Why SLAAC Isn’t Enough and When You Need DHCPv6
When first deploying IPv6 for an office of around 50 workstations and 10 internal servers, SLAAC (Stateless Address Autoconfiguration) is usually the go-to choice due to its sheer convenience. The router simply broadcasts Router Advertisement (RA) packets, and clients automatically pick up the prefix and combine it with EUI-64 or a randomized address to establish connectivity. Everything runs smoothly until day-to-day administrative tasks kick in.
Here are the three biggest challenges I encountered after three months of running SLAAC:
- Losing track of devices: The IPv6 Privacy Extensions feature on Windows and macOS rotates IP addresses every 24 hours. When a firewall triggers a security alert, tracing which host generated specific traffic at 10:00 AM becomes a nightmare.
- Needing static IPs for internal servers: Printers, NAS devices, and database servers require predictable, fixed addresses. Assigning static IPs manually on each machine is tedious and error-prone during infrastructure changes.
- Demand for automated subnetting (Prefix Delegation): When provisioning dedicated network ranges for downstream MikroTik branch routers or Proxmox virtual machines, manually allocating each
/64block is time-consuming and prone to IP collisions.
The classic isc-dhcp-server package has officially reached its End of Life (EOL). Kea DHCP, also developed by ISC, is its direct modern successor: featuring clean JSON configuration files, hook module support, REST API administration, and rock-solid handling of both Stateful IPv6 (IA_NA) and Prefix Delegation (IA_PD).
Installing Kea DHCPv6 Server on Ubuntu / Debian
Kea is available in the default repositories starting from Ubuntu 22.04 LTS and Debian 11. You only need to install the server package along with the administration utilities:
# Update repositories and install Kea DHCPv6
sudo apt update
sudo apt install -y kea-dhcp6-server kea-admin
# Check version
kea-dhcp6 -v
The default configuration file is located at /etc/kea/kea-dhcp6.conf. Back up the original file before making any changes:
sudo cp /etc/kea/kea-dhcp6.conf /etc/kea/kea-dhcp6.conf.bak
Configuration Scenario: Stateful IP & Prefix Delegation
Assume you have the following production network parameters:
- Server interface:
eth0with static IP2001:db8:1000:1::1/64. - ISP-assigned IPv6 prefix for the enterprise:
2001:db8:1000::/48. - Internal workstation allocation pool (IA_NA):
2001:db8:1000:1::/64(pool ranging from::100to::200). - Prefix Delegation range (IA_PD):
2001:db8:1000:f000::/52(split into 256/60subnets for downstream routers).
Editing /etc/kea/kea-dhcp6.conf
Edit the configuration file according to the JSON template below:
{
"Dhcp6": {
"interfaces-config": {
"interfaces": [ "eth0" ]
},
"control-socket": {
"socket-type": "stdout"
},
"lease-database": {
"type": "memfile",
"persist": true,
"name": "/var/lib/kea/kea-leases6.csv",
"lfc-interval": 3600
},
"preferred-lifetime": 3000,
"valid-lifetime": 7200,
"renew-timer": 1000,
"rebind-timer": 2000,
"option-data": [
{
"name": "dns-servers",
"data": "2001:db8:1000:1::1, 2001:4860:4860::8888"
},
{
"name": "domain-search",
"data": "itfromzero.local"
}
],
"subnet6": [
{
"id": 1,
"subnet": "2001:db8:1000:1::/64",
"interface": "eth0",
"pools": [
{
"pool": "2001:db8:1000:1::100 - 2001:db8:1000:1::200"
}
],
"pd-pools": [
{
"prefix": "2001:db8:1000:f000::",
"prefix-len": 52,
"delegated-len": 60
}
],
"reservations": [
{
"duid": "00:01:00:01:2c:4a:5b:6c:00:0c:29:8a:9d:11",
"ip-addresses": [ "2001:db8:1000:1::50" ]
}
]
}
]
}
}
Breakdown of Key Configuration Blocks
- lease-database (memfile): Kea keeps leases in memory and periodically persists them to a CSV file. This lightweight approach performs smoothly for environments with under 1,000 devices without requiring MySQL or PostgreSQL.
- pools: Individual IP address ranges (IA_NA) leased directly to clients within the
/64subnet. - pd-pools: Prefix delegation blocks (IA_PD). From the
/52block, Kea automatically slices it into/60subnets (each containing sixteen/64ranges) to assign to downstream branch routers. - reservations: Assigns fixed IPs based on the network interface’s DUID (DHCP Unique Identifier) rather than MAC addresses as in IPv4.
Crucial Step: Configuring M-Flag and O-Flag in Router Advertisements
IPv6 clients will not automatically send DHCPv6 requests unless the gateway router advertises the correct flags in its Router Advertisement messages. Without these flags, clients will continue falling back to SLAAC.
On the RA-broadcasting gateway (using radvd, dnsmasq, or FRRouting), you must enable two flags:
- M-Flag (Managed Address Configuration = 1): Forces clients to request stateful IP addresses from the DHCPv6 server.
- O-Flag (Other Configuration = 1): Instructs clients to fetch additional network configuration (DNS, search domain) via DHCPv6.
If you are using radvd, your /etc/radvd.conf should contain the following minimal configuration:
interface eth0 {
AdvSendAdvert on;
AdvManagedFlag on;
AdvOtherConfigFlag on;
prefix 2001:db8:1000:1::/64 {
AdvAutonomous off; # Disable SLAAC auto-generation
};
};
Verifying Syntax and Starting the Service
Before starting the service, test the JSON configuration using Kea’s built-in syntax checker:
# Verify configuration file
sudo kea-dhcp6 -t /etc/kea/kea-dhcp6.conf
If the syntax validation succeeds, enable and start the Kea service:
sudo systemctl restart kea-dhcp6-server
sudo systemctl enable kea-dhcp6-server
sudo systemctl status kea-dhcp6-server
Verifying Service Ports
The DHCPv6 server listens on UDP port 547, while clients transmit from UDP port 546. Verify using the ss command:
sudo ss -u -l -n -p | grep 547
# Expected output: UNCONN 0 0 *:547 *:* users:(("kea-dhcp6",pid=...,fd=...))
Testing Allocations on Client Machines
On a Linux workstation, run the following commands to request a Stateful IPv6 lease (IA_NA):
# Release existing lease and request a new IA_NA lease
sudo dhclient -6 -r eth0
sudo dhclient -6 -N -v eth0
On a downstream branch router or VM acting as a sub-gateway, run this command to request a Prefix Delegation (IA_PD):
# Request Prefix Delegation
sudo dhclient -6 -P -v eth0
Monitoring Logs and Inspecting Active Leases
To observe the complete four-way handshake (Solicit → Advertise → Request → Reply), follow the live systemd journal logs:
sudo journalctl -u kea-dhcp6-server -f
To check which client currently holds an IP address or delegated prefix, inspect the CSV lease file directly:
cat /var/lib/kea/kea-leases6.csv
Each line in the file clearly displays the IPv6 address (or delegated prefix), DUID, lease lifetime, and lease type (IA_NA for workstations or IA_PD for downstream routers). This brings transparency and predictability to managing and monitoring your IPv6 infrastructure.

