5 ms·
Indeed! If anyone needs to feel the squeeze for IPv4 to make a move to IPv6, it is AWS... which MIT is conveniently selling the IPv4 addresses to!
by hawkling 9y ago
Indeed! If anyone needs to feel the squeeze for IPv4 to make a move to IPv6, it is AWS... which MIT is conveniently selling the IPv4 addresses to!
- srcmap 9y agoSometime, I felt force all IOTs devices, typical laptops, Phones, behind NAT is actually safer for internet as whole. Security via network segmentation. IMO, NAT gateway is good place to lock down and put in network security appliance to track/block all the unwanted connections.
- kazen44 9y agoexcept NAT does neither network segmentation or lock down the network. Those things are done by a router and firewall. Implementing proper security of IoT devices can be solved by A) writing more secure software for IoT devices and B) having a proper firewall solution with sane defaults. Using NAT as a tool to masquerade your IP addres is not secure. see NAT hole punching for example [1] NAT is terrible from a network engineering perspective, it was mostly a patchwork to deal with the rapid expansion of the internet and the shortage of IPv4 space. IPv6 brings a lot of cool technology to the table in, like MTU path discovery[2], header extensions[3] and proper anycast[4]. It also makes dealing with subnets and network segments a lot more sane and scalable. [1] https://en.wikipedia.org/wiki/Hole_punching_(networking) https://en.wikipedia.org/wiki/Hole_punching_(networking) [2] https://tools.ietf.org/html/rfc1981 https://tools.ietf.org/html/rfc1981 [3] https://www.cisco.com/en/US/technologies/tk648/tk872/technologies_white_paper0900aecd8054d37d.html https://www.cisco.com/en/US/technologies/tk648/tk872/technol... [4] https://en.wikipedia.org/wiki/Anycast https://en.wikipedia.org/wiki/Anycast
- CamperBob2 9y agoHas any security threat ever relied on NAT hole punching from the outside in? The only cases I can think of involve defective gateway firmware, and IPv6 is hardly a panacea for that. My guess is that IPv6 is the ISDN of the 21st century... an intermediate step between two networking paradigms, one being IPv4 and the other being something we haven't seen yet. IPv6 will appeal to specialists but will never, by itself, see wide adoption. The fact is that NAT works for 99.99% of users, and works very well.
- bluGill 9y ago> NAT is terrible from a network engineering perspective, it was mostly a patchwork to deal with the rapid expansion of the internet and the shortage of IPv4 space NAT is very useful to the network engineer. NAT lets you turn one network into a different one on a simple one-to-one translations basis. However NAP got mixed up with masquerading to the point where when someone says NAT they assume you also mean masquerading when in fact the two are different concepts. NAT when you are doing a many-to-one translations is a disaster in many ways, but it works just well enough (and face it, the alternatives don't exist)
- kazen44 9y agoah well, i should have been more clear in my comment. PAT especially is a disaster. One to One NAT translation is fine although it still breaks a lot of things, especially on the IPV6 side of things. (like MTU path discovery).
- merb 9y agowell lately aws (even ec2) supports IPv6. would be cool if they would enforce it. I.E. only IPv6 internally and only via some kind of edge router to IPv6.
- dastbe 9y agoAWS does support ipv6 everywhere; the problem is that many consumers do not (I can't access ipv6 on my current provider w/o doing work on my side, for example) and so the need for public ipv4 is going to continue for years. I would be really happy to have only ipv6 addresses in my VPC, as that would make connecting up multiple VPCs much easier since I know their ip space won't overlap.
- jandrese 9y agoThat's new. Last time I tried to get an IPv6 address for an EC2 instance it was either impossible or you had to set up this complicated virtual network thing depending on where your EC2 instance was physically hosted.
- neuronexmachina 9y agoYup, they rolled out IPv6 support across several services in January 2017: https://aws.amazon.com/blogs/aws/aws-ipv6-update-global-support-spanning-15-regions-multiple-aws-services/ https://aws.amazon.com/blogs/aws/aws-ipv6-update-global-supp...
- dastbe 9y agoAWS will give each VPC a /56, and each subnet a /64 https://aws.amazon.com/blogs/aws/new-ipv6-support-for-ec2-instances-in-virtual-private-clouds/ https://aws.amazon.com/blogs/aws/new-ipv6-support-for-ec2-in... Again, the thing I would like to see is being able to either peer only ipv6 for VPCs, or have a VPC that is ipv6 only. That to me will greatly increase flexibility and simplicity if I'm ok with an ipv6-only deployment
- lloeki 9y agoThe situation over here is quite the opposite, if you're using the regular plans of the major ISPs (which is most people) you have IPv6. Free ADSL, which has been providing IPv6 access via 6rd for like 10 years, even started deployment of IPv6 only DSLAMs in April. This makes the absence of IPv6 on major platforms and sites very visible. There is no excuse not to have IPv6 today, especially for market leaders, and its lack thereof is definitely a showstopper WRT services we choose to use. As an anecdote, we have seen some constantly increasing traffic over IPv6 in our logs, and our customers are definitely not on the technical side, very far from it. http://m.universfreebox.com/article/38742/Free-deploie-ses-premiers-DSLAM-entierement-IPV6 http://m.universfreebox.com/article/38742/Free-deploie-ses-p...