The countdown to Elevate 2026 is on. Join us in Chicago, London, or Sydney.

Register here

Partners

Docs

LM Academy

LM Community

Platform

Solutions

Pricing

Resources

Company

Platform
  • Infrastructure
  • Cloud & Multi-Cloud
  • Log Management
  • Edwin AI
Solution
  • Automation
  • Tool Consolidation
  • Reduce MTTR
  • Cost Optimization
Industry
  • Healthcare
  • Financial Services
  • Public Sector
  • MSP
Role
  • CIO
  • ITOps
  • CloudOps
  • AIOps
There is no result.
Try it free

14-day access to the full LogicMonitor platform

Explore Platform

One platform, one system for observability, intelligence, and action.

Agentic AIOps

Infrastructure Observability

Cloud Observability

Internet Performance Monitoring

Digital Experience Monitoring

Log Management

3,000+ Integrations

Agentic AIOps Overview

Autonomously detect, diagnose, and resolve issues across your environment.

Meet Edwin AI

Turn fragmented cross-domain event noise into explainable, guided action.

AI Agent

Deploy specialized AI agents to handle investigation across the incident lifecycle.

Event Intelligence

Compress raw alert storms into high-fidelity, prioritized insights.

AI Automation

Execute governed, closed-loop remediation across automation playbooks.

ITOps Context Graph

NEW

Unify topology, telemetry, and changes into an AI-ready context layer.

MCP

NEW

Establish traceable, secure governance boundaries for AI tool integrations.

Infrastructure Observability Overview

Full visibility across your entire hybrid estate to eliminate tool sprawl.

Network Monitoring

Accelerate time to innocence with deep network path and device visibility.

Server Monitoring

Track server health, OS metrics, and resource utilization across environments.

Remote Monitoring

Monitor distributed endpoints, branch networks, and remote facility health.

VM Monitoring

Maximize hypervisor performance and streamline compute capacity planning.

SD-WAN Monitoring

Keep multi-site cloud networks connected with real-time edge visibility.

Database Monitoring

Pinpoint database query bottlenecks to keep business applications fast.

Configuration Monitoring

Minimize change failure rates by tracking device configuration drift.

Storage Monitoring

Track SAN/NAS arrays, IOPS bottlenecks, and storage capacity trends.

Cloud Observability Overview

Multi-cloud and hybrid environments unified into a single operational pane.

Container Monitoring

Automated, real-time visibility for Kubernetes and ephemeral microservices.

AWS Monitoring

Track AWS services, scaling, and costs alongside on-premises data.

Google Cloud Monitoring

Monitor native GCP infrastructure, compute, and serverless resources.

Azure Monitoring

Comprehensive visibility into Azure environments, gateways, and workloads.

AI Monitoring

Track LLM infrastructure, GPU utilization, and AI application stack health.

Oracle Cloud Monitoring

Track OCI native compute, enterprise databases, and cloud storage.

SaaS Monitoring

Validate availability and workforce productivity for critical SaaS apps.

Cloud Cost Optimization

Optimize cloud spend, maintain performance, and control budgets.

Internet Performance Monitoring Overview

Understand performance across the full stack wherever users depend on it.

Internet Health

NEW

Use global vantage points to independently validate internet outages.

Real User Monitoring

NEW

Capture actual customer journeys and frontend performance in real time.

Synthetic Monitoring

NEW

Emulate user transactions and SaaS workflows to catch problems early.

Endpoint Monitoring

NEW

Diagnose remote workforce digital experience across devices and networks.

Digital Experience Monitoring

See every dependency, regardless of ownership or location.

Website Monitoring

Protect revenue journeys with proactive synthetic checks and uptime tracking.

CDN Monitoring

NEW

Audit edge performance and latency variance across your CDN providers.

API Monitoring

NEW

Test endpoints and third-party API reliability for critical app integrations.

Application Performance Monitoring

Connect code execution and traces directly to infrastructure health.

DNS Monitoring

NEW

Speed up time-to-innocence by tracking global nameserver resolution times.

DevOps Lifecycle Monitoring

NEW

Protect release velocity by validating dependencies during deployments.

BGP Monitoring

NEW

Trace global routing changes and path leaks to secure internet reachability.

Log Management Overview

Centralize and correlate log data to resolve incidents before they escalate.

Log Analytics & Intelligence

Correlate contextual log data with metrics to speed up root-cause analysis.

WebPageTest Web Performance

Test, compare, and optimize website speed, Core Web Vitals, and performance across real devices and global locations.

Learn more
Explore Solutions

Proactively manage modern hybrid environments with predictive insights, intelligent automation, and full-stack observability.

By Business Outcome

By Role

By Industry

Professional Services

Autonomous IT

Predictive, autonomous IT built

for resilience.

Automation

Eliminate operational toil with safe, policy-governed remediation workflows.

Modernization and Transformation

Accelerate complex technology transitions while protecting core enterprise resilience.

Cloud Migration

Maintain workload performance throughout migration.

Tool Consolidation

Reduce licensing costs and silos by replacing fragmented monitoring tools.

Cost Optimization

Lower your total cost-to-serve by finding cloud waste and underused resources.

Operational Efficiency

Maximize team capacity by reducing alert storms and shift-handoff friction.

Reduce MTTR

Shorten war-rooms by surfacing topology-aware probable cause in mins.

Network Reachability

NEW

Independently audit external BGP, ISP, and SaaS provider connectivity boundaries.

Edge Deployment Optimization

NEW

Monitor SLOs, compare providers, and validate cloud and edge delivery.

Web Performance Optimization

NEW

Maximize digital checkout conversions by tracking global frontend latency metrics.

Application Resilience

NEW

Safeguard business services against transaction failures and costly downtime.

Workforce Productivity

NEW

Troubleshoot remote hardware and network issues to protect productivity.

CIO

Maximize enterprise resilience and align AI investments to measurable business ROI.

AIOps

Compress cross-domain event noise into explainable, automated ops leverage.

DevOps

Speed up releases by protecting engineering roadmaps from toil.

ITOps

Standardize incident response to reduce alert fatigue and after-hours work.

CloudOps

Unify multi-cloud visibility to optimize costs and track hybrid blast radius.

Healthcare

Protect continuity of care and EHR availability across clinical workflows.

Public Sector

Ensure mission continuity and audit readiness for citizen-facing services.

MSP

Protect service margins and scale ops using multi-tenant, AI-assisted triage.

Retail & E-commerce

Safeguard peak retail campaigns, POS uptime, and digital customer journeys.

Technology

Protect customer trust and engineering velocity with SLA-driven visibility.

Hospitality

Deliver frictionless guest experiences and keep booking engines online.

Education

Maintain always-on student portals, learning platforms, and campus networks.

Manufacturing

Prevent production downtime by unifying IT, OT-adjacent, and edge systems.

Financial Services

Secure transaction trust and meet strict resilience compliance requirements.

Why LogicMonitor?

Discover why leading IT teams trust us to unify hybrid observability and eliminate tool sprawl.

Learn more
Explore Resources

Check out our resource library for IT pros, featuring expert guides, strategies, and insights for smarter, AI-driven operations.

Resources

Upcoming Events

Platform Help

Blog

Insights and advice from the experts on all things observability and AI.

Case Studies

See what real users have to say about the LogicMonitor platform.

Webinars

Live and on-demand learning, all in one place.

IT Guides

Learn from expert guides on the topics that matter most to IT teams.

How We Compare

See how our platform stacks up against other solutions.

CONFERENCE

SWORD Day

September 17, 2026

Geneva

WEBINAR

Incident Management Has Outgrown Its Playbook

September 23, 2026

Online

View all events

Join us at innovation-focused conferences, tech talks, webinars, and other events.

Support Docs

Access product docs, release notes, and support resources.

LM Community

Join the community to learn from peers, ask questions, and connect with experts.

Customer Education

Learn more about our platform through resources and live trainings.

2026 The Year of Autonomous IT

NEW

Discover the trends, benchmarks, and strategies driving the industry shift to Autonomous IT.

Read the report
About LogicMonitor

Our observability platform proactively delivers the insights and automation CIOs need to accelerate innovation.

Leadership

Meet the leaders building the future of observability and AI.

Our Customers

See the proof of how IT teams win with LogicMonitor.

Careers

Find job openings and learn about our employee benefits.

Newsroom

Stay current with our latest mentions, press releases, and events.

Culture

NEW

Join a collaborative, values-driven culture built on innovation and growth.

Security

Purpose-built security for the hybrid observability and AI era.

Contact & Locations

Connect with our experts to explore AI-powered observability solutions.

Sustainability

Our commitment to the environment and the people in it.

The countdown to Elevate 2026 is on. Join us in Chicago, London, or Sydney.

Register here
Try it free

Platform

Explore Platform

One platform, one system for observability, intelligence, and action.

Agentic AIOps

Infrastructure Observability

Cloud Observability

Internet Performance Monitoring

Digital Experience Monitoring

Log Management

3,000+ Integrations

WebPageTest Web Performance

Test, compare, and optimize website speed, Core Web Vitals, and performance across real devices and global locations.

Solutions

Explore Solutions

Proactively manage modern hybrid environments with predictive insights, intelligent automation, and full-stack observability.

By Business Outcome

By Role

By Industry

Professional Services

Why LogicMonitor?

Discover why leading IT teams trust us to unify hybrid observability and eliminate tool sprawl.

Pricing

Resources

Explore Resources

Check out our resource library for IT pros, featuring expert guides, strategies, and insights for smarter, AI-driven operations.

Resources

Upcoming Events

Platform Help

NEW

2026 The Year of Autonomous IT

Discover the trends, benchmarks, and strategies driving the industry shift to Autonomous IT.

Company

About LogicMonitor

Our observability platform proactively delivers the insights and automation CIOs need to accelerate innovation.

Leadership

Meet the leaders building the future of observability and AI.

Careers

Find job openings and learn about our employee benefits.

Culture

NEW

Join a collaborative, values-driven culture built on innovation and growth.

Contact & Locations

Connect with our experts to explore AI-powered observability solutions.

Our Customers

See the proof of how IT teams win with LogicMonitor.

Newsroom

Stay current with our latest mentions, press releases, and events.

Security

Purpose-built security for the hybrid observability and AI era.

Sustainability

Our commitment to the environment and the people in it.

Partners

Docs

LM Academy

LM Community

Agentic AIOps

Agentic AIOps Overview

Autonomously detect, diagnose, and resolve issues across your environment.

Meet Edwin AI

Turn fragmented cross-domain event noise into explainable, guided action.

AI Agent

Deploy specialized AI agents to handle investigation across the incident lifecycle.

Event Intelligence

Compress raw alert storms into high-fidelity, prioritized insights.

AI Automation

Execute governed, closed-loop remediation across automation playbooks.

ITOps Context Graph

NEW

Unify topology, telemetry, and changes into an AI-ready context layer.

MCP

NEW

Establish traceable, secure governance boundaries for AI tool integrations.

Infrastructure Observability

Infrastructure Observability Overview

Full visibility across your entire hybrid estate to eliminate tool sprawl.

Network Monitoring

Accelerate time to innocence with deep network path and device visibility.

Server Monitoring

Track server health, OS metrics, and resource utilization across environments.

Remote Monitoring

Monitor distributed endpoints, branch networks, and remote facility health.

VM Monitoring

Maximize hypervisor performance and streamline compute capacity planning.

SD-WAN Monitoring

Keep multi-site cloud networks connected with real-time edge visibility.

Database Monitoring

Pinpoint database query bottlenecks to keep business applications fast.

Configuration Monitoring

Minimize change failure rates by tracking device configuration drift.

Storage Monitoring

Track SAN/NAS arrays, IOPS bottlenecks, and storage capacity trends.

Cloud Observability

Cloud Observability Overview

Multi-cloud and hybrid environments unified into a single operational pane.

Container Monitoring

Automated, real-time visibility for Kubernetes and ephemeral microservices.

AWS Monitoring

Track AWS services, scaling, and costs alongside on-premises data.

Google Cloud Monitoring

Monitor native GCP infrastructure, compute, and serverless resources.

Azure Monitoring

Comprehensive visibility into Azure environments, gateways, and workloads.

AI Monitoring

Track LLM infrastructure, GPU utilization, and AI application stack health.

Oracle Cloud Monitoring

Track OCI native compute, enterprise databases, and cloud storage.

SaaS Monitoring

Validate availability and workforce productivity for critical SaaS apps.

Cloud Cost Optimization

Optimize cloud spend, maintain performance, and control budgets.

Internet Performance Monitoring

Internet Performance Monitoring Overview

Understand performance across the full stack wherever users depend on it.

Internet Health

NEW

Use global vantage points for independent validation of internet outages.

Real User Monitoring

NEW

Capture actual customer journeys and frontend performance in real time.

Synthetic Monitoring

NEW

Emulate user transactions and SaaS workflows to catch problems early.

Endpoint Monitoring

NEW

Diagnose remote workforce digital experience across devices and networks.

Digital Experience Monitoring

Digital Experience Monitoring

See every dependency, regardless of ownership or location.

Website Monitoring

Protect revenue journeys with proactive synthetic checks and uptime tracking.

CDN Monitoring

NEW

Audit edge performance and latency variance across your CDN providers.

API Monitoring

NEW

Test endpoints and third-party API reliability for critical app integrations.

Application Performance Monitoring

Connect code execution and traces directly to infrastructure health.

DNS Monitoring

NEW

Speed up time to innocence by tracking global nameserver resolution times.

DevOps Lifecycle Monitoring

NEW

Protect release velocity by validating dependencies during deployments.

BGP Monitoring

NEW

Trace global routing changes and path leaks to secure internet reachability.

Logs

Log Management Overview

Centralize and correlate log data to resolve incidents before they escalate.

Log Analytics & Intelligence

Correlate contextual log data with metrics to speed up root-cause analysis.

By Business Outcome

Autonomous IT

Predictive, autonomous IT built for resilience.

Automation

Eliminate repetitive operational toil with safe, policy-governed remediation workflows.

Modernization and Transformation

Accelerate complex technology transitions while protecting core enterprise resilience.

Cloud Migration

Maintain workload performance throughout migration.

Tool Consolidation

Reduce licensing costs and data silos by replacing fragmented monitoring tools.

Cost Optimization

Lower your total cost-to-serve by finding cloud waste and underused resources.

Operational Efficiency

Maximize team capacity by reducing alert storms and shift-handoff friction.

Reduce MTTR

Shorten war-room by surfacing topology-aware probable cause in mins.

Network Reachability

NEW

Independently audit external BGP, ISP, and SaaS provider connectivity boundaries.

Edge Deployment Optimization

NEW

Monitor SLOs, compare providers, and validate cloud and edge delivery.

Web Performance Optimization

NEW

Maximize digital checkout conversions by tracking global frontend latency metrics.

Application Resilience

NEW

Safeguard business services against transaction failures and costly downtime.

Workforce Productivity

NEW

Troubleshoot remote hardware and network issues to protect productivity.

By Role

CIO

Maximize enterprise resilience and align AI investments to measurable business ROI.

AIOps

Compress cross-domain event noise into explainable, automated ops leverage.

DevOps

Speed up releases by protecting engineering roadmaps from toil.

ITOps

Standardize incident response to reduce alert fatigue and after-hours work.

CloudOps

Unify multi-cloud visibility to optimize costs and track hybrid blast radius.

By Industry

Healthcare

Protect continuity of care and EHR availability across clinical workflows.

Public Sector

Ensure mission continuity and audit readiness for citizen-facing services.

MSP

Protect service margins and scale ops using multi-tenant, AI-assisted triage.

Retail & E-commerce

Safeguard peak retail campaigns, POS uptime, and digital customer journeys.

Technology

Protect customer trust and engineering velocity with SLA-driven visibility.

Hospitality

Deliver frictionless guest experiences and keep booking engines online.

Education

Maintain always-on student portals, learning platforms, and campus networks.

Manufacturing

Prevent production downtime by unifying IT, OT-adjacent, and edge systems.

Financial Services

Secure transaction trust and meet strict operational resilience compliance requirements.

Resources

Blog

Insights and advice from the experts on all things observability and AI.

Case Studies

See what real users have to say about the LogicMonitor platform.

Webinars

Live and on-demand learning, all in one place.

IT Guides

Learn from expert guides on the topics that matter most to IT teams.

How We Compare

See how our platform stacks up against other solutions.

Upcoming Events

CONFERENCE

SWORD Day

September 17, 2026

WEBINAR

Incident Management Has Outgrown Its Playbook

September 23, 2026

View all events

Join us at innovation-focused conferences, tech talks, webinars, and other events.

Platform Help

Support Docs

Access product docs, release notes, and support resources.

LM Community

Join the community to learn from peers, ask questions, and connect with experts.

Customer Education

Learn more about our platform through resources and live trainings.

BENEFITS OF IPV6

How EUI-64 Works in IPv6

Discover how EUI-64 maps hardware addresses into IPv6 identifiers for DHCP-free autoconfiguration, with Cisco IOS examples and an analysis of the privacy implications driving modern alternatives.

13–19 minutes
June 24, 2026
Denton Chikura

IN THIS DEEP DIVE

CHAPTERS

    NEWSLETTER

    Subscribe to our newsletter

    Get the latest blogs, whitepapers, eGuides, and more straight into your inbox.

    SHARE

    The quick download:

    Why EUI-64 matters for IPv6 network addressing

    • EUI-64 converts a 48-bit MAC address into a 64-bit IPv6 interface identifier using a three-step process: split, insert FFFE, and flip bit 7.

    • On Cisco IOS, enabling IPv6 on an interface automatically generates a link-local address via EUI-64. No manual configuration required.

    • Linking hardware and IPv6 addresses simplifies autoconfiguration and troubleshooting, but exposes device identity and enables cross-network tracking.

    • Privacy concerns have driven Microsoft Windows and others to replace EUI-64 with random identifiers or RFC 4941 privacy extensions by default.

    How EUI-64 Works in IPv6

    The 64-bit Extended Unique Identifier (EUI-64) is a special address format that maps device hardware network addresses into IPv6 addresses. This method makes use of IPv6’s spacious 128-bit addresses to simplify the process of generating IPv6 addresses. 

    EUI-64 is a very simple and practical technique that has been used for decades to get devices on the Internet without the need for manual configuration or even the use of DHCP. However, it has recently fallen out of favor, and some widely used operating systems, such as Microsoft Windows, have stopped using it by default. 

    What’s the deal with EUI-64? Let’s find out.

    Summary of EUI-64 key concepts

    Here’s a brief summary of the most important concepts and areas of discussion in this article.

    What is EUI-64?EUI-64 is a special mapping technique that converts common network hardware addresses into interface identifiers that can be used to create IPv6 addresses.
    How was EUI-64 made possible?The large 128-bit address space in IPv6 enabled the mapping of smaller 48-bit hardware addresses into 64-bit identifiers, an option that was not possible with 32-bit IPv4 addresses.
    Why was EUI-64 developed?EUI-64 was created to allow for the easier configuration and administration of IPv6 addresses, allowing computers to get online without the need for manual address assignment or other interventions.
    How does EUI-64 mapping work?EUI-64 works by splitting a 48-bit hardware address into two 24-bit parts, inserting a special 16-bit code between them, and changing one bit, resulting in a 64-bit interface identifier.
    What are the advantages of EUI-64?EUI-64 enables seamless IPv6 address autoconfiguration, makes it easy to determine a hardware address from an IPv6 address and vice versa, and assists administrators with troubleshooting.
    What are the drawbacks and privacy concerns related to EUI-64?Linking hardware and IPv6 addresses means that changes to one address must force a change to the other. More importantly, it raises concerns about privacy since it becomes possible to link a hardware device to its online activity.

    Learn from the experts

    Address mapping: IPv6 address space flexibility pays off

    When IPv6 was developed, the decision to expand addresses from 32 bits all the way to 128 bits was a somewhat controversial one. At the time, some people thought this was overkill because 2128 is such an enormous number that it seemed wasteful to have to deal with such large addresses when, perhaps, 64 bits would have sufficed. However, one of the benefits of having so many bits in addresses is that it provides flexibility to allow us to make more meaningful addresses.

    IPv4 addresses traditionally have no relationship to their underlying hosts. This was necessary in part because most hardware devices have longer hardware addresses than the IPv4 address space: The most common hardware addresses are IEEE 802 MAC addresses, which are 48 bits in length, while IPv4 addresses, of course, are 32 bits long.

    With IPv6, we have 128 bits at our disposal; these are normally split into 64 bits to represent the network prefix (for global routing) and 64 bits for the local identifier. It is thus easy to use those 64 local bits to map the hardware address directly into an IPv6 address. This can then be combined with the 64-bit network portion of the address and used for various purposes, such as Stateless Address Auto-Configuration (SLAAC).

    Understanding EUI-64

    While it is possible to map many different hardware addresses to IPv6 addresses, as mentioned earlier, IEEE 802 MAC addresses are by far the most commonly used. These 48-bit addresses are used by Ethernet (IEEE 802.3), Wi-Fi (IEEE 802.11), and Bluetooth (IEEE 802.15), which are the most popular wired, wireless, and personal area networking technologies, respectively.

    The 48 bits of a MAC address are split into two blocks of 24 bits each. The first (leftmost) 24 bits are a block called the Organizationally Unique Identifier (OUI), which is a fancy name for a company ID corresponding to a hardware device manufacturer. The second 24 bits (rightmost) are then used to create unique addresses for each specific device made by the manufacturer. 

    Each company that creates hardware devices will normally assign them addresses that begin with its OUI and then have unique serial numbers in the lower 24 bits. This means you can tell which company made a hardware device by looking at its MAC address.

    IEEE, which defines MAC addresses, also defined a larger address format called the 64-bit extended unique identifier (EUI-64). This is like the 48-bit MAC format we all know and love, but with 16 extra bits added to the device-specific part of the address. The idea here was to provide 65,536 times more device addresses for large companies that make so many devices that 24 bits wasn’t enough (the limit there is about 16 million devices).

    The form of EUI-64 used in IPv6 is actually more properly called modified EUI-64. The “modification” is to change the 7th bit from the left from 0 to 1. This modification was specified in RFC 4291, IP Version 6 Addressing Architecture, and was intended to make the administration of certain types of hardware devices and connections easier.

    Note that despite the fact that IPv6 uses a “modified” EUI-64, it is rarely called that in practice; everyone just uses the term “EUI-64” by itself.

    How EUI-64 address mapping works

    Even though the IEEE defined extended 64-bit hardware addresses—the “unmodified” EUI-64—most devices continue to use 48-bit addresses. Accordingly, it’s necessary to define a mapping from 48-bit MAC addresses to (modified) EUI-64. Of course, as part of this, it’s necessary to determine what to do with the extra 16 bits that are in the EUI-64 address but not the 48-bit MAC address.

    This mapping is done by following a simple three-step process:

    1. Split the 48-bit MAC address: Put the 24-bit OUI (the left half of the MAC address) into the leftmost 24 bits of the EUI-64 address and the 24-bit local identifier (the right half of the MAC address) into the rightmost 24 bits of the EUI-64 address.
    2. Fill the middle 16 bits: Insert the value “11111111 11111110” (“FFFE” in hexadecimal) into the middle 16 bits of the EUI-64 address that weren’t filled in using bits from the MAC address.
    3. Modify the EUI-64 address: Change bit 7 from the left from 0 to 1 to give the modified EUI-64 address.

    This is easier to see with an example, so let’s convert the IEEE 802 MAC address 39-A7-94-07-CB-D0, as illustrated in the figure below (example and figure from The TCP/IP Guide and used with permission). Here are the three steps:

    1. Split the 48-bit MAC address: We take the first 24 bits of the identifier (“39-A7-94”) and put it into the first (leftmost) 24 bits of the address. The local portion of “07-CB-D0” becomes the last 24 bits of the identifier.
    2. Fill the middle 16 bits: We insert “11111111 11111110” (“FFFE” in hex) into the 16 bits between the two 24-bit values we just filled in.
    3. Modify the EUI-64 address: We change bit 7 from 0 to 1. This changes the first octet of the address from 00111001 (39 in hex) to 00111011 (3B in hex).

    The (modified) EUI-64 identifier thus becomes 3B-A7-94-FF-FE-07-CB-D0, or 3BA7:94FF:FE07:CBD0 in IPv6 colon hexadecimal notation. This becomes the rightmost 64 bits of the device’s IPv6 address, with the leftmost 64 bits the network identifier.

    How EUI-64 maps an IEEE 802 MAC address into an IPv6 interface identifier

    How EUI-64 Is Used in IPv6

    Now that we have seen how EUI-64 mapping works, let’s pause for a bit of a recap and see how the various pieces fit together in IPv6:

    • The leftmost 64 bits of the address come from the network prefix, which defines the network portion of the address.
    • The MAC address comes from the hardware device.
    • EUI-64 is used to map the MAC address into a 64-bit EUI-64 interface identifier.
    • The network prefix and interface identifier are concatenated to make the final (global unicast) IPv6 address.
    • This address can then be used by a device to access both local networks and the global Internet.

    The interface identifier created via the EUI-64 process serves as the device-unique portion of the address. It is used to differentiate individual devices or interfaces within the same network or subnet.

    Real-world example of EUI-64 configuration

    Let’s take a look at how EUI-64 actually operates on a real device.  We’ll examine two particular cases that we often see on Cisco IOS devices.  

    Generating a link-local IPv6 address

    The first scenario involves generating a link-local IPv6 address on the interface of a Cisco router. Remember that the link-local IPv6 address is an IPv6 address that is automatically generated and assigned to an active IPv6 interface. Link-local addresses, as the name suggests, have only local significance, so they are never routed. Link-local addresses are of the form FE80::/10.

    On a Cisco IOS device, as soon as you enable the IPv6 capability on an interface, the device will automatically generate a link-local address using the EUI-64 process by default. Take a look at this series of commands and their results.

    R1#show ipv6 interface  brief
    
    GigabitEthernet0/0     [administratively down/down]
    
        unassigned
    
    GigabitEthernet0/1     [administratively down/down]
    
        unassigned
    
    R1#

    Initially, you can see that all IPv6 capabilities and both router interfaces are disabled.  Let’s take a look at the MAC address of GigabitEthernet0/0:

    R1#show interfaces gigabitEthernet 0/1
    
    GigabitEthernet0/1 is administratively down, line protocol is down 
    
    Hardware is iGbE, address is 5254.001c.e726 (bia 5254.001c.e726)
    
      MTU 1500 bytes, BW 1000000 Kbit/sec, DLY 10 usec, 
    
         reliability 255/255, txload 1/255, rxload 1/255
    
      Encapsulation ARPA, loopback not set
    
      Keepalive set (10 sec)
    
    !<-- output omitted -->

    The MAC address is 52:54:00:1C:E7:26. Now, let’s enable IPv6 on the GigabitEthernet0/0 interface and bring up the interface without assigning any IPv6 address:

    R1#configure terminal
    
    Enter configuration commands, one per line.  End with CNTL/Z.
    
    R1(config)#interface gigabitEthernet 0/0
    
    R1(config-if)#ipv6 enable 
    
    R1(config-if)#no shutdown
    
    R1(config-if)#
    
    *Mar 21 11:00:41.592: %LINK-3-UPDOWN: Interface GigabitEthernet0/0, changed state to up
    
    *Mar 21 11:00:42.592: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet0/0, changed state to up
    
    R1(config-if)#exit
    
    R1(config)#exit
    
    R1#

    The interface is now IPv6 enabled and active. Let’s see what link-local address has been assigned:

    R1#show ipv6 interface gigabitEthernet 0/0
    
    GigabitEthernet0/0 is up, line protocol is up
    
      IPv6 is enabled, link-local address is FE80::5054:FF:FE1C:E726 
    
      No Virtual link-local address(es):
    
      !<-- output omitted -->
    
    R1#

    The link-local address is FE80::5054:FF:FE1C:E726. If you do the math, you’ll see that this is the result of applying EUI-64 to a link-local prefix of FE80::/10 with the MAC address of the GigabitEthernet0/0 interface.

    If you don’t want to use the EUI-64 method, you can always statically assign a link-local IPv6 address using the following syntax:

    R1#configure terminal
    
    R1(config)#inter gig 0/0
    
    R1(config-if)#ipv6 address FE80::1 link-local 
    
    R1(config-if)#exit
    
    R1(config)#exit
    
    R1#

    Generating a Global Unicast IPv6 address

    Now let’s create a global unicast IPv6 address on this interface using the EUI-64 process. Unlike the link-local IPv6 address, the global unicast address is a routable address and is assigned based on the defined IPv6 prefix for that particular interface.

    For our configuration, we’ll be assigning the prefix 2001:ABCD:1234:5678::/64 to the interface, and we’ll be instructing it to use the EUI-64 method to assign the specific IPv6 address for that interface.  This is achieved using the following commands:

    R1#configure terminal 
    
    Enter configuration commands, one per line.  End with CNTL/Z.
    
    R1(config)#interface gigabitEthernet 0/0
    
    R1(config-if)#ipv6 address 2001:ABCD:1234:5678::/64 eui-64 
    
    R1(config-if)#exit
    
    R1(config)#exit

    The eui-64 keyword tells the device to use this method to determine the IPv6 address. Let’s see what the resulting IPv6 global unicast address has become:

    R1#show ipv6 interface brief gigabitEthernet 0/0
    
    GigabitEthernet0/0     [up/up]
    
        FE80::1
    
        2001:ABCD:1234:5678:5054:FF:FE1C:E726
    
    R1#

    Note that the link-local address that we previously manually assigned appears in the output of the IPv6 information of this interface.

    The resulting IPv6 global unicast address has become:

    2001:ABCD:1234:5678:5054:FF:FE1C:E726

    Once again, if you do the math, you can see that if you apply the EUI-64 process to the 2001:ABCD:1234:5678::/64 prefix along with the MAC address of the particular interface, the result is the IPv6 address shown above.

    Advantages and disadvantages of EUI-64

    The benefits of EUI-64 generally relate to practical considerations: simplicity and administrative efficiency. More specifically, having device hardware addresses and IPv6 addresses directly linked provides value in the following areas:

    • Support for autoconfiguration: It is easy to generate an appropriate globally routable local address from any hardware device using its hardware address and a process such as SLAAC.
    • Address harmonization: Administrators no longer must keep track of two separate, unrelated addresses for each device.
    • Troubleshooting: When troubleshooting devices, administrators must often switch back and forth between working with IP addresses and hardware addresses. Using EUI-64 makes this simpler because seeing the IP address of a device indicates immediately what the MAC address is and vice versa.

    One disadvantage of EUI-64 is that tying the hardware address to the IP address means that if the hardware address changes, the IP address needs to change as well. In practice, this is a relatively minor consideration most of the time because hardware doesn’t change that often—this is something that typically occurs in the scope of years, not hours or days.

    The bigger concerns with EUI-64 are those old bugbears that administrators know too well: privacy and security. 

    EUI-64 privacy and security issues

    To understand the issue here, it’s necessary to first have a small digression into network design philosophy. One of the fundamentals of network design is the use of layers, which allow different technologies to interoperate while hiding unnecessary details that would cause complications in the implementation of each technology. One important facet of this is that “detail hiding” using layers also enhances security and privacy.

    Linking hardware device addresses to IP addresses offers practical benefits, as explained above. However, it violates one of the tenets of layer design, which is that an address in one layer (the hardware address) should not be tied to the addresses at another (the IP address). This represents a form of information sharing that can be problematic in our modern world of hackers and trackers.

    More specifically, being able to tell the hardware address of a device from its IP address is a convenience for administrators, but this same information is available to everyone else as well. IP addresses are used on the global Internet, which means that if you are using EUI-64, every request to every online resource or service is telling that resource or service what your hardware device address is. 

    Now consider how many of the devices we use these days are mobile. If the IP address is always generated based on the hardware device, and the hardware device address doesn’t change, it becomes possible to keep track of the device as it moves from one network to another, representing a clear privacy concern. Specific scenarios have been identified by security analysts that would allow a mobile device to be tied back to a home network and tracked as it moves around.

    In addition to this issue, there’s further information revealed by the hardware address that gets put out over the Internet when EUI-64 is used. As discussed earlier, the first 24 bits of the hardware address are the organizationally unique identifier, or OUI. The OUIs of all device manufacturers are recorded in a public database, which means that using EUI-64 tells everyone on the Internet which company’s hardware you are using. While this may not be an issue most of the time, there are situations where it could be very problematic to advertise what hardware you are using. For example, if there’s a known exploit for a particular hardware manufacturer or model, this could make you a target for attacks.

    Current status of EUI-64

    Unfortunately, EUI-64 is another technology that falls into the ever-expanding category of “good ideas ruined by bad actors.” It has a number of benefits that we explained above, but as originally defined, it introduces risks and concerns significant enough to outweigh the benefits in many cases.

    The security risks that EUI-64 introduces stem from the fact that the unique MAC address of a device can be easily derived from the IPv6 address assigned to it.  Malicious users can use this fact to perform many of the following attacks:

    • Device tracking: Because the MAC address is unique to each device, incorporating it into the IPv6 address makes it easier to track specific devices as they move between networks, especially mobile devices such as laptops, smartphones or tablets.
    • Privacy leakage: The use of a consistent, unique identifier in the IPv6 address can reveal information about a user’s device, such as make, model, and even approximate date of manufacture, which can potentially expose the user to targeted attacks.
    • Predictable addresses: Because EUI-64 generated addresses are predictable, the use of this technique can simplify the scanning and targeting of specific devices on a network by an attacker.

    Because of these potential security risks, the use of EUI-64 has become less popular in recent years in favor of different approaches and alternate methods. Leading hardware manufacturer Cisco still uses it by default for link-local addresses, as does MacOS. However, many other hardware and software companies have changed tactics to one or more of the approaches outlined below.

    One alternative approach is simply to stop using EUI-64 and just use a random number for the 64-bit device-specific portion of the IPv6 address. This sort of “brute-force” solution solves the privacy/security issues with EUI-64, but, of course, comes at the cost of no longer having any of its advantages. This is the method that Microsoft Windows uses; due to the prevalence of that operating system family, this means that a large percentage of devices online no longer use EUI-64.

    The Internet Engineering Task Force (IETF), which defines the “RFC” standards that govern the Internet Protocol and other Internet technologies, actually recognized the potential concerns with EUI-64 many years ago. RFC 4941, Privacy Extensions for Stateless Address Autoconfiguration in IPv6, is a standard defining a method for avoiding the privacy concerns when using SLAAC in IPv6. In simple terms, it also uses random identifiers that change periodically to avoid the potential concerns of having a static IPv6 address tied to a specific hardware device.

    Conclusion

    In this article, we looked at the 64-bit Extended Unique Identifier (EUI-64), a special format that converts common device hardware addresses—such as those used in Ethernet and Wi-Fi—into IPv6 addresses. This simple method has been used for years to make IP address generation simple and enhance the maintainability of networks. We looked at how EUI-64 mapping works, both in theory and using a real-world example.

    Unfortunately, bad actors have found ways to create privacy and security problems when hardware and IPv6 addresses are closely matched. As a result, many systems have moved away from using EUI-64 over the last few years, though it can still be useful in some implementations and is still important for any network administrator to understand.

    Spot risky EUI-64 devices before they leak identity

    LogicMonitor helps you automatically surface IPv6 interfaces using EUI-64 so you can flag privacy‑sensitive hosts, verify address policies, and fix misconfigurations before they expose users or data.

    Get a demo

    FAQs

    What is EUI-64 and how does it relate to IPv6?

    EUI-64 (64-bit Extended Unique Identifier) is an address-mapping technique that converts a device’s 48-bit MAC address into a 64-bit interface identifier used in IPv6 addresses. It does this by splitting the MAC address in two, inserting “FFFE” in the middle, and flipping the seventh bit—allowing devices to generate globally unique IPv6 addresses automatically, without DHCP or manual configuration.

    How does EUI-64 address mapping work step by step?

    EUI-64 mapping follows three steps: (1) the 48-bit MAC address is split into two 24-bit halves, with the OUI placed in the leftmost 24 bits of the EUI-64 field and the device-specific half in the rightmost 24 bits; (2) the 16-bit value “FFFE” is inserted into the empty middle; and (3) bit 7 from the left is flipped from 0 to 1, yielding the “modified EUI-64” interface identifier used in IPv6 addressing.

    Why are privacy concerns pushing vendors away from EUI-64?

    Because EUI-64 embeds the device MAC address directly in the IPv6 address, any online service receiving traffic from that device can identify the hardware vendor (via the OUI) and track the device across networks. This makes mobile devices especially vulnerable to persistent tracking. RFC 4941 defines privacy extensions using randomly generated, periodically changing identifiers as a countermeasure—an approach now used by Windows and many other operating systems by default.

    Is EUI-64 still used in modern networks?

    Yes, though its role has diminished. Cisco IOS still uses EUI-64 by default to generate link-local IPv6 addresses on router interfaces, and macOS also retains it in certain scenarios. However, Microsoft Windows generates random interface identifiers by default, and RFC 4941 privacy extensions are widely adopted across mobile and general-purpose platforms. EUI-64 remains relevant for network infrastructure environments where device tracking is not a concern and address predictability is beneficial.

    By Denton Chikura

    Technical Writer

    Denton Chikura is a technical writer and longtime observability advocate focused on helping site reliability engineers and engineering teams discover the tools and capabilities that strengthen internet resilience. He works at the intersection of monitoring, performance, and infrastructure to make complex systems more understandable and usable, bridging the gap between deep technical detail and real‑world operations. His goal is to help teams build faster, detect issues earlier, and recover smarter, ultimately making the internet a better, more reliable place for everyone.

    Disclaimer: The views expressed on this blog are those of the author and do not necessarily reflect the views of LogicMonitor or its affiliates.

    © LogicMonitor 2026 | All rights reserved. | All trademarks, trade names, service marks, and logos referenced herein belong to their respective companies.

    Product

    Platform

    Infrastructure

    Cloud & Multi-Cloud

    Log Management

    Edwin AI

    Enterprise

    Demo

    Pricing

    WebPageTest Pricing

    RUM Monitoring

    IPM Monitoring

    Synthetic Monitoring

    How We Compare

    Datadog

    Dynatrace

    Virtana

    Solarwinds

    PRTG

    ManageEngine

    ScienceLogic

    SiteScope

    BigPanda

    About

    Careers

    Our Partners

    Leadership

    Newsroom

    Security

    AI Governance

    Sustainability

    Legal

    Documentation

    Docs Hub

    Release Notes

    Security

    Support Center

    Resources

    Autonomous IT in 2026

    Resource Library

    LM Academy

    Blog

    Case Studies

    Customer Education

    Connect

    Contact & Locations

    Submit a Ticket

    Events

    LM Community

    Careers


    Product

    Platform

    Infrastructure

    Cloud & Multi-Cloud

    Log Management

    Edwin AI

    Enterprise

    Demo

    Pricing

    WebPageTest Pricing

    RUM Monitoring

    IPM Monitoring

    Synthetic Monitoring


    How We Compare

    Datadog

    Dynatrace

    Virtana

    Zenoss

    Solarwinds

    PRTG

    ManageEngine

    ScienceLogic

    SiteScope

    BigPanda


    About

    Careers

    Our Partners

    Leadership

    Newsroom

    Security

    AI Governance

    Sustainability

    Legal


    Documentation

    Docs Hub

    Release Notes

    Security

    Support Center


    Resources

    Autonomous IT in 2026

    Resource Library

    LM Academy

    Blog

    Case Studies

    Customer Education


    Connect

    Contact & Locations

    Submit a Ticket

    Events

    LM Community

    Careers


    Privacy Policy

    Terms of Use

    Preference Center

    Do Not Sell My Information

    © 2026 LogicMonitor