My old post on setting up an IPv6 tunnel from SixXS on a WRT54G still gets a steady trickle of traffic, which is a problem, because SixXS shut down in 2017. If you have found that guide recently and tried to follow it, none of it works, and no amount of fiddling with the WRT54G will bring the service back. So here is the 2026 update: what killed the tunnel-broker era, what I run in the lab now, and what you should run instead.
Why SixXS closed, and why tunnels did not fully die with it
SixXS switched off in June 2017. Their argument was reasonable: native IPv6 from ISPs had finally started arriving, and a free tunnel broker was meant to be a stopgap, not a permanent crutch that let ISPs off the hook for deploying the real thing. They were half right. Native IPv6 did arrive for a lot of people. It also very much did not arrive for others.
Here in the UK the picture is still uneven. If you are on a BT Openreach-based line or on Sky, there is a decent chance you already have native IPv6 and do not need any of this. Virgin Media, on the other hand, kept a lot of customers on IPv4-only or awkward carrier-grade NAT arrangements for years, and plenty of business and mobile connections still hand you a single CGNAT address with no v6 in sight. So the need a tunnel used to fill has shrunk, but it has not gone.
The 2026 options, in the order I would try them
1. Native IPv6 from your ISP. Check this first, before you do anything else. Log into your router or run a test against a v6-only host. If your ISP hands you a routed /56 or even a /64, use it. Nothing beats native, there is no tunnel overhead, no single point of failure sitting on someone else's server, and no MTU headaches. If you have it, stop reading and go configure your firewall (see below).
2. Hurricane Electric Tunnelbroker. This is the de facto SixXS replacement, and the good news is it is still running, still free, and still handing out routed /64s (and a /48 if you ask). It uses 6in4, which is protocol 41 encapsulation of IPv6 inside IPv4. You register at tunnelbroker.net, they give you a server IPv4, a client IPv4, and your routed prefix, and you plug those into your edge box. DD-WRT and OpenWrt both do 6in4 natively now, so unlike 2007 you are not compiling anything by hand. The shape of the config is a 6in4 interface pointing at HE's server address, your allocated /64 routed onto the LAN, and the MTU pinned to 1480 with MSS clamping so TCP does not shatter on the tunnel.
3. WireGuard to a cheap VPS. Here is the catch with option 2: 6in4 needs a public IPv4 endpoint, and protocol 41 gets dropped by a lot of CGNAT and DS-Lite setups. If your ISP has already taken your public IPv4 away, HE's tunnel will not establish. This is where I have ended up for the CGNAT connections in the lab. Spin up the cheapest VPS you can find that has native IPv6, run WireGuard between it and your edge router, and route a /64 out of the VPS's allocation over the tunnel. It survives CGNAT because WireGuard is just UDP, it is encrypted end to end, and it does not care that your ISP mangled your address. It costs a few pounds a month, which is the price of your ISP not doing its job.
4. 6rd, if your ISP happens to offer it. Rare in practice, but if it is on the table it is less faff than a tunnel broker because your ISP runs the relay.
The part everyone forgets: your v6 firewall
This is the bit that actually matters and the bit the old tunnel guides all buried at the bottom, so I am putting it near the top of what you should care about. With IPv4 behind NAT, you had an accidental firewall. Nothing from the internet could reach your internal boxes because they had no routable address. That complacency does not survive the move to IPv6. Every device on your LAN now has a globally routable address, and by default that means every device is reachable from the entire internet.
So whatever tunnel or native setup you land on, you must run a stateful IPv6 firewall on the edge with a default-deny inbound policy. On DD-WRT and OpenWrt this is ip6tables or the newer nftables equivalent, and the rule you want is the boring one: allow established and related, allow whatever you deliberately expose, drop everything else inbound. Permit ICMPv6, because unlike ICMP on v4 you genuinely need it for path MTU discovery and neighbour discovery, and a lot of people break their v6 by nuking it wholesale. Test it from outside afterwards. I run a v6-only host on a separate line specifically so I can probe the lab from a real external address rather than trusting that the rules do what I think.
What I would do today
Native if your ISP gives it to you. Hurricane Electric if it does not and you still have a public IPv4. WireGuard to a small VPS if you are stuck behind CGNAT. And a default-deny ip6tables ruleset on top of all three, because unlike your old v4 setup, nothing else is going to protect those addresses for you.
The SixXS era is genuinely over, and the honest summary is that the replacements are better than what we had in 2007. The WRT54G is not part of any of this any more; it does not have the flash or the memory for a modern v6 stack plus WireGuard, and it has earned its retirement. Everything above runs happily on any current OpenWrt-capable box, which by now is most of them.