5 ms·
Google definitely uses IPv6 internally (ie office WiFi is now using IPv6 only (with the router doing translations to IPv4 if the site doesn’t support IPv6) and
by Yeri 6y ago
Google definitely uses IPv6 internally (ie office WiFi is now using IPv6 only (with the router doing translations to IPv4 if the site doesn’t support IPv6) and afaik most of the servers in the datacenter/clusters are IPv6 only now as they ran out of IPv4 LAN IPs for their clusters.
I just think that there’s little demand on cloud (and tons of other high prior work)
- jiggawatts 6y agoThere's little demand for half-baked support. There would be a lot of demand if IPv6 wasn't an "also ran", a "tack on", some checkbox to tick. Think about how much network complexity would simply vanish if everything used only public routable IPv6 ranges. No more split DNS. No more NAT gateways. No need for a separate "public IP" and "private IP". No need to carefully "carve up" the 10.x.x.x range to carefully avoid overlaps... even with future business partners. No need to worry about the "size" of subnets or accidentally running out of addresses in the cramped /24 subnets most people allocate. It goes on and on. And on. But none of that is possible in the public cloud, because it is IPv4 first, and 99% IPv4 by default, and if there's IPv6 support, it's broken, or incomplete, or half-arsed.
- johannes1234321 6y agoLooking at the number of unprotected databases (see i.e. https://news.ycombinator.com/item?id=23957510 https://news.ycombinator.com/item?id=23957510) I think it's good that cloud providers push for gateways etc. in order to restrict access on network level. (They still could do IPv6 proper - no argument there)
- throw0101a 6y ago> I think it's good that cloud providers push for gateways etc. in order to restrict access on network level. If the default security group for IPv6 only allows SSH and ICMPv6 to an instance/host, what difference does it make? * https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-security-groups.html https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-secu... It's not the NATing that gives (internal) networks security, it's the stateful packet inspection at the gateway and--more and more--at the host level.
- jiggawatts 6y agoNobody said there wouldn't be ACLs or firewalls in an IPv6 network. IPv4 NAT provides security as a side effect. You don't need NAT for security. PS: This is the #1 most common argument trotted out against IPv6, and it is blatantly false.
- dijit 6y agoNAT doesn't do much if anything for security at all, as soon as there's an outbound connection the internet has a port mapping back to your host. https://www.f5.com/services/resources/white-papers/the-myth-of-network-address-translation-as-security#:~:text=Static%20and%20destination%20translation%20of%20hosts%20provides%20no%20security.&text=While%20it%20is%20true%20that,methods%20to%20circumvent%20the%20NAT https://www.f5.com/services/resources/white-papers/the-myth-....
- Dagger2 6y agoYou don't even need an outbound connection. If your router receives a packet with a dest IP set to one of your LAN machines, it'll be routed to that LAN machine. NAT does nothing to stop that, and thus does nothing for (this aspect of) security.
- dungdang 6y agoof course it does nothing to stop it, because you start your scenario after the stop has been made. you don't know the ip of the lan machine. the public machine receiving it's outbound packet doesn't either. but here's your simple test for the home of why nat helps with security. take a winxp machine. connect it to your lan. come back tomorrow. it's not infected. now connect it to the wan and wait about 2 minutes. you have several viruses. then, go back here, and tell us how despite nat protecting you from viruses, it does not. then we'll all laugh. you lock your door. but a guy can pick the lock. so why do you lock it? in the real world, nat adds security. wep for wifi is enough security for your home lan. and dvd encryption works for preventing copying. just like your house key. by reducing the attack surface by 99%. but i know i won't convince you, so stay with your opinion. but apply it also to vaccines.
- Dagger2 6y agoAs a side benefit of v6, it makes it harder to find unprotected machines due to the vastly increased address space. Obviously that doesn't make those machines secure, but an insecure machine that hasn't been exploited is better than an insecure machine that has.