8 ms·
My ISP supports IPv6, and while I can understand why a large organisation would want to use it (especially given the increasing cost and scarcity of IPv4 blocks
by walton_simons 6y ago
My ISP supports IPv6, and while I can understand why a large organisation would want to use it (especially given the increasing cost and scarcity of IPv4 blocks), I'm still yet to be persuaded of its benefits for home users. I admit that I only have a very cursory understanding of how it works, and perhaps I'm just stuck in my ways, but the scale and complexity seems so extreme compared to IPv4, with no compensating advantages that I can see. So all my devices become globally routable. And? I can already do everything I want and need to do with a single IPv4 address and NAT.
Even just working out what IPv6 devices are on my network and who they're communicating with seems very difficult given the giant address space. I'm slightly ashamed to admit this (feels very anti progress!), but I've blocked all the IPv6 traffic on my home LAN. Devices can still talk to each other, but no IPv6 packets are allowed out to the internet. Everything still works fine. My firewall blocks a few hundred MB per day of IPv6 traffic, and I have no idea what any of it is.
Very happy to be told why I shouldn't do this though.
- gvjddbnvdrbv 6y agoI'm certainly going to be dropping all incoming IPv6 packets when my ISP foists IPv6 on us.
- throwaway2048 6y agoThe advantage of ipv6 for consumers is that many ISPs (especially non american ISPs) don't and can't hand out public IPv4 addresses, due to the lack of remaining IPv4 addresses for them to allocate. The choice isn't between every device being globally routable (which is easily solved by a firewall WITHOUT NAT) and a single routable address, the choice is between zero public routable addresses, and as many as you need.
- tialaramex 6y ago[The parent edited their post to render my comment wrong]
- throwaway2048 6y agoI also have a non American ISP, and they will not give me a public IPv4 address, for any amount of money.
- treysis 6y agoHe didn't say "all", he said "many". And that is factually right. Many ISPs use DSLite/CGNAT and don't hand out public IPv4 addresses to their customers anymore. Yes, some offer the option to change to a public IPv4, some charge extra money for this feature, and some don't offer it at all! E.g. my ISP doesn't hand out public IPv4 and you can't order it, unless you change to a business contract. However, my ISP is doing some weird 1:1-NAT, so while I don't get assigned a public IPv4 to my router, I do get assigned a single IPv4 on the CGNAT router that also translates back to my home network.
- oarsinsync 6y ago> However, my ISP is doing some weird 1:1-NAT It's probably a 1:Many NAT, where the external IP you see yourself as coming from, is used by many customers, not just you. Otherwise there's no upside to deploying the additional overhead and cost of CGN devices for the carrier.
- deleted 6y ago[deleted]
- billpg 6y agoWhile NAT works very well for home users, servers still need distinct IPs if they are to be accessible by the public. You can get away with shared IPs with some protocols but sometimes you need a whole IP to yourself.
- q3k 6y ago> Very happy to be told why I shouldn't do this though. Because your IPv4 traffic goes (or will, in the future, as IPv4 depletes further) through a slow, overprovisioned CGNAT - making IPv4 much slower then IPv6.
- bzb3 6y agoThat's scaremongering and simply false. Cgnat servers are not necessarily congested. I've been to several isps with cgnat and none of them suffered from congestion. On a more personal note, if ipv6 were so great, their fans wouldn't have to make up things to badmouth ipv4.
- throwaway2048 6y agoNAT is fundamentally a limited technology that has massive scaling problems that simply do not exist in non-nat networking situations. The larger the network behind the NAT, the more problems you get. This is also before considerations like the fact NAT breaks 2 way connectivity that is the cornerstone of the design of the internet. >if ipv6 were so great, their fans wouldn't have to make up things to badmouth ipv4. The explicit goal and reason IPv6 was created was to make up for the short-comings of IPv4.
- deleted 6y ago[deleted]
- oarsinsync 6y agoThe IPv6 standard was ratified in the 1990s. The Internet of the 1990s was very different to the Internet of 2020. The widespread surveillance of activity as it exists today was not a consideration back then, nor were there the same security concerns, making it a desirable property to have every device uniquely and globally addressable. Privacy extensions were then ratified (RFC 4941) after 2007 as a workaround, and firewalls get applied on hosts and gateways to protect against bad actors on the Internet (which are significantly more prevalent today than 20+ years ago). IPv6 is not a magic bullet. The increase in addressable space is definitely a positive. Pretty much everything else is up for debate, depending on perspective and use case. I've been dual-stacking networks for over a decade. The easy part[0] is making the network work with both IPv4 and IPv6. The hard part is making everything else work. [0] Easy is relative. I agree with everything listed in https://news.ycombinator.com/item?id=24059729 https://news.ycombinator.com/item?id=24059729 as additional sources of complexity and confusion. That's still just the mole hill at the start of the mountain.
- iknowstuff 6y agoWhat complexity? Devices being autoconfigurable without DHCP is less complex. Having no NAT is less complex. Having a public IP is less complex. You just got used to the complexity of IPv4. Why the hell would you block IPv6. You ARE stuck in your ways. OS vendors consider it necessary on LAN for various functionality.
- georgyo 6y agoI really think IPv6 is the future but, Devices configuring without DHCP as a network administrator is really hard. There is no longer a single method to be given an IP6 address, and with the auto methods, there is no log either. Only some clients will do dhcpv6 which means you often have two different auto configuring services on a network. Similarly, to see devices on a network I now have to use neighborhood discovery whice gives me a bunch of IPs, but very hard to figure out which IP is for that raspberrypi next to me. Port scans are much harder. Public IP address are great, but now a filtering firewall is always required at the edge, since I don't want my printer being reachable on the internet. There isn't a upnp for IP6 to punch wholes automatically either. Ironically P2P over ipv6 is harder because the firewalls are so unforgiving.
- walton_simons 6y agoHonestly it's reassuring to read this. I do want to understand IPv6 better and I think I am slowly getting to grips with how it all fits together, but the details regularly make me feel as though I need to throw out a lot of what I think I know about networking, and rebuild my entire mental model from the ground up.
- Decade 6y agoYes, you should throw out a lot of what you know about networking. Port scanning _should_ be difficult in IPv6. Instead, you should be using DNS and/or multicasting. Having multiple ways to configure IP addresses _isn’t_ a problem. Modern devices have lots of RAM. They can handle having lots of IP addresses. Because of how difficult it is to port scan IPv6, as long as you don’t manually allocate a low-entropy address to the printer, it won’t be easy to get to it. Even better, these days you can allocate a unique local address to the printer (RFC 4193, fd00::/8) and eliminate Internet access entirely. https://tools.ietf.org/html/rfc4193 https://tools.ietf.org/html/rfc4193
- dijit 6y agoYou've had a few replies so I guess mine will be lost to the aether. NAT vs Direct addressing is an interesting topic, because we've gotten so used to working around the issues inherent in NAT that we take them as a sort of given. I'll lay them out here: 1) The actual NAT state table in your router is much slower than a simple bit-map firewall lookup. This will show up as a bit of latency on every new connection. 2) The state table can get full. When that happens some connection needs to be evicted. For web technologies this wont look too bad.. Maybe a websocket connection gets closed and re-connects in the background. But if you're streaming something over raw TCP then that's annoying. Basically it makes your internet connection just that little less stable. 3) uPnP exists to try to mitigate the p2p issues with NAT; but does a poor job. -- Take for instance, a video game with VOIP, consoles are notorious for this; centralising and muxing everyones audio is expensive, so it's more useful to help people build peer meshes. So "NAT PUNCHING" is the normal way to go, but of course that doesn't always work, so you have weird tutorials on "how to port forward" when in reality this shouldn't be needed, a stateful firewall would be enough if not for NAT. Some guides even suggest putting your devices in the DMZ with direct port forwards on every port from the internet[!!] https://www.denofgeek.com/games/how-to-change-nat-type-on-ps4/ https://www.denofgeek.com/games/how-to-change-nat-type-on-ps...
- mehrdadn 6y ago> The state table can get full. When that happens some connection needs to be evicted. This would be so much more convincing with some numbers to show it actually does happen in reality, especially at a rate that's comparable to other random connection drop-outs.
- c0nsumer 6y agoThe most common symptom of this is someone mentioning that their home 'router' regularly needs reboots to keep working well. Excluding memory leaks, it's frequently the state table running out of space and connections going sideways as a result. This is hard for individuals to see, but put a fair bit of load on a home consumer 'router' and, presuming you can get enough access to it to watch resources, you'll see it run out. This is one of the things that better home network devices do: have sufficient RAM to handle a big state table, and manage it well. IPv6 completely sidesteps this by not even needing a state table because no NAT.
- throw0101a 6y ago> I'm still yet to be persuaded of its benefits for home users. According to Apple, IPv6 is 1.4 times faster than IPv4 (latency wise AFAICT): * https://www.zdnet.com/article/apple-tells-app-devs-to-use-ipv6-as-its-1-4-times-faster-than-ipv4/ https://www.zdnet.com/article/apple-tells-app-devs-to-use-ip... This is supposedly "due to reduced NAT usage and improved routing."
- ac29 6y agoIn that article, Apple says the connection setup is 1.4x faster, not that there is a 40% improvement in throughput or latency.
- ksec 6y agoI wonder are these mostly on Client side or is this ISP side of things? It is great marketing to list 40%. But we need to know 40% of what. If it was 1ms, than 0.4ms faster isn't much of a performance.
- jedberg 6y agoAnecdotal, but IPv6 saved me a lot of headache recently. I got a warning about an unauthorized attempted login to my gmail account. They gave me the IP of the offending login. I was able to track that IP not only back to my house, but to a specific device in my house. It was my NAS, and it was trying to log into gmail to send me an email about a failing drive. Gmail no longer allows username/password logins from third party apps, so I got a warning instead. Without IPv6, I would have just chalked it up to a misbehaving device and ignored it since it came from my own IP, but because of IPv6, I was able to see it was from the NAS and investigate further.