Design an IPv6 addressing plan with prefix sizes that support current sites and future growth.
IPv6 Migration Planning for Enterprise Networks
Plan a phased IPv6 migration for enterprise networks, from address planning and dual-stack design through routing, security and application readiness to a controlled move towards IPv6-only operation.
Course Overview
Public IPv4 address space has been exhausted for years, yet many enterprise networks still run IPv6 nowhere beyond a default router advertisement nobody planned for, which leaves security and address management gaps that go unnoticed until an audit or an incident finds them. This course treats IPv6 as a planned migration rather than a protocol to enable later. It starts with an addressing plan built on proper prefix sizes for sites and subnets, then works through dual-stack design so IPv4 and IPv6 run side by side without breaking existing services. Participants cover stateless address autoconfiguration and DHCPv6, the routing and security changes IPv6 requires, including router advertisement guard and extension header filtering, and transition mechanisms such as NAT64 and DNS64 for reaching IPv4-only resources during the changeover. A readiness assessment module covers auditing applications, middleware, firewalls and management tools for IPv6 support before it is relied upon. The course finishes with a phased rollout plan that moves from a pilot segment to broad dual-stack coverage and, where justified, an IPv6-mostly network.
Expected Learning Outcomes
Build a dual-stack design that runs IPv4 and IPv6 together without disrupting existing services.
Choose between stateless address autoconfiguration and DHCPv6 for each network segment.
Apply IPv6-specific security controls including router advertisement guard and extension header filtering.
Use NAT64, DNS64 and other transition mechanisms to bridge IPv6-only and IPv4-only systems.
Audit applications, firewalls and management tools for IPv6 support before migration begins.
Sequence a phased rollout from pilot segment to broad dual-stack or IPv6-mostly operation.
Who Should Attend
Network engineers planning or executing an enterprise IPv6 deployment.
Network architects designing address plans for new or expanding networks.
Security teams responsible for firewall and access control policy updates.
IT managers building a business case and timeline for IPv6 adoption.
Systems administrators assessing application and middleware IPv6 readiness.
Service provider engineers supporting enterprise customers through migration.
Course Modules
Select any module to see its sessions and points.
01IPv6 Addressing and Fundamentals
2 sessions · 8 points
Session 1IPv6 Address Types and Planning
- Distinguish global unicast, link-local and unique local addresses and their intended use.
- Design a hierarchical addressing plan using appropriate prefix sizes for sites and subnets.
- Allocate address space so summarisation stays possible as sites and subnets are added.
- Document an address plan that network and security teams can reference during rollout.
Session 2Neighbour Discovery, SLAAC and DHCPv6
- Explain neighbour discovery protocol and how it replaces IPv4 address resolution protocol.
- Configure stateless address autoconfiguration for segments that do not need central tracking.
- Deploy DHCPv6 where address tracking, options or reservations are required.
- Decide per segment whether SLAAC, DHCPv6 or both should be enabled.
02Dual-Stack Design and Routing
2 sessions · 8 points
Session 1Dual-Stack Network Design
- Enable IPv4 and IPv6 together on the same interfaces and links without service disruption.
- Update DNS to publish AAAA records alongside existing A records for dual-stack hosts.
- Identify applications that will prefer IPv6 once available and plan for behaviour changes.
- Test dual-stack behaviour under a failure of either the IPv4 or IPv6 path.
Session 2IPv6 Routing Protocol Support
- Extend interior routing protocols to carry IPv6 alongside existing IPv4 routes.
- Configure BGP address families to exchange IPv6 routes with external peers.
- Plan route summarisation and filtering for IPv6 prefixes across the network.
- Verify that routing convergence behaviour for IPv6 matches the existing IPv4 network.
03Security and Transition Mechanisms
2 sessions · 8 points
Session 1IPv6-Specific Security Controls
- Apply router advertisement guard to block rogue or accidental IPv6 router advertisements.
- Filter IPv6 extension headers that are commonly used to evade inspection or cause faults.
- Update firewall and access control policy to cover IPv6 traffic to the same standard as IPv4.
- Extend logging and monitoring tools to capture IPv6 addresses and sessions correctly.
Session 2Transition Mechanisms and Coexistence
- Deploy NAT64 and DNS64 so IPv6-only clients can reach IPv4-only resources during migration.
- Evaluate 464XLAT and other translation techniques for specific coexistence scenarios.
- Retire legacy tunnelling mechanisms once native dual-stack connectivity is available.
- Plan the coexistence period length based on application and partner readiness.
04Readiness Assessment and Rollout
2 sessions · 8 points
Session 1Application and Infrastructure Readiness
- Audit applications and middleware for hard-coded IPv4 assumptions before migration.
- Verify that network management, monitoring and IP address management tools support IPv6.
- Check firewall, load balancer and VPN platforms for IPv6 feature parity with IPv4.
- Compile a readiness scorecard that identifies blockers before a pilot segment is chosen.
Session 2Phased Rollout and IPv6-Mostly Operation
- Select and migrate a pilot segment to validate design decisions with limited risk.
- Expand dual-stack coverage in phases based on lessons from the pilot segment.
- Plan a move toward IPv6-mostly operation where address exhaustion or cost justifies it.
- Set rollback criteria for each phase so a problem segment can revert without delay.
What the participant receives
4 course modules
A structured syllabus
8 training sessions
across 5 days
32 detailed points
Applied, detailed content
Accredited attendance certificate
On completing the programme
Complete your registration
We will contact you within one business day to confirm.
Ready to start?
Reserve your seat and start building the skill.
