While major cloud providers (AWS, Azure, Hetzner, etc.) increasingly impose additional surcharges of €1.00 to €2.50/month per public IPv4 address, Netcup adopts a developer-friendly reverse approach:
When ordering Root Server G12 or Cloud VPS G12 instances, choosing to forego a dedicated public IPv4 address deducts €0.60/month directly from your bill (saving €7.20/year or €21.60 over 3 years per instance).
For database replicas, private container workers, backup vaults, or web applications fronted by Cloudflare CDN, running IPv6-only is the most cost-effective hosting architecture in Europe.
However, operating in an IPv6-only environment introduces several operational gotchas. Here is a production-ready guide to configuring outbound NAT64, persistent DNS, Docker networking, and Cloudflare reverse proxies.
1. Connectivity Options & Cost Breakdown
In the Netcup configurator under Configuration -> Connectivity:
| Option | Allocated Resources | Price Adjustment | Best Used For |
|---|---|---|---|
| IPv4 + IPv6 Connectivity | 1 Dedicated IPv4 + /64 IPv6 Subnet | Base Price (±€0.00) | Legacy non-proxied services, self-hosted SMTP mail servers, direct VPN endpoints |
| IPv6 Connectivity Only | /64 IPv6 Subnet Only (No IPv4) | -€0.60 / Month | Cloudflare-proxied websites, modern backend microservices, IPv6 crawler nodes |
| None / Cloud vLAN Only | No Public IP, Datacenter Private Layer-2 Only | -€0.60 / Month | Internal databases (PostgreSQL/MySQL/Redis), private compute workers, isolated storage |
2. Persistent DNS64 / NAT64 Configuration (Debian 12 / Ubuntu 24.04)
Without an IPv4 address, your server cannot natively resolve or connect to legacy IPv4-only services. DNS64 synthesizes IPv6 addresses (using prefixes like 2001:67c:2b0:db32:...), and an upstream NAT64 gateway routes the packets to IPv4 destinations.
To prevent your configuration from being erased on reboot by systemd-resolved:
# 1. Create drop-in configuration directory
mkdir -p /etc/systemd/resolved.conf.d/
# 2. Add high-reliability European public DNS64 resolvers (Trex.fi & Cloudflare)
cat << 'EOF' > /etc/systemd/resolved.conf.d/dns64.conf
[Resolve]
# Trex.fi public NAT64 in Finland / Germany
DNS=2001:67c:2b0::4 2001:67c:2b0::6
# Cloudflare DNS64
FallbackDNS=2606:4700:4700::64 2606:4700:4700::6400
DNSSEC=no
EOF
# 3. Restart resolver service
systemctl restart systemd-resolved
ln -sf /run/systemd/resolve/resolv.conf /etc/resolv.conf
# 4. Test outbound connectivity to IPv4-only domains
curl -I http://ipv4.google.com
curl -sL https://api.ipify.org
3. Resolving GitHub and Docker IPv6 Bottlenecks
1. Fix GitHub git clone Over IPv6
Because github.com still lacks native AAAA records, route your Git SSH traffic through GitHub’s IPv6-enabled port 443:
Add to ~/.ssh/config:
Host github.com
Hostname ssh.github.com
Port 443
User git
2. Enable IPv6 for Docker Containers
By default, Docker’s default bridge is IPv4-only. Enable IPv6 in /etc/docker/daemon.json:
{
"ipv6": true,
"fixed-cidr-v6": "fd00:d0c::/64",
"experimental": true,
"ip6tables": true,
"dns": [
"2001:67c:2b0::4",
"2606:4700:4700::64"
]
}
Restart Docker:
systemctl restart docker
docker run --rm alpine ping -c 3 ipv4.google.com
4. Production Web Architecture: Cloudflare CDN + IPv6-Only Netcup Origin
[Global Visitors (IPv4 or IPv6)]
│
▼
[Cloudflare Global Anycast CDN]
│ (High-speed IPv6 Origin Fetch)
▼
[Netcup IPv6-Only Server (-€0.60/mo discount)]
1. Nginx Origin Configuration
In your Nginx virtual host, bind explicitly to the IPv6 interface and restore real visitor IP addresses:
server {
listen [::]:443 ssl http2;
server_name yourdomain.com;
# Origin SSL Certificate (e.g. Cloudflare 15-year Origin CA)
ssl_certificate /etc/nginx/ssl/cf_origin.crt;
ssl_certificate_key /etc/nginx/ssl/cf_origin.key;
# Restore real visitor IPs from Cloudflare IPv6 subnets
set_real_ip_from 2400:cb00::/32;
set_real_ip_from 2606:4700::/32;
set_real_ip_from 2803:f800::/32;
set_real_ip_from 2405:b500::/32;
set_real_ip_from 2405:8100::/32;
set_real_ip_from 2a06:98c0::/29;
set_real_ip_from 2c0f:f248::/32;
real_ip_header CF-Connecting-IP;
location / {
proxy_pass http://127.0.0.1:3000;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
}
2. Cloudflare DNS Settings
- In the Cloudflare dashboard, add an AAAA record pointing to your Netcup server’s IPv6 address (found in SCP -> Network).
- Set the proxy status to Proxied (Orange Cloud).
- In SSL/TLS, select Full (Strict).
Your website is now globally accessible, DDoS-shielded, and saves you IPv4 address fees permanently.