5 ms·
This[0] change is interesting for home deployments of IPv6: If your ISP changes advertised prefixes occasionally (which mine does), it was until now not practic
by zonefuenf 5y ago
This[0] change is interesting for home deployments of IPv6: If your ISP changes advertised prefixes occasionally (which mine does), it was until now not practical to assign/use addresses with fixed host suffixes, e.g. for internal services, because you couldn't write firewall rules using those addresses (part of the address could just change and there's no automatic update of the rules).
The change now enables you to write firewall rules that use a placeholder for the ISP-assigned prefix. The rules should update automatically after a prefix change.
(What has always worked is using the fc00 or fd00 address spaces for local fixed assignments, but pfSense has had problems with that setup as well in my experience)
[0]: https://redmine.pfsense.org/issues/6626 https://redmine.pfsense.org/issues/6626
- globular-toast 5y agoThat's good, but it's so frustrating that ISPs can't just give out a permanent address range for the lifetime of a subscription. Imagine if your telephone number changed occasionally. It's ridiculous. Some are continuing to charge for a "static IP address" under IPv6 as if they are scarce or cost them anything to implement.
- zinekeller 5y agoI believe it's more of a) some carrier-grade routers basically not supporting static IPv6 unless IPv4 is also static (don't ask why it's like that, some NOCs also deal with buggy CG and CPE firmware in general) b) deliberately done, because in those countries privacy concern in residential connections is paramount.
- SV_BubbleTime 5y agoWhile the phone number analogy does make sense on the surface, I have to agree, I don’t want my IP to be static for privacy reasons. It’s not a great barrier, but I don’t want the bare minimum skills advertiser, hacker, MPAA consultant, web store, or whoever being able to easily rely on this IP being me. Yes. There are tracking cookies, and fingerprinting, and whatever, but the bar being set this higher is better than lower. The phone analogy makes sense until you realize you’re actively calling everyone all the time, and the callerid shouldn’t be easily readable. It’s not like phones at all really.
- globular-toast 5y agoYou'll get a /64 so you'll have more than enough addresses (2^64) to play with if privacy is a concern.
- zinekeller 5y agofacepalm In residential connections, every marketer will just figure out that particular AS gives /64 (or /56 or /48) and bundle them up, like how they use IPv4 address to track families.
- Arnavion 5y agoIndeed, stuff like IP blacklists, tracking, etc should never consider anything smaller than a /64, because it's trivial for the target to change its IP within that space just with SLAAC.
- AnIdiotOnTheNet 5y agoAbout damn time. Now if only they would fix their completely broken Dynamic DNS update implementation so I wouldn't need to write a cron job to make it work properly...
- throw0101a 5y ago> If your ISP changes advertised prefixes occasionally (which mine does), it was until now not practical to assign/use addresses with fixed host suffixes, e.g. for internal services This is actually one of the use cases where 'private addresses' make sense: when you don't have a static assignment but need static addressing. In the IPv4 it's very unlikely that you'll get a static address unless from ARIN/RIPE/etc (or pay US$ 25+/IP on the open market), so we have everyone using 10/8 with NAT. It's quite easy for someone to get a statically assigned IPv6… unless you're a home user. So if you want static address, use the IPv6 equivalent of 10/8, ULA: * https://en.wikipedia.org/wiki/Unique_local_address https://en.wikipedia.org/wiki/Unique_local_address Then you NTPv6: * https://en.wikipedia.org/wiki/IPv6-to-IPv6_Network_Prefix_Translation https://en.wikipedia.org/wiki/IPv6-to-IPv6_Network_Prefix_Tr... * https://datatracker.ietf.org/doc/html/rfc6296 https://datatracker.ietf.org/doc/html/rfc6296 * https://docs.netgate.com/pfsense/en/latest/nat/npt.html https://docs.netgate.com/pfsense/en/latest/nat/npt.html The interface portion of the IPv6 address (right-most 64b) stays the same, and only the prefix (left-most 64b) gets shuffled as they pass through the gateway.