5 ms·
IPv6 is a mess, over-engineered, non-intuitive, magic addresses etc. All they needed to do was expand the address space, but it looks like the kitchen sink got
by ta58844874 7y ago
IPv6 is a mess, over-engineered, non-intuitive, magic addresses etc.
All they needed to do was expand the address space, but it looks like the kitchen sink got thrown in.
- ineedasername 7y agoWhat were the changes in IPv6, beyond just expanding the address space?
- jandrese 7y agoIP Fragmentation at routers was removed from the protocol for one. Another is that it changes the way you think about IP addresses, with endpoints getting a /64 instead of a single address like you did in IPv4. This allows users to change their IP address for every connection if they want, so if you want to apply policy to them you need to apply it to the entire subnet they are on. Granted, this also happens in IPv4 if you are doing NAT, so it's not really a change for most people. There are a few other changes to stuff like QoS to better reflect modern practice, but for the most part it's pretty similar. Also, the IP header lost its checksum, as it was basically never useful.
- dependenttypes 7y ago> IP Fragmentation at routers was removed from the protocol for one. Everyone that I talked to about this seemed to like the change.
- throw0101a 7y ago> Another is that it changes the way you think about IP addresses, with endpoints getting a /64 instead of a single address like you did in IPv4. End points get /128, it's just that subnets are now /64. That simply means that endpoints can auto-assign themselves a new /128 because--instead ofhaving only space for 2^8 hosts in the typical /24 subnet of IPv4--there is now space for 2^64 hosts, which makes it unlikely that collisions will occur.
- zAy0LfpBZLC8mAC 7y ago> Another is that it changes the way you think about IP addresses, Only if you don't have a clue of IPv4 either. > with endpoints getting a /64 instead of a single address like you did in IPv4. That's just wrong. And endpoint gets one address, just as with IPv4 (and can optionally assign additional addresses where address space is available, also just as with IPv4). What gets a /64 by default is a link, like, an ethernet. Which is also exactly like in IPv4, except, of course, with IPv4 you had shorter/fewer addresses, and thus obviously also smaller prefixes/fewer addresses per link. > This allows users to change their IP address for every connection if they want, so if you want to apply policy to them you need to apply it to the entire subnet they are on. Which is also exactly the same as with IPv4. If your LAN has an IPv4 /24, you can also change you address for every connection. > Granted, this also happens in IPv4 if you are doing NAT, so it's not really a change for most people. You have it all backwards?! NAT is what makes this impossible for connections to the public internet, in that no matter how you change your RFC1918 address, you keep the same address to the outside world? But that obviously is not a property of IPv4, but of NAT.
- jandrese 7y agoI wasn't quite precise, because there are cases where you do DHCPv6, but as Android doesn't support it the protocol is a bit dead in the water. SLAAC the router gives you the 64 bit prefix and the host chooses its own 64 bit host address, which can be any address not already in use. With IPv4 you are typically assigned a single IP address via DHCP. While it is true that you are free to ignore the DHCP address assigned to your host and select something else on the same subnet, this is not typical. With SLAAC however it is the norm for the host to figure out its own address, and to leverage the enormous IP space available in IPv6 to change up their source address at will. Filtering individual hosts by IP has always been leaky, but IPv6 makes it more or less impossible. You have to filter by subnet. IPv6 does have some braindamage. SLAAC didn't have a way to communicate the local DNS server address to hosts, nor a way for hosts to update the DNS with their selected addresses and hostnames. This is something that has just worked in DHCP for decades and was completely ignored by the IETF. There was some handwaving about mDNS and anycasting but the actual protocol for doing the updates was never nailed down and it ignored the fact that multicast on wireless networks has always been fragile and plagued by hardware/driver issues.
- unilynx 7y agoIf someone is smart enough to hop IP addresses to avoid your firewall, surely they can come up with ways to tunnel a VPN out of your network (eg through DNS or over port 443...)
- dijit 7y agoRouter advertisement via ICMP is one I can name off the top of my head.
- q3k 7y agoThere is no router advertisement/NDP/SLAAC in IPv4, so that's not a fair comparison. NDP/SLAAC has a vastly different architecture and behavior than DHCP(v4), and also deprecates other hacked-on IPv4 features (like DHCPv4 link local addresses and ARP).
- noipv6 7y agondp in ipv4 is called "arp" =D
- duffmancd 7y agoChanges to the way that DHCP works. There are now different methods if you're handing out subnets to a router, IPs to an end device or allowing devices to (automatically) self assign. And not all devices support all methods.
- azernik 7y agoEvery device that I saw as of 4 years ago (when I was working on edge IPv6 implementation) supported the NDP/SLAAC method of assigning IP addresses, which is the default for most leaf node use cases. It's optimized for a unidirectional transmission of information from routers to leaf nodes. DHCPv6 is used for routers, which need to be given not just an individual address on the local interface but also a prefix that they can hand out to their clients. It's optimized for flows that require a confirmation from the client that it has accepted/reserved the configuration that it's been given. It is technically possible to use DHCPv6 to hand out IPs to endpoints, but I have not seen any production network in the wild that does this.
- azernik 7y agoAside from what everyone else is saying about the semantics, there were also a lot of changes in the header format to make it easier to parse in hardware by ASICs. Fixed-length basic header, a single integer flag that indicates to routers when they need to parse variable-length options, a requirement that in the unlikely event they are used that those options need to be 64-bit-aligned, etc. As long as they were breaking compatibility, all kinds of details were changed to make things easier on implementers.
- q3k 7y agoIt's not more of a mess than IPv4. It's okay, people can learn it as they learned the weirdness of IPv4 (DHCP, ARP, NAT, RFC1918, IP fragmentation, ...).
- _red 7y agoWill any device made of matter / operating in polynomial time ever be able to hold the full 2^128 address space? It seems like we will forever be sub-netting into huge blocks simply because the entire space if mathematically infeasible to operate on. I think its fair to ask: Whats the point?
- q3k 7y agoFor IPv6, the Internet routing table will never be split into more than 2^64 blocks, as a /64 is the general minimum BGP-announcable IPv6 block. Regardless, I don't get your argument. Why would not being able to address all of a given address space be a bad thing? Isn't the whole point to have more address space than will ever by physically possible to need?
- _red 7y ago>Isn't the whole point to have more address space than will ever by physically possible to need? Is that not the definition of over-engineering?
- Aeolun 7y agoNah, in this case I agree. We thought the IPv4 space was more than we were ever going to need, and see where that left us... Now we just took what we thought we needed, and added a few tens of orders of magnitude.
- jsjohnst 7y agoLet me give you an example to illustrate the scale. An average human cell is composed of 100 trillion atoms. [0] An average human body is composed of 100 trillion cells. By that we see there are about 10^28 atoms in a human body. Let’s be conservative, and say the world population for the next fifty years stays under 10 billion (most estimates say closer to 100 years). That gives us about 10^38 atoms across all human beings on earth. Why does this matter? Because 2^128 is 3.4 × 10^38. That’s three IPv6 addresses for each and every atom in all the humans on earth for at least the next 50 years. If that’s not the definition of overkill, I dunno what is. [0] https://www.thoughtco.com/how-many-atoms-in-human-cell-603882 https://www.thoughtco.com/how-many-atoms-in-human-cell-60388... Edit: And if you say the real routable space of IPv6 is only 2^64, then my point still stands. Rather than it being 3 IPs for every atom, it’s still an IP for essentially every cell of every human on earth for the foreseeable future.
- Aeolun 7y agoI would have understood this, as well as making it clear just how ginormous the IPv6 space is. 65536.65536.65536.65536.65536.65536.65536.65536
- exikyut 7y ago1.8442.16384.20.9000.42.1337.999 looks half like somebody dropped a phone number into a mass-doubling machine, and half like an overgrown object identifier.