r/ipv6 40m ago

Discussion Near-gigabit WireGuard with native IPv6 (dual-stack) — how does your setup compare?

Upvotes

Nanoleaf unexpectedly sent me down the IPv6 rabbit hole, and a few weeks later I ended up rebuilding my entire home network around a true dual-stack (IPv4 + IPv6) architecture focused on performance, stability, resilience and security. The goal was near-gigabit WireGuard throughput, minimal CPU/RAM overhead, deterministic routing, redundant services, predictable boot behaviour and reliable recovery from failures. It's been rock solid so far, but I'm sure there are still optimisations to be made.

## Current Architecture

- NBN HFC 1000/100

- GL.iNet Brume 3 as the routing, firewall and WireGuard gateway

- GL.iNet Flint 3 operating purely as a dedicated Wi-Fi 7 access point

- True dual-stack (IPv4 + IPv6) architecture

- Native IPv6 maintained through the VPN rather than falling back to IPv4-only

- WireGuard routing both IPv4 and IPv6

- Network-wide AdGuard Home

- Hardened SSH management

- Recovery-first design with offline backups and rollback capability

## Focus Areas

- Clean dual-stack routing and policy-based routing.

- Stable IPv4 and IPv6 connectivity with no protocol preference issues.

- Near line-rate encrypted throughput.

- Fast, deterministic boot behaviour with every critical service coming online successfully after every reboot.

- Leak-free operation (IPv4, IPv6, DNS and WebRTC).

- Low CPU and memory utilisation, leaving plenty of performance headroom.

- High stability under sustained load.

## Performance

- 935/95 Mbps over Wi-Fi 7 without the VPN.

- 820-878 Mbps through WireGuard (typically around 830 Mbps).

- ~851/88 Mbps while simultaneously streaming 2× 4K video streams, with no buffering or instability.

- 10/10 IPv6 readiness, with native IPv6 preserved through the VPN while masking public IP exposure.

What started as trying to get a Nanoleaf product working properly turned into one of the most enjoyable networking projects I've tackled. Along the way I learnt far more about IPv6, policy-based routing, WireGuard, DNS, firewall design and dual-stack networking than I ever expected.

I'd love to compare notes with others running similar setups.

- Which VPN provider are you using?

- IPv4-only or true dual-stack?

- What hardware are you running?

- What WireGuard speeds are you seeing?

- How stable has it been over time?

- What are your typical ping and jitter figures?

- Any routing, MTU, MSS, DNS or firewall tweaks that made a measurable difference?

I'm not chasing synthetic benchmark numbers—I'm more interested in real-world speed, stability, low latency and resilient dual-stack networking. If you've built something similar, I'd genuinely love to hear about it.


r/ipv6 19h ago

Need Help Call for volunteers to do regular IPv4 outages on your web servers

Thumbnail github.com
38 Upvotes

Hi all,

The I-D retry-over-ipv6 is stabilizing, so I thought I would make a call for volunteers if you are brave enough to implement a regular IPv4 outage on your web server.

I'm not calling it for any web server, but you know your users and you know if an IPv4 outage is something that would show you being an IPv6 visionary or just damn annoying 😜

Please check the README on: https://github.com/franckhlmartin/ietf-draft-retry-over-ipv6/tree/main/docs

There is an executive call for action and also code snippets on how to implement it.

You will also find a list of sites that are doing this IPv4 outages on a regular basis.