NLB IPv6 Dual-Stack Traffic to EC2

A company hosts a highly available, scalable, and resilient application on Amazon EC2 instances that are part of an Auto Scaling group. A network engineer is planning to integrate IPv6 support with the application deployment in phases. The first phase is to enable IPv6 service consumption on the public Network Load Balancers (NLBs) that are deployed across the infrastructure. The target groups for the NLBS are configured as the Auto Scaling groups of the EC2 instances that host the application. The NLBs are configured for dual-stack operation. During the testing of the first phase, the IPv6 application queries are not reaching the backend servers. What is the cause of this issue?

  1. The subnets where the EC2 instances are deployed do not have IPv6 addresses configured. Source Reference Answer
  2. The route tables for the NLB subnets do not have IPV6 routing configured.
  3. The route tables for the EC2 subnets do not have IPV6 routing configured.
  4. The security groups that are associated with the NLBs do not allow IPv6 traffic.

Community Votes

A
80%
B
20%

80% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests understanding of NLB target group requirements; the trap is assuming protocol translation occurs automatically without IP configuration on targets.

This question tests the prerequisites for Network Load Balancer (NLB) IPv6 dual-stack operation. The consensus is that backend EC2 instances must have IPv6 addresses configured in their subnets to receive traffic from an NLB.

Option B: Users often assume the issue lies with the NLB's route table, but NLB subnets typically handle routing correctly; the bottleneck is the lack of IPv6 IPs on the actual targets.

Community Discussion (3 comments)

ashk123456 👍 1 Selected: A
For IPv6 traffic to flow from the NLB to the backend EC2 instances, the EC2 instances need to have IPv6 addresses assigned. Since the first phase was only to enable IPv6 on the NLBs, the backend EC2 instances likely weren't prepared to handle IPv6 traffic. Without IPv6 addresses configured in the EC2 subnets, the NLB cannot forward IPv6 traffic to the targets.
c1193d4 👍 1 Selected: B
See https://docs.aws.amazon.com/whitepapers/latest/ipv6-on-aws/scaling-the-dual-stack-network-design-in-aws.html NLB does the IPv6 to IPv4 conversion during this first phase so that no IPv6 configuration is necessary in the EC2 subnet
djangoGroup 👍 3 Selected: A
The EC2 subnets (where the Auto Scaling group instances run) do not have IPv6 addresses configured. Therefore, even though the Network Load Balancer (NLB) is operating in dual-stack mode and can accept IPv6 connections, it cannot forward IPv6 traffic to instances that do not themselves have IPv6 addresses in the same subnet.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Network Load Balancers operating in dual-stack mode require that both the load balancer and the registered targets (EC2 instances) support the same IP version for direct forwarding. If the Auto Scaling group instances do not have IPv6 addresses assigned within their subnet, the NLB cannot establish a connection using IPv6 because the destination endpoint lacks the necessary address. Therefore, enabling IPv6 on the NLB alone is insufficient if the backend infrastructure is not also configured for IPv6.

Why the Other Options Are Wrong

Option B is incorrect because NLB subnets are managed by AWS and generally have default routes or appropriate configurations for internet-facing LBs; the failure is at the target level. Option C is partially related but less precise than A; while route tables matter, the fundamental prerequisite is the existence of IPv6 addresses on the instances themselves. Option D is incorrect because security groups would block traffic after it reaches the instance, not prevent the NLB from attempting to forward it based on IP availability.

Community Comment Notes

Comment [1] and [2] correctly identify that EC2 instances need IPv6 addresses to receive traffic. Comment [3] suggests IPv6-to-IPv4 translation occurs, which is misleading in the context of dual-stack direct routing; while some services support NAT64, standard NLB dual-stack expects native IPv6 on targets unless specifically architected otherwise with transit gateways or specific proxies.

Related Analysis

Practice All ANS-C01 Questions

Access 137 questions with complete answers and detailed explanations.

View Full ANS-C01 Practice Test →

← Back to ANS-C01 Study Guide