4 ms·
Most of it can't, actually. Rather, using the words in the question in their strict meaning, most of the hardware out there is not on the "public internet", it
by Mythanar 10y ago
Most of it can't, actually. Rather, using the words in the question in their strict meaning, most of the hardware out there is not on the "public internet", it is behind NAT.
You can argue that behind NAT there is still IPv4 connectivity with public internet, but it is actually closer to proxying (i.e. having some device talk to internet on your behalf) than to routing (i.e. have some device pass your packets on).
Long story short, there is (for a long time already), no IPv4 public internet. There is IPv4 public interconnect between millions of isolated IPv4 islands. And a lot of hacks and shady engineering to make packets traverse from interconnect to islands and back.
- zbjornson 10y agoBut if that exists, why should I as someone running on EC2 care if I can use IPv6 natively or have to make use of such proxying/routing?
- toast0 10y agoI don't know enough AWS to understand the announcement, but if your servers and your clients can speak IPv6 and you can skip al the NAT, you don't have to debug NAT problems.
- sigjuice 10y agoWe probably won't ever be rid of NAT. The likes of Cisco, who thrive on making things enterprisey and needlessly complicated will definitely be peddling IPv6 NAT soon, if they aren't already doing it.
- toast0 10y agoYou're probably right, but many telecoms have already deployed ipv6 without a bunch of layers of networking hell, and I'm hopeful that they'll just junk all the crazy ipv4 stuff without replicating it in ipv6. It'll be cheaper for them and nobody will notice the difference.
- manigandham 10y agoNAT was created to solve the ip space shortage, which ipv6 doesnt have. There's no point in ipv6 NAT.
- sigjuice 10y agoTell that to the people who want NAT for "security".
- pilif 10y agoNAT gives the same amount of security as dropping all SYN packets at the firewall level. The latter just requires much fewer resources to do as it allows for completely stateless operation.
- openasocket 10y ago> NAT gives the same amount of security as dropping all SYN packets at the firewall level What about UDP packets?
- pilif 10y agoIPv6 NAT is generally discouraged and providers can gain huge benefits too from not doing NAT. NAT always implies state which needs to be stored somewhere. The moment you NAT, you very likely won't be able to do the routing in pure hardware any more, so throughput is an issue. routing v6 directly is completely stateless. It can easily be done completely in hardware possibly not even requiring to store the packet anywhere, nor needing any knowledge of the protocols wrapped inside of the IP packet. To do NAT, you need to know about TCP and UDP and about the various ports which means you need to look into the IP packet. To route v6, you just look at the IP packet.
- Mythanar 10y agoThe reasons are many. I'll name just a few: * You cannot send UDP packets to your IPv4 customers. * You cannot initiate TCP connections to your IPv4 customers. * You cannot use any application-level protocol that carries information about source or destination IP address. * IPSec more or less goes out the window
- brianwawok 10y agoBut even if my desktop does IPV6.. I am still going to firewall it. Seems like not a "benefit" to throw up my device directly on the internet.
- pdkl95 10y agoOf course you'll keep your firewall. NAT != Firewall Your firewall may start with a simple "deny all incoming SYN packets" rule, but IPv6 gives you the option to open up holes in the firewall to any device or devices on your LAN (port forwarding only works once per port through a NAT). The real benefits probably don't exist yet. There are entire categories of network software that have remained unknown and unexplored because it didn't work behind a NAT. There were several projects I wanted to write ~15 years ago that I never even started because it required a real internet connection, not a NAT "party line".
- brianwawok 10y ago> Your firewall may start with a simple "deny all incoming SYN packets" rule, but IPv6 gives you the option to open up holes in the firewall to any device or devices on your LAN (port forwarding only works once per port through a NAT). But see.. I can already do that with IPv4 and Nat. Oh I want to run a ftp server on my backend? Open up port 8000 on my firewall and forward to port 21 on my FTP server. I find it weird I am making this argument, as I am normally progressive. I push Python3 over Python2, because it is the way of the future. Even though it causes me pain sometime. For some reason, I just do not see the (for me personally) reason to care about ipv6. Clearly the more backbones that support it, the better. It at least gives us the OPTION to use it later. Not totally sure what good it will do still though ;)
- jbott 10y agoYou individually? There really isn't a reason to. * However, as a whole, the lack of native IPv6 support in EC2 certainly held back the global deployment cycle. It's the chicken and the egg problem: Without support for servers that use IPv6, there is no reason for last mile providers to implement it in households. With this update, a huge swath of sites will get support, hopefully leading to quicker adoption for end users. * for most applications. This is certainly trivializing a subset of applications where this could be useful.
- p1mrx 10y agoIn the vast majority of cases, you cannot use proxying/routing to reach an IPv6 address. If you don't have IPv6 yourself, then any attempt to communicate with another IPv6 address simply fails. It's sort of like asking "Why should I connect to the Internet, if everyone I know already has a telephone?"