8 ms·
Two things that come to mind are running out of private address space (a /8 isn't that large), or wanting address space that doesn't clash with other private ne
by Denvercoder9 5y ago
Two things that come to mind are running out of private address space (a /8 isn't that large), or wanting address space that doesn't clash with other private networks (e.g. to ensure a VPN doesn't overlap with home networks). There's probably more reasons.
- VLM 5y ago> running out of private address space Classic merger "solution". Company A uses 10/8 Company B uses 10/8, company A buys company B and orders new subsidiary B to renumber into 11/8 "All you have to do is change every first octet to 11"
- woleium 5y agoor, you know, use NAT to do so :)
- kenniskrag 5y agoor upgrade to ipv6 :)
- ratsmack 5y agoor maybe ask the question regarding why we're not all running ipv6.
- kenniskrag 5y agowhy?
- vxNsr 5y agoBecause ipv6 is hard and NAT works well enough.
- rswail 5y agoIPv6 on an internal network is trivial. It is supported by both Windows and MacOS (and Linux) out of the box. If your ISP doesn't provide it, get one that does. They should allocate you a /56 by default per connection, if not something larger like a /48 if you have multiple locations. Subnet the /48 for each connection, subnet each /56 into /64 subnets. reserve one of the /56's for site-to-site if needed. Done.
- trulyme 5y agoIpv6 is like python3. A worthy upgrade, but tried to do too much in a single coup and broke backwards compatibility. If they simply added two top octets, saying that 0.0.... was the old ipv4, everyone would have used it ages ago. Instead they made other improvements which led to complex standard and worse adoption.
- cesarb 5y ago> If they simply added two top octets, saying that 0.0.... was the old ipv4, everyone would have used it ages ago. How would you "simply add two top octets"? The address fields in the IPv4 header are a fixed size of 32 bits. Every time this is discussed, someone comes up with this suggestion to "just make the addresses longer and change nothing else", but there's no way to make the addresses longer without changing something else. And that's before considering compatibility with older hosts or routers; how would an old host talk to a new host, or two new hosts talk one to another with an old router in the path? In the end, what you'd have would be two separate networks, with some hosts being in both networks, which is exactly what we have with IPv4 and IPv6.
- yjftsjthsd-h 5y agoYes, obviously you need a new wire format and bigger addresses; that was always going to change. What did not need to happen was changing/replacing DHCP, routing changes, and a half-hearted attempt to bake in IPsec.
- 5y ago
- accountofme 5y agoIts incompatible with IP v4, has a stupid addressing scheme, it requires new router hardware and software for isps to buy and nobody is using it because of all the aforementioned issues.
- salawat 5y agoYou forgot, they're nowhere as easy to remember as v4. If you're used to remembering phone numbers; important v4 IP's aren't that hard to mentally internalize. Screw DNS. Screw the recommendation to stay away from IP's. If it's important enough to be on the network, it's important enough to have a static IP.
- mayama 5y agoYou're being downvoted, but, last 3 ISP's I used didn't support ipv6. First one didn't support ipv6 at all, second supported it, but was incompatible with my router. And I didn't care about it after that. Hardware incompatibility is a huge roadblock for ipv6.
- Dylan16807 5y agoWhat could an increase in the IP address space do to be compatible? I can think of a couple things to be partially compatible but IPv6 already does those. And by "stupid addressing scheme" do you mean it's too big, or what? You can ignore all that stuff with mac addresses and make all your addresses go like prefix:subnet::1 prefix:subnet::2 prefix:subnet::3 if you want to.
- icedchai 5y agoIPv6 is well over 20 years old. In fact, IPv6 is now older than the IPv4 Internet was when it went mainstream back in the mid 90's. There is really no excuse not to support it...
- mrweasel 5y agoBecause even equipment that claim IPv6 often doesn’t. We have seen both software and hardware which “supported” IPv6 for 5 - 10 year, but we’re the first to use it in production and the manufacturer haven’t tested it since the initial implementation.
- WanderPanda 5y agohow would nat help in this case?
- xxpor 5y agoIf they're not actually using the whole /8 (highly likely), you can setup a 1:1 NAT. basically from network b, if you want to talk to network a, you find out the address in 11/8 that corresponds to the 10/8 address and vice versa. You can use split horizon dns to make it mostly transparent. Every networking problem in the world can be solved with more NAT or more encapsulation :)
- jandrese 5y agoYou don't have to use every address in 10.0.0.0/8 to effectively fill it up. If your corporate policy is to assign a /16 to each floor of a building, and you have a LOT of buildings it's pretty easy to fill up the space even if most of the /16s are sparsely populated. It's much easier to move on to the 11. space when you build that new building that pushes you over than renumbering your entire corporate LAN.
- xxpor 5y agoRight, but that's not relevant for 1:1 NAT (well, at least it doesn't have to be). Since the NAT would happen in software, you're no longer constrained by subnets being physically under routers. 11.2.3.0/24 could contain 10.0.1.0/24 and 10.128.128.0/24 without any issues, assuming they don't use in total more than 256 address.
- woleium 5y agowhat you call 1:1 NAT is just called NAT by cisco, the stuff most folks think NAT is is actually NAT+PAT (like what you run on your home router with a single public IP)
- xxpor 5y agoexactly, that's why I specified.
- sk1ppy 5y agoMerger after merger after merger followed by a massive adoption of public cloud (using Direct Connect/Express Route for hybrid connectivity) has led at least two very large FinServs I worked for adopting CGNAT (100.64/10) for parts of their internal networks. In both cases RFC1918 was used throughout their global network and while not fully used, had become highly fragmented over time.