{"id":356191,"date":"2026-07-09T06:05:54","date_gmt":"2026-07-09T06:05:54","guid":{"rendered":"https:\/\/peraltafinancing.com\/analytics\/add-ipv6-support-to-your-server-side-gtm-load-balancer\/"},"modified":"2026-07-09T06:05:54","modified_gmt":"2026-07-09T06:05:54","slug":"add-ipv6-support-to-your-server-side-gtm-load-balancer","status":"publish","type":"post","link":"https:\/\/fivemor.com\/?p=356191","title":{"rendered":"Add IPv6 Support To Your Server-side GTM Load Balancer"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<blockquote>\n<p><strong>UPDATED 20 March 2026<\/strong>: Shortly after publishing this article, Google Cloud changed how Load Balancer frontend certificate management works. Instead of directly mapping a frontend to a certificate, GCP now wants you to use a <strong>certificate map<\/strong>. Luckily, creating one is (fairly) simple, and I\u2019ve updated the guide below to instruct how to do this.<\/p>\n<\/blockquote>\n<p>If you\u2019re running <a href=\"https:\/\/developers.google.com\/tag-platform\/tag-manager\/server-side\">server-side Google Tag Manager<\/a> on <strong>Google Cloud Run<\/strong> behind an <a href=\"http:\/\/www.simoahava.com\/analytics\/cloud-run-server-side-tagging-google-tag-manager\/\"><strong>External Application Load Balancer<\/strong><\/a>, your tagging endpoint is currently reachable only over IPv4 with a default installation.<\/p>\n<p>For most of your visitors, that\u2019s fine. But for users on <strong>IPv6 networks<\/strong>, it creates a silent data quality problem that directly affects how well vendor tags like <strong>Meta\u2019s Conversions API (CAPI)<\/strong> can match server-side events to their client-side counterparts.<\/p>\n<div style=\"aspect-ratio:1340\/331\" class=\"figure nocaption\"><a href=\"http:\/\/www.simoahava.com\/images\/2026\/03\/meta-capi-ip6.jpg\" title=\"Meta CAPI IPv6\"><img decoding=\"async\" class=\"fig-img\" height=\"331\" width=\"1340\" loading=\"lazy\" src=\"\/images\/2026\/03\/meta-capi-ip6.jpg#ZgotmplZ\" alt=\"Meta CAPI IPv6\"\/><\/a><\/div>\n<p>When a user on an IPv6 network fires the <strong>Meta pixel<\/strong> on your site, Meta records the event alongside the user\u2019s IPv6 address. Your server-side CAPI tag is then supposed to send the server-side version of that <strong>same event<\/strong>, including the <a href=\"https:\/\/developers.facebook.com\/docs\/marketing-api\/conversions-api\/parameters\/customer-information-parameters#client_ip_address\"><code>client_ip_address<\/code> field<\/a>, so that Meta can deduplicate the two and improve match quality.<\/p>\n<p>The problem: if your SGTM load balancer only has an IPv4 frontend, that IPv6 user\u2019s request goes through <strong>NAT64<\/strong> address translation before it ever reaches sGTM. The IP address SGTM reads from the incoming request is a <strong>translated IPv4 address<\/strong>. Your CAPI tag dutifully forwards it to Meta, which then compares it against the IPv6 address the pixel recorded. They don\u2019t match. The deduplication is degraded and the match score drops.<\/p>\n<p>The fix is to give your load balancer a <strong>dual-stack frontend<\/strong>: one IPv4 address (already in place) and one IPv6 address. When an IPv6 user connects, they reach SGTM natively over IPv6. No translation, no mismatch. The CAPI tag reads the real IPv6 address and sends it to Meta. Events match correctly.<\/p>\n<p>In practice, this is <strong>very easy to do<\/strong>. You need to reserve a <strong>static external IPv6 address<\/strong> in Google Cloud, attach it as a second frontend on your existing load balancer, and add an <code>AAAA<\/code> record to your DNS. Cloud Run itself needs no changes: <strong>IPv6 termination<\/strong> happens at the load balancer, and the LB continues to forward traffic to Cloud Run over IPv4 internally. You\u2019ll need a <strong>certificate map<\/strong> to configure the frontend, but luckily that isn\u2019t too difficult to do.<\/p>\n<p>Read on to learn how to do this!<\/p>\n<p><span class=\"simmer\"><span class=\"close\">X<\/span><\/p>\n<p><span class=\"fa fa-md fa-bell\"\/><br \/>\n<strong>The Simmer Newsletter<\/strong><\/p>\n<p>Subscribe to the <a href=\"http:\/\/www.simoahava.com\/newsletter\/\">Simmer newsletter<\/a> to get the latest news and content from Simo Ahava into your email inbox!<\/p>\n<p><\/span><\/p>\n<h2 id=\"how-ip-address-matching-breaks-without-ipv6\">How IP address matching breaks without IPv6<\/h2>\n<p>It\u2019s worth being precise about the mechanism, because the failure is silent and won\u2019t show up as an error anywhere in your setup.<\/p>\n<p>When SGTM receives a request, it reads the <strong>client IP address<\/strong> from the incoming connection. The load balancer forwards this via the <code>X-Forwarded-For<\/code> header. The official Meta CAPI tag template (and most other vendor templates) reads this header and uses the value as the <code>client_ip_address<\/code> parameter in the outgoing server-to-server request to Meta\u2019s API.<\/p>\n<div style=\"aspect-ratio:1790\/406\" class=\"figure nocaption\"><a href=\"http:\/\/www.simoahava.com\/images\/2026\/03\/x-forwarded-for.jpg\" title=\"X-Forwarded-For\"><img decoding=\"async\" class=\"fig-img\" height=\"406\" width=\"1790\" loading=\"lazy\" src=\"\/images\/2026\/03\/x-forwarded-for.jpg#ZgotmplZ\" alt=\"X-Forwarded-For\"\/><\/a><\/div>\n<p>On Meta\u2019s side, incoming pixel events and CAPI events are compared using a set of <a href=\"https:\/\/developers.facebook.com\/docs\/marketing-api\/conversions-api\/parameters\/customer-information-parameters\/\">customer information parameters<\/a>: IP address, user agent, email hash, and so on. IP address is one of the stronger signals. When both events carry the same IP, Meta can confidently deduplicate them and attribute the conversion to the correct user journey.<\/p>\n<p>Here is what happens step by step when an IPv6 user hits an <strong>IPv4-only<\/strong> SGTM endpoint:<\/p>\n<ol>\n<li>The user\u2019s device is on <code>2001:db8::1<\/code> (an IPv6 address).<\/li>\n<li>The <strong>client-side<\/strong> Meta pixel fires. Meta logs the event with <code>client_ip_address: 2001:db8::1<\/code>.<\/li>\n<li>The browser sends a request to your SGTM endpoint to trigger the CAPI event.<\/li>\n<li>Your SGTM endpoint has no IPv6 frontend. The user\u2019s device connects via NAT64, which translates the source address to something like <code>192.0.2.1<\/code>.<\/li>\n<li>SGTM reads <code>192.0.2.1<\/code> from the <code>X-Forwarded-For<\/code> header.<\/li>\n<li>The CAPI tag sends <code>client_ip_address: 192.0.2.1<\/code> to Meta.<\/li>\n<li>Meta compares <code>192.0.2.1<\/code> against <code>2001:db8::1<\/code>. No match. Deduplication is incomplete.<\/li>\n<\/ol>\n<p>With a dual-stack load balancer, <strong>step (4)<\/strong> changes: the user connects natively over IPv6, the address reaches SGTM untranslated, and the CAPI tag sends the correct value. Meta matches the events cleanly.<\/p>\n<p>Meta is the most visible example here, but the same logic applies to any vendor tag that uses the client IP as a matching or enrichment signal.<\/p>\n<h2 id=\"prerequisites\">Prerequisites<\/h2>\n<p>This guide assumes you already have:<\/p>\n<ul>\n<li><a href=\"http:\/\/www.simoahava.com\/analytics\/cloud-run-server-side-tagging-google-tag-manager\/\">A working SGTM deployment on <strong>Cloud Run<\/strong><\/a> (or Cloud Run-compatible infrastructure)<\/li>\n<li>A <strong>Global External Application Load Balancer<\/strong> fronting that deployment, with an HTTPS frontend and a valid SSL certificate<\/li>\n<li>Access to your <strong>DNS provider<\/strong> to add records<\/li>\n<li>The <strong>Owner<\/strong> or <strong>Network Admin<\/strong> role in your Google Cloud project<\/li>\n<\/ul>\n<blockquote>\n<p>If you\u2019re still setting up your SGTM infrastructure, <a href=\"https:\/\/developers.google.com\/tag-platform\/tag-manager\/server-side\/cloud-run-setup-guide\">this guide<\/a> covers the baseline Cloud Run deployment. The load balancer configuration described here assumes the standard setup that follows from that guide. I also cover the Cloud Run setup extensively in Simmer\u2019s <a href=\"https:\/\/www.teamsimmer.com\/all-courses\/server-side-tagging-google-tag-manager\">Server-side Tagging In Google Tag Manager<\/a> online course.<\/p>\n<\/blockquote>\n<h2 id=\"step-1-reserve-a-static-external-ipv6-address\">Step 1: Reserve a static external IPv6 address<\/h2>\n<p>In the <strong>Google Cloud Console<\/strong>, navigate to <strong>VPC Network<\/strong> &gt; <strong>IP addresses<\/strong> and click <strong>Reserve External<\/strong>.<\/p>\n<div style=\"aspect-ratio:2118\/598\" class=\"figure nocaption\"><a href=\"http:\/\/www.simoahava.com\/images\/2026\/03\/reserve-external-ip.jpg\" title=\"Reserve external IP\"><img decoding=\"async\" class=\"fig-img\" height=\"598\" width=\"2118\" loading=\"lazy\" src=\"\/images\/2026\/03\/reserve-external-ip.jpg#ZgotmplZ\" alt=\"Reserve external IP\"\/><\/a><\/div>\n<p>Configure the new address as follows:<\/p>\n<ul>\n<li><strong>Name<\/strong>: something descriptive, e.g. <code>sgtm-ipv6<\/code><\/li>\n<li><strong>Network Service Tier<\/strong>: Premium (required for global load balancers)<\/li>\n<li><strong>IP version<\/strong>: IPv6<\/li>\n<li><strong>Type<\/strong>: Global<\/li>\n<\/ul>\n<div style=\"aspect-ratio:1620\/1422\" class=\"figure nocaption\"><a href=\"http:\/\/www.simoahava.com\/images\/2026\/03\/reserve-ip6.jpg\" title=\"Reserve IPv6 in Google Cloud\"><img decoding=\"async\" class=\"fig-img\" height=\"1422\" width=\"1620\" loading=\"lazy\" src=\"\/images\/2026\/03\/reserve-ip6.jpg#ZgotmplZ\" alt=\"Reserve IPv6 in Google Cloud\"\/><\/a><\/div>\n<p>Click <strong>Reserve<\/strong>. Google will allocate <a href=\"https:\/\/en.wikipedia.org\/wiki\/IPv6_address#Transition_from_IPv4\">a <code>\/96<\/code> IPv6 prefix<\/a> and surface the first usable address. You\u2019ll see it listed in the IP addresses table. It will look something like <code>2600:1901:0:xxxx::<\/code>.<\/p>\n<p>Copy that address. You\u2019ll need it for both the DNS record and the load balancer frontend configuration.<\/p>\n<h2 id=\"step-2-add-an-aaaa-record-to-your-dns\">Step 2: Add an AAAA record to your DNS<\/h2>\n<p>Before wiring up the load balancer, add the DNS record so that propagation can start in the background while you finish the configuration.<\/p>\n<p>In your DNS provider, add a new record for your sGTM subdomain (e.g. <code>sst.yourdomain.com<\/code>):<\/p>\n<ul>\n<li><strong>Type<\/strong>: <code>AAAA<\/code><\/li>\n<li><strong>Name<\/strong>: <code>sst<\/code> (or whatever subdomain you\u2019re using)<\/li>\n<li><strong>Value<\/strong>: the IPv6 address you reserved in Step 1<\/li>\n<li><strong>TTL<\/strong>: your standard TTL (300 seconds is fine)<\/li>\n<\/ul>\n<p>The screenshot below is what my dual-stack configuration looks like in my DNS settings.<\/p>\n<div style=\"aspect-ratio:2460\/458\" class=\"figure nocaption\"><a href=\"http:\/\/www.simoahava.com\/images\/2026\/03\/dns-records.jpg\" title=\"DNS records\"><img decoding=\"async\" class=\"fig-img\" height=\"458\" width=\"2460\" loading=\"lazy\" src=\"\/images\/2026\/03\/dns-records.jpg#ZgotmplZ\" alt=\"DNS records\"\/><\/a><\/div>\n<blockquote>\n<p>Keep the existing <code>A<\/code> record in place. The goal is <strong>dual-stack<\/strong>. Both IPv4 and IPv6 clients should be able to reach your endpoint. Removing the <code>A<\/code> record would break IPv4-only clients.<\/p>\n<\/blockquote>\n<h2 id=\"step-3-create-a-certificate-map\">Step 3: Create a certificate map<\/h2>\n<p><strong>Note!<\/strong> You\u2019ll need the <code>gcloud<\/code> command-line tool to proceed, as certificate map creation is not yet available through the Google Cloud Platform console. <a href=\"https:\/\/docs.cloud.google.com\/sdk\/docs\/install-sdk\">Click here for installation instructions<\/a>, and <a href=\"https:\/\/docs.cloud.google.com\/sdk\/docs\/initializing\">click here for the initialization guide<\/a>. Make sure you\u2019ve set your project ID, so that the <code>gcloud<\/code> commands are executed in the correct context!<\/p>\n<p>Google Cloud has migrated to <strong>certificate maps<\/strong> in Load Balancer frontend configurations. While you can still link a single frontend directly to a certificate, as soon as you want to add multiple frontends, you need to use a certificate map. It\u2019s also possible that at some point in the near future, you\u2019ll need a certificate map for your single SSL frontend, too.<\/p>\n<div style=\"aspect-ratio:1648\/778\" class=\"figure nocaption\"><a href=\"http:\/\/www.simoahava.com\/images\/2026\/03\/certificate-map-lb-frontend.jpg\" title=\"Certificate Map\"><img decoding=\"async\" class=\"fig-img\" height=\"778\" width=\"1648\" loading=\"lazy\" src=\"\/images\/2026\/03\/certificate-map-lb-frontend.jpg#ZgotmplZ\" alt=\"Certificate Map\"\/><\/a><\/div>\n<p>Unfortunately, certificate maps won\u2019t work with the \u201cclassic\u201d Google-managed SSL certificate you\u2019re probably using in your load balancer. Instead, you need to go to Certificate Manager, and create a new certificate.<\/p>\n<p><a href=\"https:\/\/console.cloud.google.com\/security\/ccm\/certificates\/add\">Follow this link to jump straight to this process in your Google Cloud project<\/a>.<\/p>\n<p>Here, give the certificate name (e.g. <code>sgtm-ssl-cert<\/code>), choose <strong>Create Google-managed certificate as the type<\/strong>, add the domain name(s) you want the certificate to cover, and leave everything else as default and click <strong>Create<\/strong>.<\/p>\n<div style=\"aspect-ratio:1612\/2402\" class=\"figure nocaption\"><a href=\"http:\/\/www.simoahava.com\/images\/2026\/03\/create-new-certificate.jpg\" title=\"Create new certificate\"><img decoding=\"async\" class=\"fig-img\" height=\"2402\" width=\"1612\" loading=\"lazy\" src=\"\/images\/2026\/03\/create-new-certificate.jpg#ZgotmplZ\" alt=\"Create new certificate\"\/><\/a><\/div>\n<p>Once you\u2019ve created the certificate, you need to move to the command line (in your terminal application) and run the following commands.<\/p>\n<p>First, <strong>create the certificate map with this<\/strong>:<\/p>\n<div class=\"highlight\">\n<pre tabindex=\"0\" style=\"background-color:#fff;-moz-tab-size:4;-o-tab-size:4;tab-size:4\"><code class=\"language-bash\" data-lang=\"bash\"><span style=\"display:flex\"><span>gcloud certificate-manager maps create <map-name\/><\/span><\/span><\/code><\/pre>\n<\/div>\n<p>I chose <code>sgtm-cert-map<\/code> as the name, so the command and successful response look like this:<\/p>\n<div style=\"aspect-ratio:1308\/88\" class=\"figure nocaption\"><a href=\"http:\/\/www.simoahava.com\/images\/2026\/03\/map-created.jpg\" title=\"certificate map created\"><img decoding=\"async\" class=\"fig-img\" height=\"88\" width=\"1308\" loading=\"lazy\" src=\"\/images\/2026\/03\/map-created.jpg#ZgotmplZ\" alt=\"certificate map created\"\/><\/a><\/div>\n<p>Next, you need to create a certificate map entry that links your new certificate and its associated hostnames to the certificate map. Here\u2019s the command:<\/p>\n<div class=\"highlight\">\n<pre tabindex=\"0\" style=\"background-color:#fff;-moz-tab-size:4;-o-tab-size:4;tab-size:4\"><code class=\"language-bash\" data-lang=\"bash\"><span style=\"display:flex\"><span>gcloud certificate-manager maps entries create <entry-name> --map=<map-name> --hostname=<sgtm-hostname> --certificates=<certificate-name\/><\/sgtm-hostname><\/map-name><\/entry-name><\/span><\/span><\/code><\/pre>\n<\/div>\n<blockquote>\n<p>Replace <code>entry-name<\/code> with a custom name for the certificate entry. Replace <code>map-name<\/code> with the name of the map you just created. Replace <code><sgtm-hostname\/><\/code> with the hostname the certificate should cover. Replace <code>certificate-name<\/code> with the name of the SSL certificate you created in the beginning of this step.<\/p>\n<\/blockquote>\n<p>Since I only have a single hostname to map to, I only need a single entry. If you have multiple hostnames associated with the certificate(s), you\u2019d need to create one entry per hostname. Here\u2019s what my command output looked like:<\/p>\n<div style=\"aspect-ratio:2654\/84\" class=\"figure nocaption\"><a href=\"http:\/\/www.simoahava.com\/images\/2026\/03\/create-certificate-map-entry.jpg\" title=\"Create certificate map entry\"><img decoding=\"async\" class=\"fig-img\" height=\"84\" width=\"2654\" loading=\"lazy\" src=\"\/images\/2026\/03\/create-certificate-map-entry.jpg#ZgotmplZ\" alt=\"Create certificate map entry\"\/><\/a><\/div>\n<p>Once ready, you can head over to the GCP console\u2019s <a href=\"https:\/\/console.cloud.google.com\/security\/ccm\/list\/certificateMaps\">Certificate Maps page<\/a> to verify your map has been created.<\/p>\n<div style=\"aspect-ratio:2504\/300\" class=\"figure nocaption\"><a href=\"http:\/\/www.simoahava.com\/images\/2026\/03\/certificate-map-console.jpg\" title=\"Certificate map console\"><img decoding=\"async\" class=\"fig-img\" height=\"300\" width=\"2504\" loading=\"lazy\" src=\"\/images\/2026\/03\/certificate-map-console.jpg#ZgotmplZ\" alt=\"Certificate map console\"\/><\/a><\/div>\n<p>Now, you\u2019ll want to wait for your new SSL certificate and certificate map to signal green for completion before proceeding. This should only take a short while. Click the certificate map name in the console, and wait for the SSL certificate(s) under <strong>Associated certificates<\/strong> to have the green cherkmark which signals that it has been successfully provisioned.<\/p>\n<div style=\"aspect-ratio:1920\/324\" class=\"figure nocaption\"><a href=\"http:\/\/www.simoahava.com\/images\/2026\/03\/certificate-map-ready.jpg\" title=\"certificate map ready\"><img decoding=\"async\" class=\"fig-img\" height=\"324\" width=\"1920\" loading=\"lazy\" src=\"\/images\/2026\/03\/certificate-map-ready.jpg#ZgotmplZ\" alt=\"certificate map ready\"\/><\/a><\/div>\n<h2 id=\"step-4-add-an-ipv6-frontend-to-the-load-balancer\">Step 4: Add an IPv6 frontend to the load balancer<\/h2>\n<p>Next, navigate to <strong>Network Services<\/strong> &gt; <strong>Load balancing<\/strong> in the Cloud Console and click your existing load balancer.<\/p>\n<p>As you can see below, this load balancer has just a single HTTPS frontend, which only handles IPv4 traffic.<\/p>\n<div style=\"aspect-ratio:2542\/516\" class=\"figure nocaption\"><a href=\"http:\/\/www.simoahava.com\/images\/2026\/03\/load-balancer-details.jpg\" title=\"Load balancer details\"><img decoding=\"async\" class=\"fig-img\" height=\"516\" width=\"2542\" loading=\"lazy\" src=\"\/images\/2026\/03\/load-balancer-details.jpg#ZgotmplZ\" alt=\"Load balancer details\"\/><\/a><\/div>\n<p>Click <strong>Edit<\/strong>, then go to the <strong>Frontend configuration<\/strong> section and click <strong>Add Frontend IP and port<\/strong>.<\/p>\n<div style=\"aspect-ratio:1450\/378\" class=\"figure nocaption\"><a href=\"http:\/\/www.simoahava.com\/images\/2026\/03\/add-frontend-ip.jpg\" title=\"Add frontend IP\"><img decoding=\"async\" class=\"fig-img\" height=\"378\" width=\"1450\" loading=\"lazy\" src=\"\/images\/2026\/03\/add-frontend-ip.jpg#ZgotmplZ\" alt=\"Add frontend IP\"\/><\/a><\/div>\n<p>Configure the new frontend:<\/p>\n<ul>\n<li><strong>Name<\/strong>: e.g. <code>sgtm-https-ipv6<\/code><\/li>\n<li><strong>Protocol<\/strong>: HTTPS<\/li>\n<li><strong>Network Service Tier<\/strong>: Premium<\/li>\n<li><strong>IP version<\/strong>: IPv6<\/li>\n<li><strong>IP address<\/strong>: select the <code>sgtm-ipv6<\/code> address you reserved in Step 1<\/li>\n<li><strong>Port<\/strong>: 443<\/li>\n<li><strong>Select a certificate map<\/strong>: select the certificate map you created in the previous step<\/li>\n<\/ul>\n<div style=\"aspect-ratio:1492\/1534\" class=\"figure nocaption\"><a href=\"http:\/\/www.simoahava.com\/images\/2026\/03\/frontend-configuration.jpg\" title=\"Frontend confgiuration\"><img decoding=\"async\" class=\"fig-img\" height=\"1534\" width=\"1492\" loading=\"lazy\" src=\"\/images\/2026\/03\/frontend-configuration.jpg#ZgotmplZ\" alt=\"Frontend confgiuration\"\/><\/a><\/div>\n<p>While you\u2019re at it, you might also want to edit your existing IPv4 frontend to use the certificate map, too. To support a seamless migration, it won\u2019t let you jump directly to the certificate map. Instead, you need to choose the \u201cUse Certificate Map and Classic Certificates\u201d option, and then choose the map from the list. This ensures that the frontend uses the pre-existing classic certificate for as long as it takes for the certificate map to be ready.<\/p>\n<div style=\"aspect-ratio:1324\/666\" class=\"figure nocaption\"><a href=\"http:\/\/www.simoahava.com\/images\/2026\/03\/update-ip4-to-use-certificate-map.jpg\" title=\"Update IP4 to use certificate map\"><img decoding=\"async\" class=\"fig-img\" height=\"666\" width=\"1324\" loading=\"lazy\" src=\"\/images\/2026\/03\/update-ip4-to-use-certificate-map.jpg#ZgotmplZ\" alt=\"Update IP4 to use certificate map\"\/><\/a><\/div>\n<blockquote>\n<p>You do not need to create a new backend service or routing rule. The new IPv6 frontend shares the same backend and URL map as your IPv4 frontend. Traffic coming in over IPv6 is handled identically once it hits the load balancer.<\/p>\n<\/blockquote>\n<p>Click <strong>Done<\/strong>, then <strong>Update<\/strong> to save the load balancer configuration.<\/p>\n<h2 id=\"step-5-verify-the-setup\">Step 5: Verify the setup<\/h2>\n<p>Give DNS a few minutes to propagate, then verify both stacks are working.<\/p>\n<h3 id=\"check-dns-resolution\">Check DNS resolution<\/h3>\n<p>From a terminal, confirm that both record types resolve correctly:<\/p>\n<div class=\"highlight\">\n<pre tabindex=\"0\" style=\"background-color:#fff;-moz-tab-size:4;-o-tab-size:4;tab-size:4\"><code class=\"language-bash\" data-lang=\"bash\"><span style=\"display:flex\"><span><span style=\"color:#aaa;font-style:italic\"># Should return your IPv4 address<\/span>\n<\/span><\/span><span style=\"display:flex\"><span>dig A sst.yourdomain.com +short\n<\/span><\/span><span style=\"display:flex\"><span>\n<\/span><\/span><span style=\"display:flex\"><span><span style=\"color:#aaa;font-style:italic\"># Should return your IPv6 address<\/span>\n<\/span><\/span><span style=\"display:flex\"><span>dig AAAA sst.yourdomain.com +short<\/span><\/span><\/code><\/pre>\n<\/div>\n<div style=\"aspect-ratio:1394\/148\" class=\"figure nocaption\"><a href=\"http:\/\/www.simoahava.com\/images\/2026\/03\/terminal-dig.jpg\" title=\"Test dig in terminal to see DNS records\"><img decoding=\"async\" class=\"fig-img\" height=\"148\" width=\"1394\" loading=\"lazy\" src=\"\/images\/2026\/03\/terminal-dig.jpg#ZgotmplZ\" alt=\"Test dig in terminal to see DNS records\"\/><\/a><\/div>\n<h3 id=\"test-ipv6-connectivity\">Test IPv6 connectivity<\/h3>\n<p>If your local machine has an IPv6 address, <code>curl<\/code> can force an IPv6 connection:<\/p>\n<div class=\"highlight\">\n<pre tabindex=\"0\" style=\"background-color:#fff;-moz-tab-size:4;-o-tab-size:4;tab-size:4\"><code class=\"language-bash\" data-lang=\"bash\"><span style=\"display:flex\"><span>curl -6 -v https:\/\/sst.yourdomain.com\/healthy<\/span><\/span><\/code><\/pre>\n<\/div>\n<p>You should get an <code>ok<\/code> response (or whatever your sGTM container returns for health checks). The <code>-v<\/code> flag will show the connection details. Confirm the remote address is an IPv6 address.<\/p>\n<p>If you don\u2019t have native IPv6 at home, <a href=\"https:\/\/test-ipv6.com\">test-ipv6.com<\/a> can give you a sense of your current stack, and tools like <a href=\"https:\/\/test-ipv6.run\/domain-checker\">test-ipv6.run\/domain-checker<\/a> can do a quick DNS and connectivity check against a domain.<\/p>\n<div style=\"aspect-ratio:1062\/250\" class=\"figure nocaption\"><a href=\"http:\/\/www.simoahava.com\/images\/2026\/03\/curl-bash.jpg\" title=\"Curl command output\"><img decoding=\"async\" class=\"fig-img\" height=\"250\" width=\"1062\" loading=\"lazy\" src=\"\/images\/2026\/03\/curl-bash.jpg#ZgotmplZ\" alt=\"Curl command output\"\/><\/a><\/div>\n<h3 id=\"verify-in-the-cloud-console\">Verify in the Cloud Console<\/h3>\n<p>Back in the load balancer detail page, both frontends (IPv4 and IPv6) should now appear under <strong>Frontend<\/strong>, each with their respective IP address.<\/p>\n<div style=\"aspect-ratio:2098\/304\" class=\"figure nocaption\"><a href=\"http:\/\/www.simoahava.com\/images\/2026\/03\/updated-frontend-configuration.jpg\" title=\"Updated frontend configuration\"><img decoding=\"async\" class=\"fig-img\" height=\"304\" width=\"2098\" loading=\"lazy\" src=\"\/images\/2026\/03\/updated-frontend-configuration.jpg#ZgotmplZ\" alt=\"Updated frontend configuration\"\/><\/a><\/div>\n<h2 id=\"update-the-certificate-configuration\">Update the certificate configuration<\/h2>\n<p>Once you\u2019ve verified everything works, you can edit your Load Balancer frontend again, and switch to Certificate Map only for the IPv4 frontend, too. This will release the classic SSL certificate you used to have, and you can delete it in the Certificate Manager as it\u2019s no longer needed.<\/p>\n<div style=\"aspect-ratio:2470\/610\" class=\"figure nocaption\"><a href=\"http:\/\/www.simoahava.com\/images\/2026\/03\/classic-cert-delete.jpg\" title=\"Classic cert delete\"><img decoding=\"async\" class=\"fig-img\" height=\"610\" width=\"2470\" loading=\"lazy\" src=\"\/images\/2026\/03\/classic-cert-delete.jpg#ZgotmplZ\" alt=\"Classic cert delete\"\/><\/a><\/div>\n<h2 id=\"summary\">Summary<\/h2>\n<p>Adding IPv6 to a Cloud Run sGTM deployment is largely a load balancer exercise. Cloud Run itself stays untouched. The key steps are:<\/p>\n<ol>\n<li>Reserve a global static external IPv6 address in GCP<\/li>\n<li>Add an <code>AAAA<\/code> record to your DNS (keep the <code>A<\/code> record)<\/li>\n<li>Create a new Google-managed SSL certificate and add it to a new certificate map<\/li>\n<li>Add an IPv6 HTTPS frontend to the existing load balancer, pointing at the same backend and the new certificate map<\/li>\n<li>Verify with <code>dig<\/code> and <code>curl -6<\/code><\/li>\n<li>Update the IPv4 HTTPS frontend to use the certificate map, too, and delete the now unused classic SSL certificate<\/li>\n<\/ol>\n<p>While working with the certificate map is a bit of a hassle (hopefully it will be fully UI-managed soon!), the payoff is concrete: IPv6 users reach your SGTM endpoint without address translation, so the <code>client_ip_address<\/code> your Meta tags collect (and other vendors!) matches what the client-side tags recorded. Better IP matching means better event deduplication and more reliable attribution.<\/p>\n<p>Let me know in the comments if you run into anything unexpected!<\/p>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>UPDATED 20 March 2026: Shortly after publishing this article, Google Cloud changed how Load Balancer frontend certificate management works. Instead of directly mapping a frontend to a certificate, GCP now wants you to use a certificate map. Luckily, creating one is (fairly) simple, and I\u2019ve updated the guide below to instruct how to do this. [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":356192,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[12033],"tags":[16353,177416,32680,177415,25619,18475,952],"dealstore":[],"offerexpiration":[],"class_list":["post-356191","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-analytics","tag-add","tag-balancer","tag-gtm","tag-ipv6","tag-load","tag-serverside","tag-support"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Add IPv6 Support To Your Server-side GTM Load Balancer - Som2ny Network<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/fivemor.com\/?p=356191\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Add IPv6 Support To Your Server-side GTM Load Balancer - Som2ny Network\" \/>\n<meta property=\"og:description\" content=\"UPDATED 20 March 2026: Shortly after publishing this article, Google Cloud changed how Load Balancer frontend certificate management works. Instead of directly mapping a frontend to a certificate, GCP now wants you to use a certificate map. Luckily, creating one is (fairly) simple, and I\u2019ve updated the guide below to instruct how to do this. [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/fivemor.com\/?p=356191\" \/>\n<meta property=\"og:site_name\" content=\"Som2ny Network\" \/>\n<meta property=\"article:published_time\" content=\"2026-07-09T06:05:54+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/add-ipv6-support-server-side-gtm-load-balancer.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"960\" \/>\n\t<meta property=\"og:image:height\" content=\"540\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"admin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"admin\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"11 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/fivemor.com\/?p=356191#article\",\"isPartOf\":{\"@id\":\"https:\/\/fivemor.com\/?p=356191\"},\"author\":{\"name\":\"admin\",\"@id\":\"https:\/\/fivemor.com\/#\/schema\/person\/b85e3c3dc0e1daea076524dc8810c371\"},\"headline\":\"Add IPv6 Support To Your Server-side GTM Load Balancer\",\"datePublished\":\"2026-07-09T06:05:54+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/fivemor.com\/?p=356191\"},\"wordCount\":2072,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/fivemor.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/fivemor.com\/?p=356191#primaryimage\"},\"thumbnailUrl\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/add-ipv6-support-server-side-gtm-load-balancer.jpg\",\"keywords\":[\"Add\",\"Balancer\",\"GTM\",\"IPv6\",\"Load\",\"Serverside\",\"Support\"],\"articleSection\":[\"Analytics\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/fivemor.com\/?p=356191#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/fivemor.com\/?p=356191\",\"url\":\"https:\/\/fivemor.com\/?p=356191\",\"name\":\"Add IPv6 Support To Your Server-side GTM Load Balancer - Som2ny Network\",\"isPartOf\":{\"@id\":\"https:\/\/fivemor.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/fivemor.com\/?p=356191#primaryimage\"},\"image\":{\"@id\":\"https:\/\/fivemor.com\/?p=356191#primaryimage\"},\"thumbnailUrl\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/add-ipv6-support-server-side-gtm-load-balancer.jpg\",\"datePublished\":\"2026-07-09T06:05:54+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/fivemor.com\/?p=356191#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/fivemor.com\/?p=356191\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/fivemor.com\/?p=356191#primaryimage\",\"url\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/add-ipv6-support-server-side-gtm-load-balancer.jpg\",\"contentUrl\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/add-ipv6-support-server-side-gtm-load-balancer.jpg\",\"width\":960,\"height\":540},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/fivemor.com\/?p=356191#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/fivemor.com\/?bp_activities=1\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Add IPv6 Support To Your Server-side GTM Load Balancer\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/fivemor.com\/#website\",\"url\":\"https:\/\/fivemor.com\/\",\"name\":\"Som2ny Network\",\"description\":\"Daily Deals\",\"publisher\":{\"@id\":\"https:\/\/fivemor.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/fivemor.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/fivemor.com\/#organization\",\"name\":\"Som2ny Network\",\"url\":\"https:\/\/fivemor.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/fivemor.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/4a0953c4-logo-300x86-1.png\",\"contentUrl\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/4a0953c4-logo-300x86-1.png\",\"width\":300,\"height\":86,\"caption\":\"Som2ny Network\"},\"image\":{\"@id\":\"https:\/\/fivemor.com\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/fivemor.com\/#\/schema\/person\/b85e3c3dc0e1daea076524dc8810c371\",\"name\":\"admin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/fivemor.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/729ae85bf62b9917e93538db2f2688ca?s=96&r=g&default=https%3A%2F%2Ffivemor.com%2Fwp-content%2Fplugins%2Fbuddypress-first-letter-avatar%2Fimages%2Fdefault%2F96%2Flatin_a.png\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/729ae85bf62b9917e93538db2f2688ca?s=96&r=g&default=https%3A%2F%2Ffivemor.com%2Fwp-content%2Fplugins%2Fbuddypress-first-letter-avatar%2Fimages%2Fdefault%2F96%2Flatin_a.png\",\"caption\":\"admin\"},\"sameAs\":[\"https:\/\/fivemor.com\"],\"url\":\"https:\/\/fivemor.com\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Add IPv6 Support To Your Server-side GTM Load Balancer - Som2ny Network","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/fivemor.com\/?p=356191","og_locale":"en_US","og_type":"article","og_title":"Add IPv6 Support To Your Server-side GTM Load Balancer - Som2ny Network","og_description":"UPDATED 20 March 2026: Shortly after publishing this article, Google Cloud changed how Load Balancer frontend certificate management works. Instead of directly mapping a frontend to a certificate, GCP now wants you to use a certificate map. Luckily, creating one is (fairly) simple, and I\u2019ve updated the guide below to instruct how to do this. [&hellip;]","og_url":"https:\/\/fivemor.com\/?p=356191","og_site_name":"Som2ny Network","article_published_time":"2026-07-09T06:05:54+00:00","og_image":[{"width":960,"height":540,"url":"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/add-ipv6-support-server-side-gtm-load-balancer.jpg","type":"image\/jpeg"}],"author":"admin","twitter_card":"summary_large_image","twitter_misc":{"Written by":"admin","Est. reading time":"11 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/fivemor.com\/?p=356191#article","isPartOf":{"@id":"https:\/\/fivemor.com\/?p=356191"},"author":{"name":"admin","@id":"https:\/\/fivemor.com\/#\/schema\/person\/b85e3c3dc0e1daea076524dc8810c371"},"headline":"Add IPv6 Support To Your Server-side GTM Load Balancer","datePublished":"2026-07-09T06:05:54+00:00","mainEntityOfPage":{"@id":"https:\/\/fivemor.com\/?p=356191"},"wordCount":2072,"commentCount":0,"publisher":{"@id":"https:\/\/fivemor.com\/#organization"},"image":{"@id":"https:\/\/fivemor.com\/?p=356191#primaryimage"},"thumbnailUrl":"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/add-ipv6-support-server-side-gtm-load-balancer.jpg","keywords":["Add","Balancer","GTM","IPv6","Load","Serverside","Support"],"articleSection":["Analytics"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/fivemor.com\/?p=356191#respond"]}]},{"@type":"WebPage","@id":"https:\/\/fivemor.com\/?p=356191","url":"https:\/\/fivemor.com\/?p=356191","name":"Add IPv6 Support To Your Server-side GTM Load Balancer - Som2ny Network","isPartOf":{"@id":"https:\/\/fivemor.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/fivemor.com\/?p=356191#primaryimage"},"image":{"@id":"https:\/\/fivemor.com\/?p=356191#primaryimage"},"thumbnailUrl":"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/add-ipv6-support-server-side-gtm-load-balancer.jpg","datePublished":"2026-07-09T06:05:54+00:00","breadcrumb":{"@id":"https:\/\/fivemor.com\/?p=356191#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/fivemor.com\/?p=356191"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/fivemor.com\/?p=356191#primaryimage","url":"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/add-ipv6-support-server-side-gtm-load-balancer.jpg","contentUrl":"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/add-ipv6-support-server-side-gtm-load-balancer.jpg","width":960,"height":540},{"@type":"BreadcrumbList","@id":"https:\/\/fivemor.com\/?p=356191#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/fivemor.com\/?bp_activities=1"},{"@type":"ListItem","position":2,"name":"Add IPv6 Support To Your Server-side GTM Load Balancer"}]},{"@type":"WebSite","@id":"https:\/\/fivemor.com\/#website","url":"https:\/\/fivemor.com\/","name":"Som2ny Network","description":"Daily Deals","publisher":{"@id":"https:\/\/fivemor.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/fivemor.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/fivemor.com\/#organization","name":"Som2ny Network","url":"https:\/\/fivemor.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/fivemor.com\/#\/schema\/logo\/image\/","url":"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/4a0953c4-logo-300x86-1.png","contentUrl":"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/4a0953c4-logo-300x86-1.png","width":300,"height":86,"caption":"Som2ny Network"},"image":{"@id":"https:\/\/fivemor.com\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/fivemor.com\/#\/schema\/person\/b85e3c3dc0e1daea076524dc8810c371","name":"admin","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/fivemor.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/729ae85bf62b9917e93538db2f2688ca?s=96&r=g&default=https%3A%2F%2Ffivemor.com%2Fwp-content%2Fplugins%2Fbuddypress-first-letter-avatar%2Fimages%2Fdefault%2F96%2Flatin_a.png","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/729ae85bf62b9917e93538db2f2688ca?s=96&r=g&default=https%3A%2F%2Ffivemor.com%2Fwp-content%2Fplugins%2Fbuddypress-first-letter-avatar%2Fimages%2Fdefault%2F96%2Flatin_a.png","caption":"admin"},"sameAs":["https:\/\/fivemor.com"],"url":"https:\/\/fivemor.com\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/posts\/356191","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=356191"}],"version-history":[{"count":0,"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/posts\/356191\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/media\/356192"}],"wp:attachment":[{"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=356191"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=356191"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=356191"},{"taxonomy":"dealstore","embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fdealstore&post=356191"},{"taxonomy":"offerexpiration","embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fofferexpiration&post=356191"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}