5 ms·
This is my favorite bit about native IPv6 at home [0]. No more port forwarding to expose particular services -- I can just `ssh desktop.home.net` or `ssh other.
by cfallin 7y ago
This is my favorite bit about native IPv6 at home [0]. No more port forwarding to expose particular services -- I can just `ssh desktop.home.net` or `ssh other.home.net`, and they both get to run on default ports! (Of course, one probably wants a firewall -- I block inbound IPv6 by default except ssh.)
[0] Comcast is surprisingly good here -- they'll give you a /60 (16 /64 networks) if you ask for it with the right DHCP option!
- floren 7y ago> [0] Comcast is surprisingly good here -- they'll give you a /60 (16 /64 networks) if you ask for it with the right DHCP option! Can you go into more detail or point me to instructions? I'm on Comcast and would be interested in getting v6 at home.
- Aloha 7y agoI think Comcast is native dual stack across their entire footprint so long as you have new enough hardware
- cfallin 7y agoSure! The keyword to look for is "DHCP-PD" (DHCP prefix delegation). I run a little OpenBSD router and my dhcpcd.conf is here [1], but I've done this before on a Linux router box too -- here are some instructions from Arch's wiki [2]. IIRC, the stock firmware on my old consumer router was also able to request a prefix and advertise it on the network. [1] https://gist.github.com/cfallin/e5865a6a93c75ace8d26d6a85287ed76 https://gist.github.com/cfallin/e5865a6a93c75ace8d26d6a85287... [2] https://wiki.archlinux.org/index.php/IPv6#Prefix_delegation_(DHCPv6-PD) https://wiki.archlinux.org/index.php/IPv6#Prefix_delegation_...
- virusduck 7y agoDo you also have an IPv4 address that you can use for NAT for those things that cant use IPv6? (Also do you have devices that aren't capable of using IPv6?)
- cfallin 7y agoYes, I have native IPv4 too, with the usual NAT. I think the default router that Comcast will rent to you actually is dualstack in this way too -- IPv4 NAT, and IPv6 prefix advertised for devices that want it. I actually played with NAT64 for a bit (IPv6-only internally, all IPv4 space is mapped to a special /96 in IPv6-space and NAT'd at the router, and local DNS server on the router returns translated AAAA records for IPv4-only hosts), but dropped that when I simplified my router config. It works, it just takes a bit of config :-)
- kadoban 7y agoThis may be a dumb question, but why does one need with a /60 ? Isn't a /64 already ridiculously huge to the point that I could never possibly use it all?
- snagglegaggle 7y agoNot with that attitude.
- oarsinsync 7y agoIETF recommend a /64 as the smallest subnet size to use, as stateless auto address configuration (SLAAC) only works with that subnet size. Any user that wants more than a single subnet at home is supposed to receive a /48 by the same recommendation base. A lot of ISPs settled on /56s. Comcast is a bit more stingy than some. That introduces a whole other set of problems.
- zaphoyd 7y agoNot a dumb question at all! The smallest IPv6 subnet is /64, so a /60 lets you split your network into multiple subnets without all the software that assumes a subnet is /64 (like address autoconfig) breaking. Why might you need multiple subnets? Lots of reasons, common ones are for security. It lets you do things like split up a home office network from home from guest wifi from IoT/home automation. Also allows new services to be created that use that capability.
- cfallin 7y agoThe RIPE guidelines at [0] line up with what I've heard as justification before: basically, /64 is the smallest you can go without lots of manual configuration (the way that SLAAC auto-assigns addresses from Ethernet MACs or random bytes only works when the host part of the address is 64 bits). There may be valid technical reasons to want > 1 subnet at a customer site. And finally, the space is huge -- an ISP would typically get a /32 at least (Whois says that Comcast is using a /26 just for the Bay area), so if every customer gets a /60, that's 2^28, or 256M, delegations. (With the /26, Comcast could hand out 16 billion /60 delegations to their SFBA subscribers.) [0] https://www.ripe.net/publications/docs/ripe-690#4--size-of-end-user-prefix-assignment---48---56-or-something-else- https://www.ripe.net/publications/docs/ripe-690#4--size-of-e...
- magicalhippo 7y agoThat was one of my motivations to try IPv6 at home, only to quickly get disappointed because my ISP gives me a new prefix change very often (in stark contrast to my IPv4 address for some reason).
- ripdog 7y agoI have this issue too, so I use Ddclient-curl to do dynamic dns via cloudflare. DDNS is something that I once thought would be an artifact of a less civilized time, but ISPs gotta upsell, I guess.
- magicalhippo 7y agoMain problem for me is that my router doesn't update firewall rules when prefix changes, and I can't get it to not advertise its public ip for the DNS resolver running on the router which of course breaks when the prefix changes.
- ripdog 7y agoHmm. I run pfsense, it advertises its own v6 address as a DNS resolver, and I've never had any issues with it breaking. Admittedly, I don't know it isn't just falling back to v4 for a period when the prefix changes. But I did just check and my PC is getting the correct v6 addr of my router as DNS resolver.
- magicalhippo 7y ago> Admittedly, I don't know it isn't just falling back to v4 for a period when the prefix changes. At the very least, IPv4 fallback takes a few seconds for each DNS query, and I've experienced it failing completely in some cases (can't recall if I ever figured out why). So regardless it's a PITA when it happens. I tried disabling the option for it to advertise itself as a DNS and instead insert the local IPv4 address in the DHCP options but to no avail, clients still ended up with public IPv6 as main DNS. After a few hours of trying to fix it I just turned off IPv6 again.
- tialaramex 7y agoYes, you probably should have a firewall but the sheer size of IPv6 means that whereas I'll have several idiots banging their heads on my SSH services at any one time on IPv4 I'm not sure I've ever had one trying on IPv6 in the years that I've had service available on both public IPv4 and IPv6. If you set a machine to try just one IP address per second in IPv4 you'll explore a significant fraction of the whole public address space per year. In IPv6 doing that is extremely unlikely to find even a single valid address to connect to in a human lifetime.