guide (Updated: 2026-09-22)

Netcup IPv6-Only & Cloud vLAN Cost-Saving Guide: Save €0.60/Month (€7.20/Year)

Netcup offers a direct -€0.60/month discount on VPS and Root Servers when opting out of public IPv4. Complete engineering guide on persistent systemd-resolved DNS64/NAT64 setups, solving GitHub & Docker IPv6 issues, and Cloudflare CDN origin architecture.

#Cost Optimization #IPv6-Only #Cloud vLAN #NAT64 #Docker IPv6 #Cloudflare #DNS64

While major cloud providers (AWS, Azure, Hetzner, etc.) increasingly impose additional surcharges of €1.00 to €2.50/month per public IPv4 address, Netcup adopts a developer-friendly reverse approach:

When ordering Root Server G12 or Cloud VPS G12 instances, choosing to forego a dedicated public IPv4 address deducts €0.60/month directly from your bill (saving €7.20/year or €21.60 over 3 years per instance).

For database replicas, private container workers, backup vaults, or web applications fronted by Cloudflare CDN, running IPv6-only is the most cost-effective hosting architecture in Europe.

However, operating in an IPv6-only environment introduces several operational gotchas. Here is a production-ready guide to configuring outbound NAT64, persistent DNS, Docker networking, and Cloudflare reverse proxies.


1. Connectivity Options & Cost Breakdown

In the Netcup configurator under Configuration -> Connectivity:

Netcup Network Connectivity Tiers
-€0.60/mo Recurring Discount
Option Allocated Resources Price Adjustment Best Used For
IPv4 + IPv6 Connectivity 1 Dedicated IPv4 + /64 IPv6 Subnet Base Price (±€0.00) Legacy non-proxied services, self-hosted SMTP mail servers, direct VPN endpoints
IPv6 Connectivity Only /64 IPv6 Subnet Only (No IPv4) -€0.60 / Month Cloudflare-proxied websites, modern backend microservices, IPv6 crawler nodes
None / Cloud vLAN Only No Public IP, Datacenter Private Layer-2 Only -€0.60 / Month Internal databases (PostgreSQL/MySQL/Redis), private compute workers, isolated storage

2. Persistent DNS64 / NAT64 Configuration (Debian 12 / Ubuntu 24.04)

Without an IPv4 address, your server cannot natively resolve or connect to legacy IPv4-only services. DNS64 synthesizes IPv6 addresses (using prefixes like 2001:67c:2b0:db32:...), and an upstream NAT64 gateway routes the packets to IPv4 destinations.

To prevent your configuration from being erased on reboot by systemd-resolved:

# 1. Create drop-in configuration directory
mkdir -p /etc/systemd/resolved.conf.d/

# 2. Add high-reliability European public DNS64 resolvers (Trex.fi & Cloudflare)
cat << 'EOF' > /etc/systemd/resolved.conf.d/dns64.conf
[Resolve]
# Trex.fi public NAT64 in Finland / Germany
DNS=2001:67c:2b0::4 2001:67c:2b0::6
# Cloudflare DNS64
FallbackDNS=2606:4700:4700::64 2606:4700:4700::6400
DNSSEC=no
EOF

# 3. Restart resolver service
systemctl restart systemd-resolved
ln -sf /run/systemd/resolve/resolv.conf /etc/resolv.conf

# 4. Test outbound connectivity to IPv4-only domains
curl -I http://ipv4.google.com
curl -sL https://api.ipify.org

3. Resolving GitHub and Docker IPv6 Bottlenecks

1. Fix GitHub git clone Over IPv6

Because github.com still lacks native AAAA records, route your Git SSH traffic through GitHub’s IPv6-enabled port 443:

Add to ~/.ssh/config:

Host github.com
    Hostname ssh.github.com
    Port 443
    User git

2. Enable IPv6 for Docker Containers

By default, Docker’s default bridge is IPv4-only. Enable IPv6 in /etc/docker/daemon.json:

{
  "ipv6": true,
  "fixed-cidr-v6": "fd00:d0c::/64",
  "experimental": true,
  "ip6tables": true,
  "dns": [
    "2001:67c:2b0::4",
    "2606:4700:4700::64"
  ]
}

Restart Docker:

systemctl restart docker
docker run --rm alpine ping -c 3 ipv4.google.com

4. Production Web Architecture: Cloudflare CDN + IPv6-Only Netcup Origin

[Global Visitors (IPv4 or IPv6)]
              │
              ▼
[Cloudflare Global Anycast CDN]
              │ (High-speed IPv6 Origin Fetch)
              ▼
[Netcup IPv6-Only Server (-€0.60/mo discount)]

1. Nginx Origin Configuration

In your Nginx virtual host, bind explicitly to the IPv6 interface and restore real visitor IP addresses:

server {
    listen [::]:443 ssl http2;
    server_name yourdomain.com;

    # Origin SSL Certificate (e.g. Cloudflare 15-year Origin CA)
    ssl_certificate     /etc/nginx/ssl/cf_origin.crt;
    ssl_certificate_key /etc/nginx/ssl/cf_origin.key;

    # Restore real visitor IPs from Cloudflare IPv6 subnets
    set_real_ip_from 2400:cb00::/32;
    set_real_ip_from 2606:4700::/32;
    set_real_ip_from 2803:f800::/32;
    set_real_ip_from 2405:b500::/32;
    set_real_ip_from 2405:8100::/32;
    set_real_ip_from 2a06:98c0::/29;
    set_real_ip_from 2c0f:f248::/32;
    real_ip_header CF-Connecting-IP;

    location / {
        proxy_pass http://127.0.0.1:3000;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
    }
}

2. Cloudflare DNS Settings

  1. In the Cloudflare dashboard, add an AAAA record pointing to your Netcup server’s IPv6 address (found in SCP -> Network).
  2. Set the proxy status to Proxied (Orange Cloud).
  3. In SSL/TLS, select Full (Strict).

Your website is now globally accessible, DDoS-shielded, and saves you IPv4 address fees permanently.

❓Frequently Asked Questions (FAQ)

Is the -€0.60/month discount permanent or just for the first month?▼
The discount is permanently applied to your recurring monthly base bill for the entire lifecycle of the server. On a 3-year contract, this saves €21.60 per server. For a 5-node microservice or database cluster, this yields over €100 in net savings.
Why does my /etc/resolv.conf DNS64 configuration get wiped out after a reboot?▼
Modern Linux systems like Debian 12 and Ubuntu 24.04 use systemd-resolved or DHCP clients that dynamically overwrite /etc/resolv.conf on every reboot. You must configure a persistent drop-in file under /etc/systemd/resolved.conf.d/ to ensure DNS64 remains active permanently.
How do I fix git clone and docker pull errors on an IPv6-only server?▼
GitHub (github.com) does not provide public IPv6 AAAA records on its apex domain. You can route Git traffic over ssh.github.com port 443 or use a NAT64 gateway. For Docker, you must enable IPv6 in /etc/docker/daemon.json so the default bridge interface can reach the internet.
Can regular visitors with IPv4-only connections still access my website?▼
Yes, seamlessly! Deploy Cloudflare CDN (free tier is fully sufficient) in front of your Netcup server. Visitors connect to Cloudflare edge nodes over IPv4 or IPv6, and Cloudflare fetches content from your Netcup origin server over IPv6. Visitors notice zero difference, while your origin remains protected and saves IPv4 costs.