7 ms·
Unfortunately only a /64 per server :/
by mfontani 5y ago
Unfortunately only a /64 per server :/
- sneak 5y agoThat's normal/standard for a whole LAN, and is more than enough for all of your VMs/containers on the box.
- xnyanta 5y agoNo, it's not enough because you end up needing Proxy NDP for your traffic to reach other subnets smaller than a /64 (e.g. a /80) if you have the /64 on your wan interface and carve it out. Normally, you'd have a /64 on your wan, then another /64 for your containers or multiple /64s for different container deployments or virtual machines. Then traffic would route properly between your networks with ipv6 forwarding enabled.
- sneak 5y ago> is more than enough for all of your VMs/containers on the box > you end up needing Proxy NDP for your traffic to reach other subnets smaller than a /64 (e.g. a /80) if you have the /64 on your wan interface and carve it out It sounds like we are in full agreement.
- Dagger2 5y agoIf you're using proxy NDP then you don't have "more than enough" IP space for what you're doing. You have none and you're hacking up a workaround -- one that's inevitably going to have people coming away thinking "v6 is hard" rather than putting the blame where it deserves to be.
- WesolyKubeczek 5y agoWhat would you do with all those addresses? Could you please elaborate about each one?
- edm0nd 5y agoFirst thing I can think of is spam and abuse
- formerly_proven 5y agoGood luck sending emails with IPv6.
- profmonocle 5y agoIt works fine with Gmail. And since G Suite is so widely used, tons of domains can send/receive mail over IPv6 just fine.
- vaylian 5y agoWhy should that be an issue?
- erinnh 5y agoSome mail-admins will downgrade IPv6-only MX servers reputation-wise, due to the limiting/cost-increasing factor of IPv4 Addresses.
- BenjiWiebe 5y agoI do it already. Well, both IPv4 and IPv6. There's a decent number of IPv6 capable MX's out there, the most prominent being GMail. If you were meaning IPv6-only then yes that would be pretty bad.
- profmonocle 5y agoIf an IPv6 spam filter is working on a per-address basis, it's never going to work. The smallest allocation you can get from a RIR is a /48. Even residential ISPs give at least a /64. You could use a different address for every email and never run out.
- fuzzy2 5y agoA /56 + prefix delegation would enable IPv6 VMs without any dirty hacks.
- RexM 5y agoIs that not enough? I was curious how many IPs that'd give you, and it is 2^64 Genuinely curious what you might need more for (for a single server).
- momothereal 5y agoIt's about having multiple continuous ranges of addresses. Think of it in IPv4 terms, it's like having the range 192.168.0.0 to 192.168.0.255 (192.168.0.0/24) assigned to your host. 256 addresses should be plenty of addresses, but you can't cleanly segment them into multiple ranges, like you could with 192.168.0.0/16: because you can have 192.168.0.0/24, 192.168.1.0/24, 192.168.2.0/24. By having multiple, complete blocks of /24, you can easily assign them to different classes of IP interfaces on your host.
- nightpool 5y agoWhy not? Couldn't you just assign e.g. 192.168.0.0/26, 192.168.0.64/26, 192.168.0.128/26, 192.168.0.192/26?
- ISO-morphism 5y agoYes, you can, but there's a bit more mental math involved for a human looking at it, and more truthfully it's just less aesthetically pleasing.
- igjeff 5y agoNothing in IPv6 says you have to stop dividing at the /64 level. There has been some hardware that takes a bit of a performance hit when doing route lookups that are longer than /64 in the past, but if you're doing this all in software on an end host, that's not an issue. Go ahead and divide up that /64 to smaller blocks for your classification purposes, you'll still have plenty.
- hansel_der 5y ago> Nothing in IPv6 says you have to stop dividing at the /64 level. but as you mentioned, there are a few roadblocks that say: you shouldn't
- deleted 5y ago[deleted]
- dxld 5y agoYou can actually request a /56 per-server for a one-time fee of, IIRC, 60 EUR or so. Just talk to support since it's not listed anywhere in their docs for some reason.