3 ms·
People are going to have to wrap their head around the brave new v6 world. I get "logged in from a new IP address!" alerts with a service I use almost every ti
by DanielDent 11y ago
People are going to have to wrap their head around the brave new v6 world.
I get "logged in from a new IP address!" alerts with a service I use almost every time I log in, even though my IPv6 prefix hasn't changed. Deciding it's a completely new IP just because something changed in the last 64 bits is probably a bad idea in a v6 world.
Devices being multi-homed is intended to be standard practice.
My iPhone regularly has multiple IPv6 addresses, with different reachability characteristics for different addresses. There's an address used by my carrier for voice, there are addresses I locally administer, there are addresses from a stable prefix I use, addresses from dynamic prefixes provided by my upstreams, ...
The v6 world is a world where many devices have many addresses and addresses do not all have the same scope.
Application developers are going to need to get used to this new normal.
An application I manage has ~40% of users accessing it over IPv6, most of which would have a degraded experience if we didn't offer v6 connectivity.
IPv6 is here, it's here to stay, and applications are going to need to understand the new world they live in.
- mirimir 11y agoYes. And it's not just multiple IPv6. I don't know iOS, but Windows, OS X and Debian all use only "privacy-friendly" (RFC 4941) IPv6 with remote devices. And they change frequently. That gets to be a pain when you're pushing static routes. NAT was so easy.
- DanielDent 11y agoI'm not sure I understand what your use case is for pushing static routes & would be interested to understand what you mean. I've been trying a few different approaches to routing. Putting link-local addresses in routing tables has worked well in some deployments. Debian & OS X use MAC based addresses in addition to their privacy addresses. https://www.danieldent.com/blog/remote-ipv6-device-fingerprinting/ https://www.danieldent.com/blog/remote-ipv6-device-fingerpri...
- mirimir 11y agoI'm pushing static routes over OpenVPN tap to get IPv6 assigned to remote LANs. In my (very limited) experience, the MAC-based IPv6 don't reach the Internet (http://test-ipv6.com http://test-ipv6.com for example). However, they do get revealed via WebRTC in Firefox (default install). IE and Safari block WebRTC by default.
- DanielDent 11y agoMy testing has shown they are accessible over the internet :(. They are not marked as 'preferred' and won't be used by default. But they are still available for use if someone goes out of their way to do so.
- mirimir 11y agoThanks. I was going from http://test-ipv6.com/ http://test-ipv6.com/. Unless the "privacy" address is routed, it reports no IPv6 connectivity. I'm guessing that ping6 should find them, right?