---
title: "Public IPv6"
description: "Every Metalhost VM gets a free, routable public IPv6 address by default. How it"
url: "https://metalhost.net/docs/dashboard/guides/public-ipv6"
---

# Public IPv6

Every VM on Metalhost gets a **public, routable IPv6 address for free** — it's part of the public NIC that comes with the VM. You don't opt in or pay for it; it's just there unless you explicitly make the VM private-only.

## How it works

When a VM is created, one global unicast IPv6 address is reserved from the datacenter's IPv6 pool and configured on the VM's public network interface. The address is written into the guest's network config at boot, so it's live as soon as the VM is up — no DHCP wait, no manual setup inside the VM.

- **Free** — there's no per-address charge for IPv6, unlike IPv4.
- **Always on** — every VM gets one unless it's marked private-only.
- **Stable** — the address persists across stop/start, restart, and resize. Deleting the VM releases it.
- **Routable** — it's a real internet address, reachable from anywhere IPv6 reaches.

> **IPv6 is independent of IPv4**
>
> A VM can have IPv6 only, IPv6 + IPv4, or (private-only) neither. Adding a [public IPv4](https://metalhost.net/docs/dashboard/guides/public-ipv4.md) is a separate, billed opt-in — your free IPv6 is there either way.

## Reaching your VM over IPv6

Find the address on the VM's overview under **Public IPv6** (and in the Access card). From an IPv6-capable client:

```
ssh user@2606:2a80:...
```

Note that inbound IPv6 is gated by the same firewall as IPv4 — see below. If your local network or ISP doesn't offer IPv6 connectivity, you'll need a [public IPv4](https://metalhost.net/docs/dashboard/guides/public-ipv4.md) to reach the VM directly.

## Firewall

The public NIC is **default-deny** for both IPv4 and IPv6. A baseline SSH rule is seeded at create so you can get in; everything else is closed until you open it. [Firewall rules](https://metalhost.net/docs/dashboard/guides/firewall.md) accept IPv6 source CIDRs (e.g. `2001:db8::/32`) just like IPv4 — a rule with an empty source applies to both families.

> **don't forget v6 when locking down SSH**
>
> If you tighten the SSH rule to a specific IPv4 CIDR, remember your VM is also reachable over IPv6. Add a matching IPv6 source CIDR (or rely on the fact that, with the v4 rule in place and no v6 rule, inbound v6 on 22 is denied by default).

## Opting out: private-only VMs

If you want a VM with no internet exposure at all, toggle *Private only* at create time. That VM gets no public NIC — no IPv6 and no IPv4 — and is reachable only inside your project's [VPC](https://metalhost.net/docs/dashboard/guides/networks.md). Outbound internet still works through NAT, so it can pull packages and updates. This is a create-time choice; you can't remove the public NIC from an existing VM.

## What's next

- [Public IPv4](https://metalhost.net/docs/dashboard/guides/public-ipv4.md) — the billed, opt-in v4 address.
- [Firewall rules](https://metalhost.net/docs/dashboard/guides/firewall.md) — gate inbound on the public NIC.
- [VPC & private network](https://metalhost.net/docs/dashboard/guides/networks.md) — private connectivity and private-only VMs.
