Network knowhow

Why TMW loves IPv6

IPv6 is not a line on a spec sheet. It is how the network is built.

AS215828 is dual-stack on every BGP session, every public exchange port and every upstream. We love IPv6 because it is cleaner engineering: enough addresses, no NAT theatre, and a protocol a large share of European users already speak.

01

Dual-stack is the default, not an upgrade

IPv4-only networks still work. They also hide a pile of workarounds: CGNAT, extra state, broken incoming connections, and a constant hunt for scarce address space. We did not want that as the foundation of a transit and DDoS network.

Every TMW BGP session carries IPv4 and IPv6 unicast. IX ports at Frankfurt, Amsterdam, Zurich and beyond have both families. Upstreams - including Hurricane Electric - are dual-stack. If a customer wants IPv6, it is already in the fabric, not a special project.

02

No NAT, real end-to-end

IPv6 gives each host a globally unique address. Servers, game endpoints, VPNs and APIs can accept inbound sessions without port-forwarding puzzles. That is how IP was supposed to work.

NAT is a tax on debugging, logging and DDoS forensics. Source addresses get rewritten, return paths get weird, and operators spend nights proving whose packet it actually was. Native IPv6 removes that layer of fiction.

03

IPv4 is scarce. Eyeballs already moved.

IPv4 space is expensive and getting more so. RIPE ran out of free IPv4 years ago. Buying, leasing and hoarding /24s is a business model - it is not a network design. IPv6 prefixes from RIPE are plentiful; we can give customers room to grow without rationing addresses.

German and European access networks already carry a large share of traffic over IPv6 - Deutsche Telekom and other eyeball ISPs dual-stack by default. If your origin is IPv4-only, those users take a translation hop. Dual-stack origins talk to them natively, with a shorter path and fewer middleboxes.

04

Cleaner BGP, cleaner IX

IPv6 routing is the same protocol operators already know - just a larger address family. Longest-prefix match, communities, RPKI and looking-glass checks work the same way. What changes is operational hygiene: no need to NAT a prefix just to bring a new service online.

Public peering is dual-stack or it is incomplete. Our IX ports publish IPv6 addresses next to IPv4. Peers who only exchange v4 leave a growing share of traffic on transit. We peer both families because that is how you keep latency and cost under control.

05

What you get on TMW

VPS, cloud and transit products ship with IPv6 included - not as a paid add-on. You get addresses, routing and DDoS filtering in both families. HTTP/2, HTTP/3 and modern clients already prefer v6 when it is available; we make sure it is.

We love IPv6 because it matches how we want to operate: public, dual-stack, RIPE-registered, and boring in the best way. If your stack is still v4-only, we will help you turn up v6 without turning it into a six-month programme.

IPv6 FAQ

Do I have to pay extra for IPv6 at TMW?

No. IPv6 is included on transit, hosting and DDoS protection. Dual-stack is the default on AS215828, not a surcharge.

Can I run IPv6-only?

Yes for many workloads - especially APIs, anycast edges and internal services. Most public origins still need IPv4 for older clients, so dual-stack is the usual recommendation. We can route and protect v6-only prefixes.

Is IPv6 less safe than IPv4?

No. Exposure comes from open services, not from the address family. IPv6 needs the same firewall discipline and DDoS filtering. The difference is you can filter on real host addresses instead of a NAT pool.

Does TMW filter IPv6 DDoS?

Yes. Scrubbing, filter profiles and BGP-based protection cover both address families. IPv6 floods are mitigated at the same edges as IPv4.

Want dual-stack transit or hosting?

AS215828 is IPv4 and IPv6 by default - peering, upstreams, Looking Glass and TMW Shield included. Tell us the prefixes and we will turn them up.