NBN Help

IPv6 for business on NBN — what it means in practice

Business NBN customers have stronger reasons than most to care about IPv6 — not as a future IT checkbox, but as a practical question affecting connectivity right now. CGNAT (where your business shares a single public internet address with many other customers) creates real complications for inbound connections and remote access that IPv6 resolves at the source. Australia is one of the slowest developed countries to adopt business IPv6 — and the gap is costing organisations time and money they may not realise they're spending.

Tired of fighting your ISP? HIT Pacific — transparent pricing, no lock-in, real local support.

See our plans

Why this happens

How to fix it — step by step

  1. 1. Understand what IPv6 actually solves for your business

    With native IPv6, your premises gets a block of globally routable addresses. Any server or device you want reachable from the internet can be reached directly — no port forwarding, no shared address complications, no CGNAT blocking inbound traffic. This matters for self-hosted services, remote access, branch office connections, and cloud hybrid setups.

  2. 2. Configure your router or firewall for prefix delegation

    Your router or business firewall needs to request an IPv6 address block from your ISP using DHCPv6-PD (prefix delegation). Enterprise routers and firewalls — including pfSense, OPNsense, Fortinet, Mikrotik, and Cisco — all support this. Once configured, enable address distribution (DHCPv6 or Router Advertisements) on your internal network so servers and devices receive IPv6 addresses automatically.

  3. 3. Add IPv6 address records to your DNS

    If you run any internet-facing services, add AAAA records (IPv6 addresses) alongside your existing A records (IPv4 addresses) in DNS. Clients that support IPv6 use the direct path; IPv4-only clients fall back automatically. Running both side by side is the standard approach during the transition.

  4. 4. Audit your applications and firewall rules

    Most modern server software binds to both IPv4 and IPv6 by default — check that your firewall rules permit IPv6 traffic where needed. If your business VPN still runs on older protocols like PPTP or L2TP, migrating to WireGuard improves both security and IPv6 compatibility in one move.

  5. 5. Set a course for IPv6-primary operation

    The practical stance today is dual-stack: IPv6 for the majority of traffic, IPv4 where still required. The direction is clear — each year more internet infrastructure moves to IPv6-first. Getting it right now means a smooth path forward rather than a scramble when IPv4 workarounds become untenable.

  6. 6. Help close Australia's business IPv6 gap

    Australia's IPv6 adoption in business is low — not because the technology is hard, but because no one inside most organisations has pushed for it. If you get IPv6 working in your business, talk about it. Ask your cloud providers, software vendors, and IT suppliers whether their services are IPv6-ready. Check hardware before you buy it. The businesses leading this shift are setting the standard for how Australian enterprise infrastructure works in five years — and every one of them started exactly where you are now.

Still having trouble?

If none of these steps resolve the problem, it may be an issue with your current provider. HIT Pacific offers transparent pricing, faster fault response, and local support.

See our plans