10 ms·
Creating a Home IPv6 Network
- nix23 6y agoSlashdot https://web.archive.org/web/20200920202328/https://blog.hansenpartnership.com/creating-a-home-ipv6-network/ https://web.archive.org/web/20200920202328/https://blog.hans...
- Jaruzel 6y agoWe like to call it a 'Hug of death' around here :)
- selfhoster11 6y agoI don't think software is there yet for creating a home IPv6 network. Docker doesn't have good IPv6 support, for instance. It felt like going back to the stone ages of IPv4 and specifying all IP addresses manually vs doing some kind of DHCP-like automatic assignment like IPv4 does. Maybe it's possible, but I haven't been able to get it to work.
- how_gauche 6y agoYou're supposed to use DHCPv6 or Neighbor Discovery -- like everything else in IPv6-land, it's significantly more complicated than it is over IPv4. I don't run the whole network IPv6 -- for hosts I care about having an IPv6 egress for, I use a Wireguard tunnel in IPv6 private address space to a bastion host. If I want to expose a port, I forward it from the other side. It's a sad state of affairs :-(
- gertrunde 6y agoI'm not sure it's that much more complicated as such, beyond being different/unfamiliar. Just setting up SLAAC is very straightforward, probably (ignoring any unfamiliarity issues) more simple than DHCP? Pulling addresses from your service provider via prefix delegation can be a bit funny, and could do with being a lot more polished. Instructions/community support in particular can be problematic as ISPs tend to use different prefix lengths, rather than just standardising on /56. And also less relevant if you have a static allocation, which is potentially more likely with IPv6 than IPv4. And DNS becomes more important, as does firewalling, no more relying on the somewhat dubious NAT safety net.
- Havoc 6y agoIs your wireguard ipv6 setup a security consideration or working around a technical issue with your ISP? My ISP seems to have ipv6 out of the box, but a little worried about security given it's NAT-less nature
- how_gauche 6y agoIt's mainly so I can "road warrior" to my internal resources from my laptop transparently. IPv6 is a good choice for this since it won't conflict with any NAT address space you're likely to be on.
- xfalcox 6y agoDocker works fine with IPv6. Don't get me wrong, it had it's fair share of bugs over the years, but recent releases are in a usable shape.
- selfhoster11 6y agoIt didn't work for me on my IPv6 ISP, until I started assigning addresses manually. It felt like a big step back. I wasn't willing to waste more time on research, so I decided to go with IPv4. For a home network/SME-scale, I don't see the value proposition of IPv6. It takes time to retrain staff, incurs hardware and software replacement costs in some cases (not to mention licensing changes from vendors) and ties up developer/IT time during the process of upgrading and troubleshooting IPv6 teething issues (as I've found in my case). The outcome is that the network can now handle more addresses and more advanced workloads, but becomes harder to maintain. Most home/SME-scale networks don't need even half of the 10.0.0.0/8 address space and don't take advantage of the new features, so it becomes pointless to upgrade unless you outgrow IPv4's capabilities or know you're on track to doing so.
- Leo_Verto 6y agoDocker doesn't support Prefix Delegation which makes it unusable on home networks with dynamic ipv6 prefixes. What worked for me was running https://github.com/robbertkl/docker-ipv6nat https://github.com/robbertkl/docker-ipv6nat which allows you to run containers with NATed ipv6 addrsses exactly the same way you'd run ipv4.
- deleted 6y ago[deleted]
- bzb5 6y ago> One of the recent experiences of Linux Plumbers Conference convinced me that if you want to be part of a true open source WebRTC based peer to peer audio/video interaction, you need an internet address that’s not behind a NAT. ...or upnp and pcp, which work out of the box.
- milankragujevic 6y agoUPnP is completely useless for CGNAT, and PCP would work only IF the CGNAT gateway would support it, which most don't (or it's disabled). I don't think great difficulty about NAT is concerning CPE NAT, i.e. your local network, as it's trivial to forward ports (or port ranges) manually. Most problems are with CGNAT, i.e. on mobile broadband or some cable and DSL providers.
- bzb5 6y agoWhere I am there are more isps that support pcp than isps that support ipv6 at all (zero)
- milankragujevic 6y agoWhere I am the number of ISPs that support PCP is the same as the number of ISPs that support IPv6 - zero. My point wasn't that IPv6 is currently the answer, my point was that it's impossible to host anything or be reachable by anyone for A LOT of people in the world.
- xxpor 6y agoUsing CGNAT while not offering IPv6 at all is professional malpractice.
- cassianoleal 6y agoGood luck if you're behind CGNAT on IPv4, which an increasingly high number of people are.
- bzb5 6y ago
- zonefuenf 6y agoSadly, depending on the ISP, the prefix is not necessarily static and may change on reconnect (for example, Deutsche Telekom will only keep the prefix static for business accounts). This is completely arbitrary and makes relying on GUAs for internal addresses problematic. It’s too bad that we are inheriting the static IP policies from IPv4, because ISPs want to upsell.
- anthropodie 6y agoSame thing is happening with Jio in India. Is it possible that this is happening because Jio is mobile network. I think I read somewhere that mobile phones are not provided static IPs.
- tormeh 6y agoWould make sense for routing if the first n bits are common to the cell tower. Static IPs for phones would result in slower and more expensive routing, as we can't use prefixes for routing anymore.
- magicalhippo 6y agoI've had my IPv4 address from my cable ISP for years. They give me a new IPv6 prefix every time my cable modem loses connection. For privacy I think it would be nice if the IP/prefix isn't fixed per household for long periods of time, but there seems to be a lot of IPv6 software out there designed with the assumption that the prefix is static.
- lizknope 6y agoMostly the same here. My cable modem IPv4 address would stay the same for about a year. It only changed when we had an extended power outage of more than 6 hours about once a year during a bad storm.
- redprince 6y agoThere's also a privacy argument here. Changing prefixes makes user tracking harder. That's about the only win for the user. I for one would have preferred to have a choice. I would accept the privacy issues for a static prefix in return. Supporting a dynamic prefix in a not so typical home setup is a PITA.
- quaintdev 6y agoMy hometown does not have wired Internet but fortunately 4G is available. So I decided to share my Android Internet using a WiFi router. I had a Raspberry Pi lying around and decided to put it to use for this. All I had to do was tether USB to raspberry PI and connect PI to the router over Ethernet. I had working Internet connection in first attempt only to realize after some time that it was only IPv6 websites that worked. I had to touch router configuration to fix IPv4. IPv6 seems to solve lot of networking issues. It's a pity that the giants[1] still haven't implemented it. [1]: https://github.com/quaintdev/awesome-no-ipv6-websites https://github.com/quaintdev/awesome-no-ipv6-websites
- thedanbob 6y ago> The problem is how do you know how many subnets the ISP is willing to give you? Unfortunately there’s no way of finding this This was by far the most frustrating part of configuring IPv6 on my home network. Every IPv6 guide out there assumes you already know the PD size for your ISP, and I couldn't find any tool that would let me test different sizes. Even if I had known > you can run odhcp6c manually with the -P option if you have to probe your ISP to find out what size of prefix you can get , I don't have an OpenWRT router so that wouldn't have helped me. In the end I just had to guess and hope that if it didn't work it was in fact the wrong PD size and not some other misconfiguration on my part.
- Smar 6y agoIf I’m not wrong, can’t you just listen router advertisements to get correct subnet? I just configured similar setup using RA and DHCPv6 for my personal network.
- thedanbob 6y agoI don't know, and I wouldn't know how to do that either. In the end I found out that if I monitored the dhcp6c.log file on my router and tried different PD sizes I could see whether it was working or not.
- Dagger2 6y agoYou can listen to RAs on your router's WAN interface, which may tell you the WAN subnet, but they won't tell you anything about the routed prefix which is what you use for networks on the LAN side of the router. The only way to get any info about that is to do DHCPv6-PD requests (or ask the ISP).
- takeda 6y agoHmm, I thought these prefixes a subset of the CIDR provided through RA on WAN? I am kind of in similar situation as parent poster. My ISP supposedly provides IPv6, but from the RA announcements it looks like it is /64. My assuption was that I supposed to split it myself into smaller pieces. It's also sucks since they are providing /64 which is the smallest CIDR that SLAAC requires. When I called my ISP they said that I only have IPv4, so it's not like I can get much help with IPv6. Although I know IPv6 works, because when I connected a box and told it to configure itself through RA it did and I was able to ping ipv6 hosts.
- kenada 6y agoThis is a pretty decent overview of IPv6 on a home network. Here are some other things I learned when doing something similar recently on my home network (except the router is a FreeBSD box). - You can run `dhclient` interactively to learn the size of the prefix your ISP delegates. The OP touches on this, but the solution is OpenWRT-specific. Most distributions include `dhclient` or have it packaged. - It’s possible that the IP your ISP assigns your router is in a different prefix from the prefix it delegates to you. For example, my ISP for a while assigned an IP in 2607::/16 while delegating a /56 prefix in 2605::/16. - Prefixes can also change. When I switched my router to FreeBSD, I started getting a /56 prefix in 2607::/16 instead of 2605::/16. - Some systems (e.g., Windows 7) don’t support getting DNS via router advertisements. If you want to support them, you need to run a DHCPv6 server and advertise that other stateful configuration is available. - Kea is the successor to the ISC DHCP server. I found it a bit nicer and more flexible to configure. - On Linux, NetworkManager and systemd-networkd handles a lot of this stuff automatically, but your customization options are limited. I couldn’t find a way to do the above without having to do things manually myself. - FreeBSD’s DHCP client in base does not yet support DHCPv6. To get an IP and a prefix, you need to install one from ports. I’m using dhcp6c, following this guide[1] to set it up. - ICMPv6 is integral to IPv6, but if you want to filter it, follow the advice in RFC-4890. Filtering ICMPv6 incorrectly will mess up your network in weird ways (e.g., my MBP could get an IP but wouldn’t get a DNS server until I fixed the problem). - IANA maintains a registry[2] of IPv6 multicast addresses. I found this helpful when writing firewall rules. - When advertising LAN services over DNS, make sure you use the “secure” or “template” IP and not the temporary IP used for IPv6 privacy. Also, you can’t assign domain names to link-local addresses, but you can advertise a DNS server (via RA and DHCPv6) on one. - mDNS is the exception to the above. Avahi and Bonjour advertise link-local address and are able to resolve them properly. [1]: https://vladvasiliu.com/post/20180827-0922-ipv6_prefix_delegation_freebsd/ https://vladvasiliu.com/post/20180827-0922-ipv6_prefix_deleg... [2]: https://www.iana.org/assignments/ipv6-multicast-addresses/ipv6-multicast-addresses.xhtml https://www.iana.org/assignments/ipv6-multicast-addresses/ip...
- takeda 6y ago> FreeBSD’s DHCP client in base does not yet support DHCPv6. To get an IP and a prefix, you need to install one from ports. I’m using dhcp6c, following this guide[1] to set it up. Colin Percival made it a bit easier (IMO)[1] it is meant for AWS EC2 but worked for me with my ISP as well. The guide you submitted probably will work everywhere. [1] http://www.daemonology.net/blog/2017-01-26-IPv6-on-FreeBSD-EC2.html http://www.daemonology.net/blog/2017-01-26-IPv6-on-FreeBSD-E...
- ncmncm 6y agoIs there an easy way to discover whether your ISP would support v6? Eg run a dhcp6 client and see if it gets an address? Verizon fiber has been talking about v6 for a long time, and at least some have it, but they don't provide any sort of map.
- oofnik 6y agoThanks, this was immensely informative. Please consider contributing to the OpenWrt wiki IPv6 page: https://openwrt.org/docs/guide-user/network/ipv6/start https://openwrt.org/docs/guide-user/network/ipv6/start