IPv4/IPv6 Dual-Stack
Native dual-stack deployment with IPv4 exhaustion mitigation and phased IPv6 rollout planning. Includes structured subnet allocation, ACL parity across both address families and DNS/routing readiness validation to avoid retrofitting under time pressure.
Overview
IPv4 exhaustion is not a future problem — it is a present constraint. It limits how many devices you can connect, how your network talks to modern platforms, and how you prepare for an IoT and mobile-first world. IPv4/IPv6 Dual-Stack runs both protocol stacks simultaneously on your infrastructure. Your systems reach IPv4-only and IPv6-enabled services without translation, tunnelling, or NAT64 gateways. Traffic uses whichever protocol is available, with no degradation and no architectural workarounds.
Clevertek scopes every engagement to your environment — capacity, sites, compliance and support model — so you get a tailored plan rather than a fixed SKU. Pricing is quote-only, and our solutions architects will work through your requirements before any proposal.
Our approach
We enable dual-stack IPv4/IPv6 on your existing infrastructure — DIA circuits, transit ports, firewalls, and CPE — so both protocol families are active at the same time. We allocate IPv6 address blocks (/48 or /64 as needed), configure BGP peering for IPv6 prefixes, update firewall rules and ACLs for dual-stack, and validate end-to-end connectivity for both protocols. Your existing IPv4 services continue unchanged while IPv6 capability is added alongside. No disruption, no migration window, no tunnel overhead.
Why work with us
Native dual-stack, not tunnels
Both protocols run natively on the same infrastructure — no 6to4, Teredo, or NAT64 gateways that add latency and complexity.
IPv6 address allocation
We allocate and register IPv6 address blocks (/48 or /64) from our provider-independent space or your RIR allocation, configured for your network topology.
Full BGP peering for IPv6
DIA and transit circuits configured with IPv6 BGP peering — full IPv6 routing tables where available, default route where full tables are not needed.
Firewall and security policy update
Firewall rules, ACLs, and security policies updated for dual-stack — no gaps where IPv6 traffic bypasses IPv4-only policies.
Validation and testing
End-to-end connectivity testing for both protocols — DNS resolution, path MTU, application-layer connectivity verified before handover.
Compatible with your existing monitoring
Dual-stack metrics collected for both protocols — latency, packet loss, and throughput per address family, integrated into your existing dashboards.
Key benefits
What this solution delivers for your business.
Future-proof your network
Government and enterprise networks increasingly require IPv6 readiness. Dual-stack ensures your infrastructure can communicate with these networks today.
Eliminate NAT and its complexity
IPv6 restores end-to-end connectivity without NAT — simplifying application architectures, reducing troubleshooting complexity, and removing NAT-related performance bottlenecks.
Compatible with modern platforms
AWS, Azure, Google Cloud, Microsoft 365, and major SaaS platforms are increasingly IPv6-only for internal communication. Dual-stack ensures optimal connectivity to these services.
No disruption to existing services
IPv4 services continue exactly as before. IPv6 is added alongside without changes to existing IP addressing, routing, or firewall policies.
IoT and device density scalability
IPv6 provides enough address space for billions of IoT sensors, smart devices, and endpoints without NAT exhaustion — critical for organisations deploying large-scale IoT.
Regulatory compliance readiness
Many regulated sectors (government, defence, telecom) now mandate IPv6 capability. Dual-stack satisfies compliance requirements without requiring an IPv6-only migration.
What's included
Part of this managed service.
Dual-stack enablement
Both IPv4 and IPv6 running concurrently on DIA circuits, transit ports, and CPE — native, not tunnelled.
- Native dual-stack
- No tunnel overhead
- Concurrent operation
- Transparent to applications
IPv6 address allocation
Provider-independent or RIR-allocated IPv6 address blocks (/48 or /64) configured for your network.
- /48 or /64 allocation
- Provider-independent option
- RIR registration support
- Subnet planning
BGP peering for IPv6
Full or default IPv6 routing tables via BGP peering on DIA and transit circuits.
- IPv6 BGP peering
- Full routing tables option
- Default route option
- Route policy control
Security policy alignment
Firewall rules, ACLs, and security policies updated for dual-stack so IPv6 traffic has equivalent protection.
- Firewall rule audit
- ACL update for IPv6
- Security policy alignment
- No IPv6 bypass risk
Validation and testing
End-to-end connectivity validation for both protocols — DNS, ping, traceroute, application-layer tests.
- DNS resolution (AAAA records)
- Path MTU validation
- Application connectivity
- Dual-stack test report
Where it helps
Real-world scenarios where this solution delivers measurable outcomes.
Enterprise network modernisation
Enable dual-stack across all DIA circuits and site routers as part of a network refresh — IPv6 capability added alongside existing IPv4 without disruption.
Government and regulated sector compliance
Meet IPv6 readiness mandates for government contracts, defence sector networks, or telecom regulatory requirements.
SaaS company serving IPv6-only users
If your platforms serve users in markets with significant IPv6 adoption (mobile-first, APAC regions), dual-stack ensures they reach your services without translation.
IoT deployment preparation
Before deploying thousands of IoT sensors, enable dual-stack on the network that will carry their traffic — each sensor gets a globally unique IPv6 address without NAT.
Questions buyers actually ask
Will dual-stack slow down my network?
No. Both protocols run at wire speed on modern CPE and firewalls. There is no encapsulation or processing overhead with native dual-stack.
Do I need to change my IPv4 addresses?
No. IPv4 addresses stay exactly as they are. IPv6 addresses are added alongside — no renumbering, no reconfiguration of existing services.
Does dual-stack work with my existing firewall?
Modern enterprise firewalls support dual-stack natively. We audit your current make and model during the assessment to confirm capability and plan any required updates.
How long does dual-stack deployment take?
Typical deployment takes 1-2 weeks for a single site — address allocation, router and firewall configuration, BGP peering setup, validation testing, and handover.
What happens if IPv6 traffic hits a destination without IPv6?
Modern operating systems use RFC 6724 address selection — they try IPv6 first, and if the destination does not support it, the connection falls back to IPv4 transparently.
Ready to scope a solution?
Talk to a Clevertek solutions architect about your requirements — no obligation.