How many addresses are in a /48?
An IPv6 address has 128 bits. The number after the slash says how many leading bits are fixed, so a prefix of length n contains 2^(128 − n) addresses and 2^(64 − n) subnets of size /64.
| Prefix | Addresses | /64 subnets inside | Typical use |
|---|---|---|---|
| /48 | 2^80 = 1,208,925,819,614,629,174,706,176 | 65,536 | One business customer's site (RIPE-690) |
| /56 | 2^72 = 4,722,366,482,869,645,213,696 | 256 | One residential customer (RIPE-690) |
| /64 | 2^64 = 18,446,744,073,709,551,616 | 1 | One network segment (RFC 4291) |
| /128 | 1 | None | One address |
In words, a /48 holds about 1.2 septillion addresses. The number that matters more in practice is 65,536: that is how many separate /64 networks a /48 contains. The /48 and /56 sizes come from RIPE-690, RIPE's best-practice guidance on IPv6 prefixes for end users.
Why is a /64 the smallest normal IPv6 network?
Most IPv6 unicast addresses split into a 64-bit network prefix and a 64-bit interface identifier: RFC 4291 requires 64-bit interface identifiers for them. A home network or a server segment therefore gets at least a /64, and devices on it can change their own addresses. Under RFC 8981, hosts “SHOULD generate new temporary addresses over time” for privacy.
That is why one IPv6 address says little about who sent a request. A single laptop can use more than one address at a time, all inside the same /64.
How do websites limit IPv6 traffic by prefix?
Sites that limit or block IPv6 traffic can act on a whole prefix instead of one address. Three public examples:
- MediaWiki, the software behind Wikipedia: its administrator guidance says “IPv6 /64 rangeblocks are recommended”, because a block on one IPv6 address stops working as soon as the device changes address.
- Cloudflare: its IP Access rules let a site owner block, challenge or allow an IPv6 /64, /48 or /32 in a single rule.
- TrueProxies: our own gateway counts failed proxy logins from an IPv6 client per /64, not per address.
How a particular site limits traffic is up to that site and is not always published. Plan for limits on your /64 at least, and possibly on your whole /48. A rate limit applied to your /48 covers every address in it, so keep request rates within what the target allows, whichever address a request leaves from.
What does a private /48 mean on a proxy?
A private /48 is a prefix assigned to one customer only. On TrueProxies Datacenter IPv6 each service gets its own /48, so no other customer exits from those addresses, and the prefix's history on a site comes from your traffic alone.
A shared prefix works the other way. Many customers exit from the same /64 or /48, and a limit triggered by one customer's traffic can reach all of them.
A private /48 is still datacenter address space, not addresses that a consumer internet provider assigns to homes. A site that treats hosting ranges differently will treat a private /48 the same way.
How do connections spread across a /48?
On TrueProxies Datacenter IPv6, each new connection without a session token gets an address chosen at random from the whole /48, so consecutive connections almost always land in different /64s. Requests that reuse an open connection keep its address.
With a session token, every connection that carries the token leaves from one address for the session's lifetime, which you set in seconds with the lifetime option. Use a session when a permitted multi-step flow needs one address, and plain connections when requests are independent. The Datacenter IPv6 connection reference has the exact syntax.
for i in 1 2 3; do
curl -s -x http://YOUR_HOST:8080 -U "YOUR_USERNAME:YOUR_PASSWORD" https://api64.ipify.org
echo
doneEach line prints a different address. The first three groups of four hex digits (48 bits) match on every line: that is your /48. The fourth group usually differs, which means a different /64.
What does a /48 not do?
- It does not make traffic anonymous. The prefix is registered to a network operator, and sites see datacenter address space.
- It does not reach IPv4-only sites. Check your targets with the IPv6 test first.
- It does not change a site's rules. Terms, robots.txt and rate limits apply to the whole prefix.
- It does not pick a city per request. Datacenter IPv6 is one city per plan, chosen at checkout.
Read what an IPv6 proxy is for the wider comparison with IPv4, or see Datacenter IPv6 plans.