Short answer: IPv6 is the newer version of the internet’s addressing system, with enough addresses for every device to have its own. If your provider supports it, leave it switched on and keep your router’s firewall on. Turn it off only to troubleshoot a specific problem.

Why IPv4 needs NAT

IPv4 addresses are scarce, so your home gets one public address and your devices use private ones, from ranges such as 192.168.0.0/16. Your router shares the public address using NAT, which lets connections start from inside while allowing incoming ones only by exception. Some providers even share addresses between customers with carrier-grade NAT, using the 100.64.0.0/10 range. That sharing is behind many NAT type and port forwarding problems.

What IPv6 changes

IPv6 is the successor to IPv4, and it increases addresses from 32 to 128 bits. That’s enough for every device to have its own public address, so there’s no need to share one. Most homes run both side by side, and devices use IPv6 when the website or service supports it. For the basics of how addressing fits together, see how a home network works.

Privacy

If each device has its own address, couldn’t it be tracked? IPv6 handles this with temporary addresses: devices generate addresses that change over time, typically after hours to days, to make it harder to link their activity, and use them for outgoing connections.

Security

Should you turn it on?

If you set custom DNS servers, add their IPv6 addresses too; Cloudflare’s, for example, include 2606:4700:4700::1111. See how to change your DNS server.