Manage IPv6 Address Labels Safely with ip addrlabel
You will finish with a small, reversible workflow for inspecting and changing the IPv6 address label table with ip addrlabel. Address labels influence IPv6 source and destination address selection. They are not IPv6 addresses, routes or firewall rules, and changing one does not by itself change precedence.
The route
Jump straight to the step you need, or tick off Done means at the end.
Allow about ten minutes. You need the ip command from iproute2 and an IPv6 label change that you can explain before applying it. These examples were checked with iproute2 6.1.0, package version 6.1.0-1ubuntu6.4. Listing is normally unprivileged. Adding, deleting or flushing entries requires the network administration capability, commonly supplied by sudo.
1. Check the installed command
Start with read-only checks so you know which implementation and package are in use:
$ ip -Version
ip utility, iproute2-6.1.0, libbpf 1.3.0
$ dpkg-query -W -f='${Package} ${Version}\n' iproute2
iproute2 6.1.0-1ubuntu6.4
The spelling used throughout this guide is ip addrlabel. The command also accepts the object and operation in the same order shown in the manual: add, del, list or flush.
Checkpoint
If your version differs, run ip addrlabel help and read the installed manual before copying a production change. The kernel table and the userspace tool must agree about the syntax you use.
2. Inspect the current table
Listing does not alter the table:
$ ip addrlabel list
prefix ::1/128 label 0
prefix ::/96 label 3
prefix ::ffff:0.0.0.0/96 label 4
prefix 2001::/32 label 6
prefix 2001:10::/28 label 7
prefix 3ffe::/16 label 12
prefix 2002::/16 label 2
prefix fec0::/10 label 11
prefix fc00::/7 label 5
prefix ::/0 label 1
Your entries can differ. The output has a prefix and a numeric label; an optional dev restriction can also be shown when an entry is tied to an outgoing interface. Record the table before changing it. That gives you a reference for recovery and helps catch an already existing rule.
Do not confuse the broad ::/0 entry with a route. It is an address-selection label covering all IPv6 addresses that do not match a more specific entry. The manpage says that only the label is stored in the kernel. Precedence is managed in userspace, so this command is not a general priority editor.
3. Plan one narrow label
Choose a prefix that represents the addresses whose selection behaviour you need to influence. Use a real prefix from your network, not the documentation prefix in this example. Choose a label number that your address-selection policy defines, and do not use 4294967295, written as 0xffffffff in the manual, because that value is reserved.
PREFIX='2001:db8:1234::/48'
LABEL=99
The shell assignments above change only shell variables. A prefix can be supplied with an optional interface:
sudo ip addrlabel add prefix "$PREFIX" dev eth0 label "$LABEL"
Leave out dev eth0 when the label should apply regardless of outgoing interface. Replace eth0 with the actual interface name if you do need that restriction. This command changes live kernel state, so stop if you cannot describe which traffic should match it. It does not create a persistent configuration file, and the setting may disappear after a reboot or network-management reload.
Checkpoint
Immediately inspect the result and look for the exact prefix and label:
$ ip addrlabel list | grep -F -- "$PREFIX"
prefix 2001:db8:1234::/48 label 99
If the add command reports Operation not permitted, the shell is missing the required network administration capability. Use an authorised sudo invocation or ask the system administrator. Do not treat a failed add as a successful policy test.
4. Remove the test or obsolete entry
Deleting is the recovery action for the example above. Supply the same identifying values you used for the entry:
sudo ip addrlabel del prefix "$PREFIX" dev eth0 label "$LABEL"
ip addrlabel list | grep -F -- "$PREFIX" || echo 'label removed'
Omit dev eth0 if the original entry had no device restriction. Keep the label value in the deletion command when working with this installed iproute2 build. Although the local manual describes the label as optional for deletion, the command can request it when identifying an entry. If deletion fails, first compare the prefix, label and device with the current listing rather than guessing.
If the entry was added without dev, the matching undo command is:
sudo ip addrlabel del prefix "$PREFIX" label "$LABEL"
Do not use flush as a shortcut. The manual says it removes all address labels and does not restore default settings. That is a broad, potentially service-disrupting change with no built-in undo. If someone has already flushed the table, restore the intended entries from a saved listing or the host's documented network configuration, one rule at a time.
5. Use labels without overclaiming what they do
After a change, test the application or address-selection decision that motivated it. An entry appearing in ip addrlabel list proves that the kernel table contains it. It does not prove that a particular application will choose a specific source address, because address selection also depends on available addresses, routes, scope and the userspace precedence policy.
Check the live state again after a network service reload or reboot. If your entry has vanished, identify the component that owns network configuration and add the rule there rather than relying on a one-off command. Keep the recorded before-and-after listings with the change ticket so a later operator can distinguish an intended label from an unexpected one.
Done means
- You confirmed the installed iproute2 version and read the local command contract.
- You saved the current label table before changing it.
- You used a narrow prefix, an intentional numeric label and, where needed, an exact device.
- You verified the new entry with
ip addrlabel list. - You know that labels affect address selection, while precedence is managed elsewhere.
- You can remove the entry and have avoided
flushunless a full, documented rebuild is possible.