses to the wider network is the safer order of operations on any internet-facing host.
A practical baseline for any Australian deployment is to confirm the prefix, document the gateway, set a sensible firewall zone, and keep a rollback plan to revert the nmcli connection profile. With those four points in place, IPv6 on RHEL 9 stops being a special project and becomes a routine part of every server build.