4 ms·
As a side note, I was very confused about IPv6 addresses popping up in my server logs when I knew it only had IPv4 provisioned. Turns out CloudFlare had automat
by CodeWriter23 9y ago
As a side note, I was very confused about IPv6 addresses popping up in my server logs when I knew it only had IPv4 provisioned. Turns out CloudFlare had automatically published AAAA records for my domain and was v6-to-v4 proxying my inbound HTTP/HTTPS traffic. For free! Just another reason to love CloudFlare.
- exikyut 9y agoThat's... cute. But not breaking anything, so, huh. Not bad.
- lathiat 9y agoessentially because of X-Forwarded-For They have an even crazier feature that rewrites IPv6 source addresses as random but unique IPv4 addresses for software that can't deal with that: https://blog.cloudflare.com/eliminating-the-last-reasons-to-not-enable-ipv6/ https://blog.cloudflare.com/eliminating-the-last-reasons-to-...
- jgrahamc 9y agoThat feature isn't as nuts as you think. Clearly the IPv6 space doesn't compress 1-1 into the IPv4 space but this gives you way to work with the top 64 bits of the IPv6 address and then feed it into your anti-abuse system. If your abuse system works probabilistically then this isn't too problematic as this becomes just another signal. And IPv4-based systems already deal with multiple people behind the same IP because of NAT.
- peterwwillis 9y agoYou have users who can already access a site using IPv4, but want to use IPv6, and you have an anti-abuse system that lacks support, so you decided to invent a new kind of NAT, rather than require the customer to just fix their anti-abuse system, which they'd need to do on other platforms anyway? The feature isn't nuts, but the rationale seems so.
- jgrahamc 9y agoHow could we 'require a customer to just fix their anti-abuse system'?