Unique local address

A unique local address (ULA) is an Internet Protocol version 6 (IPv6) address in the address range fc00::/7.[1] These addresses are non-globally reachable[2] (routable only within the scope of private networks, but not the global IPv6 Internet). For this reason, ULAs are somewhat analogous to IPv4 private network addressing, but with significant differences. Unique local addresses may be used freely, without centralized registration, inside a single site or organization or spanning a limited number of sites or organizations.

History

In December 1995, the IPv6 address block fec0::/10 was reserved for site-local addresses,[3] that could be used within a "site" for private IPv6 networks. However, insufficient definition of the term site led to confusion over the governing routing rules.

In September 2004, the Internet Engineering Task Force (IETF) deprecated the definition of this address range,[4] and postulated solutions to its problems. The special behaviour for this type of addresses as required at that time[5] was lifted in 2006 and the block returned to regular global unicast.[6]

In October 2005, the IETF reserved the address block fc00::/7 for use in private IPv6 networks and defined the associated term unique local addresses.[1]

Definition

Unique local addresses use prefix fc00::/7. The first bit following the prefix indicates, if set, that the address is locally assigned. This splits the address block in two equally sized halves, fc00::/8 and fd00::/8.

The block with L = 0, fc00::/8, is currently not defined.[1] It has been proposed that an allocation authority manage it, but this has not gained acceptance in the IETF.[7][8][9]

The block with L = 1, fd00::/8 follows the following format.

RFC 4193 blockPrefix/LGlobal ID (random)Subnet IDNumber of addresses in subnet
48 bits16 bits64 bits
fd00::/8fdxx:xxxx:xxxxyyyy18446744073709551616

It is divided into /48 prefixes, formed by setting the forty bits following the prefix fd00/8 to a randomly generated bit string. This results in the format fdxx:xxxx:xxxx::/48 for a prefix in this range. RFC 4193 offers a suggestion for generating the random identifier to obtain a minimum-quality result if the user does not have access to a good source of random numbers.

Example

A routing prefix in the range fd00::/8 may be constructed by generating a random 40-bit hexadecimal string, taken for this example to be 0x123456789a. The string is appended to the prefix fd00::/8, which forms the 48-bit routing prefix fd12:3456:789a::/48. With this prefix, 65536 subnets of size /64 are available for the private network: fd12:3456:789a::/64 to fd12:3456:789a:ffff::/64. For example Subnet ID 0x1 would be the subnet fd12:3456:789a:1::/64.

Prefix/LGlobal ID (random)Subnet IDInterface IDAddressSubnet
fdxx:xxxx:xxxxyyyyzzzz:zzzz:zzzz:zzzzfdxx:xxxx:xxxx:yyyy:zzzz:zzzz:zzzz:zzzzfdxx:xxxx:xxxx:yyyy::/64
fd12:3456:789a00010000:0000:0000:0001fd12:3456:789a:1::1fd12:3456:789a:1::/64

Properties

Prefixes in the range fc00::/7 have some characteristics in common with the IPv4 private address ranges: They are not allocated by an address registry and may be used in networks by anyone without outside involvement. They are not mathematically guaranteed to be globally unique, but the probability of a collision is nevertheless extremely small. Reverse Domain Name System (DNS) entries (in ip6.arpa) for fd00::/8 ULAs cannot be delegated in the global DNS.

As fc00::/7 ULAs are not meant to be routed outside their administrative domain (site or organization), administrators of interconnecting networks normally do not need to worry about the uniqueness of ULA prefixes. However, if networks require routing ULAs between each other in the event of a merger, for example, the risk of address collision is very small if the RFC 4193 selection algorithm was used.

Industry usage

The ULA block is useful in the context of service providers and content providers, as it provides isolation of the infrastructure and hence avoids exposure to the Internet.

One such example is Amazon Web Services, which uses ULAs within its virtual private cloud networking. In particular it uses the block fd00:ec2::/32 for local services, such as time sync services or DNS resolvers.[10]

Attempts of registration and allocation

SixXS attempted to maintain a voluntary registration database for fd00::/8 ULA prefixes to reduce the risk of different organisations using identical prefixes.[11] When the SixXS services were discontinued on 6 June 2017, the database became read-only.

On 6 December 2020, the Swiss-based company 'ungleich' announced that it would revive the IPv6 ULA registry based on the original SixXS database, citing user demands for a ULA registry.[12]

For the range fc00::/8, different design decisions have been proposed and submitted to the IETF,[7][9] trading the risk of non-uniqueness for the requirement that the range be managed by a central allocation authority. However, such attempts at standardizing this range have not resulted in a request for comments.[7][8][9]

See also

Notes

References

External links