Networking, DNS & Wi-Fi

IPv6 has an address but no usable default route

Separate IPv6 addressing from router-advertisement route learning when IPv4 works but IPv6 lacks a gateway, especially on hosts with forwarding enabled.

On this page
  1. Symptoms & scope
  2. Possible causes
  3. Diagnose safely
  4. Evidence-guided next steps
  5. References & review
  6. Related problems

Symptoms & scope

  • IPv6 shows a link-local or global address but no expected default route.
  • The failure follows enabling forwarding for containers, virtualization or routing.

Relevant environment

IPv6 networks using router advertisements and NetworkManager; routers and intentionally static deployments need an explicit routing design.

Possible causes

These are possible explanations, not a confirmed diagnosis. Several independent faults can coexist.

  • The local profile may suppress automatic routes, or the upstream router may not advertise a usable default-router lifetime.
  • Kernel router-advertisement acceptance normally changes when forwarding is enabled; DHCPv6 address assignment does not itself supply a default gateway.

Diagnose safely

Run one command at a time in the relevant session. Read the explanation first. Uppercase placeholders need your own values; tools and privileges vary by distribution. These commands are displayed here and never executed by the website.

Check 1

Replace IFACE with the IPv6 uplink. Read connected and default routes without soliciting advertisements or changing routes.

ip -6 route show dev IFACE

Interpret the result: A default via a link-local router with proto ra supports RA learning. A global address without default route is possible; a fe80:: address alone does not establish Internet IPv6.

Check 2

Replace IFACE with the uplink’s actual name; this reads two per-interface values without assigning them. Names containing dots may require reading the corresponding /proc/sys paths instead.

sysctl net.ipv6.conf.IFACE.accept_ra net.ipv6.conf.IFACE.forwarding

Interpret the result: accept_ra=1 normally accepts RAs only without forwarding; accept_ra=2 permits acceptance even with forwarding. NetworkManager may manage RA processing, so also compare its active IPv6 profile before changing kernel settings.

Check 3

Replace PROFILE with the active uplink profile. Read how the manager intends to obtain addresses and routes, without modifying the profile.

nmcli -f ipv6.method,ipv6.never-default,ipv6.ignore-auto-routes,ipv6.gateway connection show "PROFILE"

Interpret the result: never-default or ignore-auto-routes can intentionally suppress a learned gateway. An automatic host profile differs from a manually routed server; match the actual network design.

Evidence-guided next steps

Restore intended IPv6 route learning

If the uplink is meant to be an automatic IPv6 host but the profile suppresses its default route, save the profile and correct that specific automatic-route setting. If all clients lack an RA default, have the router administrator inspect advertisement lifetime and upstream connectivity instead.

Precautions: Preserve an intentional VPN-only or secondary interface never-default policy. Do not invent a global IPv6 gateway from an address alone.

Recovery / rollback: Restore the saved profile and router advertisement settings; reactivate the original connection locally if another default route becomes preferred.

Did this solution help you?

Share this solution#

Configure deliberate forwarding with RA acceptance

If this machine intentionally forwards traffic but its uplink must also learn an upstream RA route, follow the owning network manager’s documented method for that design. For kernel-managed RA reception, accept_ra=2 on that exact uplink permits this combination; verify a learned route after the change.

Precautions: Do not change every interface or disable IPv6 globally. Forwarding has security and routing implications; retain the intended firewall and local recovery access.

Recovery / rollback: Restore the recorded per-interface RA/forwarding settings and manager profile, then restart only the affected connection using its normal procedure.

Did this solution help you?

Share this solution#

References & review

This guide was prepared from primary project or distribution sources and reviewed on the date shown. This is an editorial source check, not evidence that a fix was reproduced on your hardware. Diagnostic log examples are synthetic fixtures. Version-dependent details must be checked against your installed release.