As mobile network operators worldwide accelerate their transition to IPv6-only core architectures — driven by address exhaustion in IPv4 and the operational cost of maintaining Carrier-Grade NAT (CG-NAT) infrastructure at scale — the 5G CPE device layer has emerged as a critical gateway for IPv6 transition strategies. For wholesale buyers, system integrators, and enterprise procurement teams evaluating 5G FWA CPE in 2026, understanding the IP transition capabilities of candidate devices is no longer optional. It directly affects application compatibility, VPN performance, IoT sensor reachability, and total cost of ownership across the device lifecycle.
Why IPv6 Matters for 5G CPE in 2026
The 3GPP 5G specification has mandated IPv6 support since Release 15, and virtually every 5G SA (Standalone) core deployed today operates on an IPv6-native user plane. Major operators — including T-Mobile US, Reliance Jio, Deutsche Telekom, and China Mobile — have publicly committed to IPv6-only or IPv6-dominant architectures for their 5G SA networks, with CG-NAT positioned as a transitional bridge rather than a permanent solution.
For CPE buyers, this shift introduces a concrete set of technical evaluation criteria that go well beyond “does it support IPv6.” The device must handle:
- IPv6-only WAN with IPv4-only LAN clients. The most common deployment scenario in 2026: the operator provides an IPv6-only PDN connection, but the enterprise LAN still runs legacy IPv4-only devices (printers, cameras, building management systems, industrial controllers).
- Dual-stack application coexistence. Enterprise SaaS applications, VPN concentrators, and SD-WAN endpoints may be reachable over either protocol depending on carrier peering and application provider infrastructure.
- 464XLAT translation performance. The CPE must perform stateless IPv4-IPv6 translation at line rate without introducing latency that degrades real-time applications — particularly critical for voice, video conferencing, and industrial control traffic.
Key Architectural Components to Evaluate
1. WAN-Side IP Stack: Dual-Stack vs. IPv6-Only with CLAT
The most mature approach is dual-stack WAN, where the CPE receives both an IPv6 prefix (via DHCPv6-PD or SLAAC) and an IPv4 address from the 5G core. This provides maximum compatibility but requires the operator to maintain dual-stack infrastructure — precisely the operational burden that IPv6-only cores aim to eliminate.
The emerging standard is IPv6-only WAN with CLAT (Customer-side Translator), defined in RFC 6877 (464XLAT). In this architecture, the CPE receives only an IPv6 address/prefix from the 5G core, a CLAT function embedded in the CPE performs stateless NAT46 translation for IPv4-only LAN clients, and the operator provides a PLAT (Provider-side Translator) in the core network.
For buyers, the critical evaluation point is whether the CPE’s CLAT implementation is hardware-accelerated (via NPU or dedicated packet processing engine) or software-based. Hardware-accelerated CLAT can sustain 2–5 Gbps of NAT46 throughput with sub-millisecond latency; software CLAT may cap at 300–800 Mbps and introduce 2–5ms of additional latency per packet.
2. LAN-Side DHCP and DNS Architecture
IPv6 transition puts significant pressure on the CPE’s LAN-side services. Buyers should verify:
- DNS64/NAT64 integration. The CPE must synthesize AAAA records for IPv4-only destinations (DNS64) and route the resulting traffic through a NAT64 gateway. Poor DNS64 implementations can break DNSSEC validation.
- DHCPv6-PD sub-delegation. Enterprise deployments often require the CPE to sub-delegate IPv6 prefixes to downstream routers or VLANs. Verify that the device can receive a /56 or /48 prefix and delegate /60 or /64 sub-prefixes.
- Happy Eyeballs v2 (RFC 8305) support. The CPE should not interfere with endpoint Happy Eyeballs algorithms. Some CPE ALG implementations inadvertently break dual-stack connection racing.
3. Firewall, ALG, and Application Layer Gateway Behavior
IPv6 introduces a fundamentally different security model at the CPE. Unlike IPv4, where NAT provides implicit ingress filtering, IPv6’s end-to-end architecture requires explicit stateful firewall rules. Buyers should evaluate stateful IPv6 firewall with default-deny inbound, RFC 4890 compliant ICMPv6 handling, and ALG transparency for SIP, FTP, and other protocols that rewrite IP addresses in application-layer payloads.
4. VPN and SD-WAN Interoperability
Enterprise VPN clients — IPSec, WireGuard, OpenVPN, and SD-WAN edge appliances — exhibit varying levels of IPv6 compatibility. The CPE must pass IPv6-encapsulated VPN traffic transparently, support IPv6 WAN addressing for management plane TR-069/TR-369 USP sessions, and handle fragmented IPv6 packets correctly.
The CG-NAT Sunset Horizon
Operators worldwide are beginning to signal CG-NAT sunset timelines. T-Mobile US has indicated that its 5G SA core will move to IPv6-only with 464XLAT as the default CPE configuration by 2027. European operators following GSMA IPv6 transition guidelines are on similar trajectories. For CPE buyers, this means devices purchased today on 3–5 year deployment cycles will almost certainly need to operate in IPv6-dominant environments within their service lifetime.
Honlly’s IPv6 Transition Architecture
Honlly Telecom’s 5G CPE portfolio implements hardware-accelerated 464XLAT CLAT with dedicated packet processing engines capable of sustaining multi-gigabit NAT46 throughput at wire speed. The platform supports both dual-stack and IPv6-only WAN modes, with dynamic mode selection via TR-369 USP provisioning. Enterprise features including DHCPv6-PD sub-delegation, RFC 4890-compliant ICMPv6 filtering, and transparent VPN passthrough are standard.
Evaluation Checklist for IPv6 Transition
- CLAT performance: Hardware-accelerated with verified throughput ≥ 1 Gbps NAT46
- DNS64/NAT64: Embedded DNS64 with RFC 7050-compliant NAT64 discovery
- Firewall: Stateful IPv6 firewall with default-deny inbound, RFC 4890 ICMPv6
- Prefix delegation: DHCPv6-PD with sub-delegation to LAN interfaces
- VPN transparency: WireGuard, IPSec, and SD-WAN passthrough validated
For detailed technical specifications on Honlly’s 5G CPE IPv6 capabilities, visit honllytelecom.com/products or contact the Honlly B2B engineering team.

