Summary
- An IPv6 address and ordinary packet can be reachable while a packet carrying a Fragment, Destination Options, Hop-by-Hop or Routing header is dropped or moved to a slow path. Capability therefore belongs to a tested path, direction, header chain and time window—not to “IPv6” in the aggregate.
- RFC 7872 and later APNIC and RIPE work demonstrate material, experiment-specific loss and sharp variation by header, option size, endpoint population and server environment. Those historical measurements prove the need for controls; they are not a 2026 global drop-rate census.
- The networks and vendors that own parsers, firewalls and DDoS services exercise practical admission power. A falsifiable baseline must compare ordinary IPv6 with declared EH variants across paths and device families, while a credible counterfactual publishes bounded capability, diagnostics and expiry rather than promising universal carriage.
One address, two packet realities
Suppose a subscriber or server has a working IPv6 address. DNS returns it. BGP carries the prefix. A short control packet arrives. These are useful facts. They do not establish what happens when the upper-layer header sits behind an extension-header chain.
IPv6’s base header is 40 bytes. Optional internet-layer information lives in separate extension headers. RFC 8200 defines Hop-by-Hop Options, Destination Options, Routing and Fragment headers among the architecture’s core forms, alongside IPsec-related headers. The chain is followed through successive Next Header fields until the upper-layer protocol is found. A firewall that wants a TCP or UDP port must keep parsing.
That variable depth is the economic mechanism. High-speed packet equipment has finite parser stages, fixed buffers and finite slow-path capacity. A box can forward a plain IPv6 packet at line rate yet handle a deeper chain differently: inspect, ignore, punt, rate-limit or discard. The packet format is global. The budget is purchased one chassis, firewall service and cloud edge at a time.
RFC 7045 says forwarding nodes should carry packets regardless of present extension headers and requires inspecting firewalls to recognise standard types appropriately. It also preserves intentional configured policy. This is the correct technical distinction and an awkward commercial one. A specification can say what interoperability requires; it cannot install parser silicon in a third party’s old line card or compel an independently operated DDoS service to accept risk.
RFC 7112 improves inspectability by requiring the first fragment to contain the entire chain through the upper-layer header. It does not guarantee that every device can reach that header. RFC 9098 identifies the harder edge: beyond the path MTU, the architecture has no universal ceiling on the number of headers or their aggregate depth. Finding Layer 4 means walking the chain in order. “IPv6 supported” is consequently too broad to be evidence.
The measurements are warnings, not current market shares
RFC 7872 published a detailed 2016 record. Its World IPv6 Launch web-server dataset reported drops of 11.88% for an eight-byte Destination Options header, 40.70% for an eight-byte Hop-by-Hop header and 30.51% for its tested Fragment condition. The corresponding Alexa web-server values were 10.91%, 39.03% and 28.26%. Results differed for mail and name servers; the Alexa name-server Fragment condition reached 55.23%.
Those figures matter because ordinary IPv6 destinations were not a sufficient denominator. Header type and destination population changed the outcome. They must not be presented as today’s global rate. The input lists, server roles, paths, packet construction and observation period belong to the result.
APNIC later reversed the direction, recruiting clients through online advertisements and sending extension-header traffic from a small server set. Its October 2022 account said the platform executed about four million measurements a day. The June 2023 follow-up varied Destination Options and Hop-by-Hop padding through 8, 16, 32, 64 and 128 bytes and tested Fragment initial sizes from 1,200 to 1,416 octets.
The 2023 APNIC article reported roughly 30% Destination Options loss through 64 bytes and roughly 55% at 128 bytes, after an unexplained change from about 90% to 55%. The same APNIC article reported that a University of Aberdeen experiment from 27 April to 15 May 2023 recorded 370,742 Hop-by-Hop trials with 99.04% loss overall. The 8-byte case was 98.25%; the 128-byte case was 99.99%. Yet sampled access networks differed, and the authors did not claim to have conclusively located the dropping component.
That caveat is not cosmetic. A result close to 99% may describe the full tested path, including hosting and virtualisation, not one universal rule in the public Internet. The finding is stronger when kept narrow: moving the server, option size or sampled access AS changed what could be inferred. Compatibility needs a matrix, not a slogan.
RIPE Atlas packet-size work supplies an adjacent control. It reported about 10% of participating IPv6 probes with fragmentation problems while also recording about 11% baseline all-loss at 100-byte probes. The experiment used roughly 1,284–1,292 IPv6 probes depending on the size case and explicitly declined to generalise to the entire Internet. A baseline matters because every failed variant should first be conditioned on the same endpoint successfully carrying ordinary IPv6.
The parser is a control surface
The vendor record makes the cost concrete. A Cisco extension-header paper describes named hardware platforms with fixed parsing resources, a 64-byte EH-chain example for hardware processing and software-path treatment beyond that boundary when upper-layer filters apply. A Cisco IOS XR 7.1.1 NCS 5500 guide documents line-card differences, including models with hardware handling for specified headers and cases where Layer 4 ACL matching with EH traffic is unavailable.
Juniper exposes EH match conditions and platform-specific support. On one IDS service surface, omitting the explicit allow-ipv6-extension-header rule blocks packets containing any extension header. Nokia documentation offers ipv6-eh max and limited modes and, in the cited release, searches up to six headers for certain filter matches.
These documents do not establish global vendor rankings. They prove something more useful: parser depth, recognised types, defaults and fast-path treatment are product and release properties. An operator choosing hardware also chooses which future packet shapes remain inexpensive. A cloud or DDoS supplier can make the same choice for customers who never see the chassis.
Security cost is real. RFC 8504 permits host limits on header length, header count, option count and aggregate chain. RFC 8883 defines ICMPv6 codes for an extension header that is too large, a chain that is too long, too many headers and too many options. RFC 9288 gives transit filtering recommendations. RFC 9673 updated Hop-by-Hop processing in October 2024 to make selective, practical processing possible without pretending every router must execute every option. RFC 9805 later deprecated Router Alert for new protocols while leaving existing use scoped.
The pattern is not “standards versus bad operators”. Unlimited parser work is not a credible entitlement. Opaque silent failure is not credible assurance. The useful operating question is which bounded profile a path carries, at what rate, with which diagnostic and until which hardware or policy change.
Measure the feature that procurement bought
A defensible 90-day test needs three access, three transit and three cloud or DDoS service families; three router-silicon, three firewall and three host-stack families; and 100 independently observed path pairs per service family. Test ordinary IPv6, Fragment, Destination Options, Hop-by-Hop and Routing or SRH conditions.
Vary aggregate EH depth through 8, 16, 32, 64 and 128 bytes; use recommended and alternate valid order where applicable; exercise TCP, UDP and QUIC-like UDP at 256, 1,200 and 1,400 bytes; run 100 trials per cell. Record delivery, silent loss, p95 latency, throughput, ICMP, parser/slow-path counters and CPU where equipment is controlled.
The thesis is deliberately rejectable. Reject it only if every valid EH cell is within 0.1 percentage point of ordinary IPv6 delivery, no family produces more than one silent EH-specific drop per 100,000 trials, p95 latency and throughput remain within 2%, controlled CPU rises by less than five percentage points, no slow-path discontinuity appears through 128 EH bytes, and 99.9% of deliberately exceeded declared limits return the expected RFC 8883 error. Header type, bytes, order, device and policy must add no predictive power beyond ordinary reachability, while new EH uses expand without tunnels, allowlists, probing or replacement.
Evidence strengthens the trend if a valid 8-byte header creates a delivery gap above five percentage points on at least 10% of controlled paths; 64 to 128 bytes produces a reproducible cliff; p95 latency rises over 25%; throughput falls over 20%; CPU rises more than 15 percentage points; more than half of limit discards yield no usable ICMP; or changing only device, firmware, DDoS service or path changes the result. These are prospective thresholds, not convenient claims about 2026.
What an IPv6 allocation does not buy
For a number-resource holder, an allocation establishes uniqueness and a registry record. A BGP route establishes some control-plane visibility. Neither is a purchase order for optional packet processing throughout a supplier chain.
That distinction should affect procurement. Ask providers to disclose EH types and byte limits, fast versus slow path, relevant firewall defaults, RFC 8883 counters, and the expiry condition after firmware, chassis, cloud edge or policy change. Test in both directions. An SLA that says only “IPv6 connectivity” may be perfectly accurate while covering much less than an application designer imagines.
It also limits governance claims. IANA’s registry gives common identifiers. IETF documents give common syntax and processing expectations. RIRs allocate and record addresses. None of those roles operates a transit parser or creates a mandate over private equipment. Conversely, a box on the path has practical power but not global legitimacy. Its operator can protect its service; it should disclose the effect, bound the policy and supply a useful failure signal.
The lock-in is circular. Applications avoid extension headers because carriage is uncertain. Low use makes capable silicon harder to justify. Fixed silicon then makes new use uncertain. Encapsulation or a closed SRv6 domain can break the loop, but moves control into a tunnel or controller that brings its own switching cost. The public Internet stays “extensible” on paper while buying compatibility as an exception.
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
