4 ms·
Yeah that was a great idea. Until NAT, firewalls, your average contracted out MSP at an SME sysadmin who's idea of admin is lock everything down and pay £300 to
by buffoon 11y ago
Yeah that was a great idea. Until NAT, firewalls, your average contracted out MSP at an SME sysadmin who's idea of admin is lock everything down and pay £300 to open a port (I have to deal with this at least one a week).
- voltagex_ 11y agoIf normal Skype supported SIP it could just be bounced to Skype in that case. Also, IPv6 FTW!
- buffoon 11y agoYes that's true although I've lost count of the hours I've thrown out on Skype. Yes IPv6 definitely FTW. We just migrated our office and two data centres to it. Life is good now. V6 firewalls are just packet filters; all our nets are in the public address space.
- simoncion 11y agoStupid question: Just in case you want some nets to not be globally routeable, you guys are aware of the Unique Local Addressing block?
- buffoon 11y agoYes aware of that. There are some gotchas with that, particularly address space collision between two sites with a tunnel between them. I've never seen one in v6 but one of our clients had a 10.0.0.0/8 and so did we and I don't want to get into that state of affairs again. I'd only use that for totally airgapped networks.
- simoncion 11y agoThere's a mechanism for randomly generating a /48 with a low probability of collision. [0] SixXS maintains a list of "allocated" prefixes, [1][2] but who knows how complete it is? Edit: Also, you might be interested in reading about the NETMAP iptables/ip6tables target. See iptables-extensions(8) for more info. [0] https://tools.ietf.org/html/rfc4193#section-3.2 https://tools.ietf.org/html/rfc4193#section-3.2 [1] https://www.sixxs.net/tools/grh/ula/ https://www.sixxs.net/tools/grh/ula/ [2] https://www.sixxs.net/tools/grh/ula/list/ https://www.sixxs.net/tools/grh/ula/list/
- sanderjd 11y agoYou seem to know a lot about this so I thought I'd ask: is there a good book getting into this level of detail about IPv6?
- simoncion 11y agoI'm sure that such a book exists, but I have no idea what it is. I've picked up what I know by reading RFCs, Wikipedia pages, and the like and experimenting on my LAN. It's been quite some time, and the details are hazy, but I remember the process of getting a tunnelbroker.net tunnel configured, and the subsequent (totally optional) series of knowledge tests required to unblock IRC over the tunnel taught me a fair bit about IPv6 and some about (reverse DNS? forward DNS?) glue records. Figuring out the meaning of all of the options available in an radvd config file was also rather educational. (20->40% of the educational value was in reading about things that were tangentially related to whatever the radvd configuration item was.)
- aexaey 11y agoYou can make a non-routable subnet if you need one by configuring a firewall/access list. Pretty much any router can do that. Plus you get way better granularity in controlling access - office-local subnet, DC-local, branch-local, country-local, whatever-local access - unlike venerable RFC1918. But never use non-globally-unique addresses as other commentators suggest with wonky probabilistic allocations. There is absolutely zero benefits for that, and it will inevitably end up to be a huge PITA down the line. IPv6 used to have 6-to-6 NAT and site-local addresses, but sanity won, and both were dropped from the current slew of RFCs.
- simoncion 11y agoSure, you can go to all that hassle. Or, you can use RFC4193 (AKA ULA) space, which allocates a /48 and is designed to be non-routable, unless an admin chooses to make it routable. RFC4193 specifies a prefix generation method and lays out the probability of collision. If you join two networks together, you've a (1.81x10^-10)% chance of prefix collision. If you join ten-thousand networks together, you have a 0.0045% chance of collision. [0] If my math is right [1], this means that you'd need to join 2,500,000 networks [2] together to have a 1% chance of a prefix collision. I am squarely in the "If there's a chance that it can happen, it will happen." camp. However, I'm rather okay with those odds. [0] Either my figures are right here, or you need to take those percentages and divide them by 1000 to arrive at the correct figure. [1] And it may not be right! [2] Networks -each with its own /48- as opposed to hosts.
- aexaey 11y agoCollision probability is indeed low if you'll assume perfectly generated prefixes, and even in an unlikely case of /48 collision, those themselves would be pretty sparse, so again assuming perfectly random distribution, chance of collision of say fifty /64s on one side with the same amount from the other network is still pretty low. But bigger point here is that often you will need external connectivity for those ULAs, similar to what everybody used to do in IPv4 world (i.e. NAPT, a.k.a. "nat overload" a.k.a. "IP masquerade"), and that is not something that is available, really. Instead, IPv6 offers prefix translation (a.k.a NPTv6, see RFC6296). So effectively that means that: - for each LAN segment (i.e. /64) you have to have a "private /64" and a "public /64" (or same at coarser granularity up to /49 or even more). Twice the number of networks to configure and keep track of; - "NAT as a security measure" argument flies out of the window, as NPTv6 is stateless. In other words, you get all the hassle of IPv4 NAPT with none of its (meagre) benefits.
- yrro 11y agoMay I ask how you deal with multiple redundant Internet connections at your office? It seems that you either end up with devices having two addresses, and have to deal with all the broken software that assumes a machine only ever has one address, or you use a ULA and NAT which is no better than IPv4 in many ways.
- buffoon 11y agoI really don't know how that works - we contracted it out. There is a router that has an ethernet port on it. That's our internet in. Anything in front of that is ours. Anything behind we don't care about but there is a 100mbit local shared ethernet and a backup FTTP line. I assume it's switched to the same network at the peer end as if either goes down, we only have one address space. We have a couple of front-facing v4 addresses that handles incoming mail. This all sits in a cabinet we don't touch owned by the provider. The stupid thing is the LSE and fibre cables leave the building in the same pipe. Wonder how long it'll be before someone digs through it.
- yrro 11y agoThanks!
- simoncion 11y agouPnP/NAT-PMP pretty much solves the NAT problem, for the home user. :) I'm having difficulty parsing your second sentence. So, I'll say this: If you're a tech business and can't manage to cost-effectively manage the settings on your border equipment, you're doing something really wrong. :)
- buffoon 11y agoSorry my bad. You got the point though. You'd be surprised how many messes there are out there. I tripped over a whole network of unpatched windows XP sp1 machines the other day.
- simoncion 11y agoI'm not sure I got the point. Were you trying to say that before NAT, businesses contracted out to vaguely-competent third-parties who charged an arm and a leg for changes to firewall configuration?
- buffoon 11y agoNo I'm saying that still they do that today and always have done. UPnP is always off. And that's £300 and a service case open to turn it on. Then a 48 hour turnaround. MSP=Managed Service Provider. Basically rip off merchants who charge you for everything because you are trying to run a business with the tech rather than run an operations team.