Why you'd do this¶
Usually a stopgap on a box where IPv6 is misconfigured or causing DNS/routing weirdness you don't want to properly fix yet — not a recommended permanent state on anything internet-facing today. Prefer fixing IPv6 configuration over disabling it where practical.
Disable via sysctl (runtime + persistent)¶
sudo tee /etc/sysctl.d/10-disable-ipv6.conf << 'EOF'
net.ipv6.conf.all.disable_ipv6 = 1
net.ipv6.conf.default.disable_ipv6 = 1
net.ipv6.conf.lo.disable_ipv6 = 1
EOF
sudo sysctl --system
This disables IPv6 on all current and future interfaces, including loopback. It survives reboot because it's read from /etc/sysctl.d/ at boot.
Disable at the kernel command line (belt and suspenders)¶
Some services/modules check for IPv6 availability at load time before sysctl has a chance to apply — disabling it in the boot parameters closes that gap:
# Debian/Ubuntu: /etc/default/grub
# append to GRUB_CMDLINE_LINUX_DEFAULT:
ipv6.disable=1
sudo update-grub # Debian/Ubuntu
# or
sudo grub2-mkconfig -o /boot/grub2/grub.cfg # RHEL/CentOS
sudo reboot
Verify¶
cat /proc/cmdline | grep ipv6 # confirm the kernel param took
ip a s # no inet6 addresses should appear
sysctl net.ipv6.conf.all.disable_ipv6 # should read 1
Re-enabling¶
Remove both the sysctl file and the ipv6.disable=1 kernel parameter, regenerate the grub config, and reboot. A partial revert (sysctl only, kernel param left in place) will leave IPv6 disabled regardless of the sysctl value.