8 ms·
I’m confused. Can I use this in an IPv4-only environment (i.e. my Stone Age ISP)?
by jagger27 5y ago
I’m confused. Can I use this in an IPv4-only environment (i.e. my Stone Age ISP)?
- Aloha 5y agoIt appears you can. https://p2p.nat64.dk/help https://p2p.nat64.dk/help
- jagger27 5y agoYes I read that and that’s why I’m confused. > In order to run an IPv4 peer you need access to IPv4 which can be through one or more layers of NAT. Before installing the software you should ask your network provider for a routed IPv6 prefix. If the provider gives you a functional /60 or shorter prefix free of charge I recommend that you make good use of that and do not install the IPv4 peer. If my ISP gave me a functional IPv6 prefix I wouldn’t be bothering with this.
- dundarious 5y agoThat's what that text is saying. If you have v6, just use it (and maybe run a v6 peer instead). If you _don't_ have a usable v6 prefix, then continue with the instructions.
- jagger27 5y agoOk.
- wmf 5y agoNo, this is a workaround for people who don't have IPv4. If you have IPv4 you don't need this. It's for people on broken IPv6-only networks (i.e. basically nobody).
- DarylZero 5y agoHuh? Almost all people have "broken" IPv6-only networks -- their computers don't have IPv4 addresses and must use NAT to access remote IPv4 nodes. The only routable IP address on a typical home computer is IPv6.
- mindslight 5y agoEven in your paradigm, NAT is a mitigation for a security deficiency of IPv4 (servers get too much visibility into client identity). Rather than relying on each node to implement "privacy extensions" on its own, I think it makes sense to keep up v6 NAT for outgoing connections. For example, distribute every outgoing connection from a network to be uniform over the full address space + port. (There may be even better strategies, like emulating a certain number of discrete devices. But you get my point)
- DarylZero 5y agoNAT isn't a security feature. It's forced on users when their ISP only allocates one IPv4 address per site.
- mindslight 5y agoNAT has been forced on users. But NAT is also a security feature. I'm not talking about the implicit stateful firewall that could just as well be explicitly deployed for a whole subnet. Rather I'm talking about hiding as much information as possible about devices on your network. If you have a /28 with an IP for each computer on your network, then surveillance companies can build separate profiles on your desktop, your laptop, your wife's laptop, your kid's laptop, etc. When they're all behind a single IP, then they lose those bits of information. Higher level protocols can leak much more information, but it's better to address the problem at every level rather than giving up.
- DarylZero 5y agoThat's a rather useless form of "security." It's not even going to be effective in preventing the machines running web browsers from being distinguishable, if that's a real concern.
- dundarious 5y agoThat's wrong. Note the last bullet from the /why page: > The primary purpose of this service is to encourage deployment of IPv6. The primary method this service uses to encouraging deployment of IPv6 is to lend a helping hand to two groups of users. > * Users of IPv6-only networks who need NAT64 in order to reach legacy services. > * Users who due to no fault of their own is stuck on an IPv4-only network behind NAT.
- wmf 5y agoAll the instructions require IPv6 so ¯\_(ツ)_/¯
- dundarious 5y agoYou know what, on second thought, I think you're totally right and I'm totally wrong. I had this marked down as something to help me out because I only have 6to4 from my ISP, and I often get at least one relay that's broken. But NAT64 _is_ primarily for v6 access to v4. As far as I can see, running a v4 node just adds another endpoint to the network for those v6 people to use.
- progval 5y agoNot these ones: https://p2p.nat64.dk/v4peer https://p2p.nat64.dk/v4peer And also, https://p2p.nat64.dk/why https://p2p.nat64.dk/why mentions: "IPv4-only users contribute by providing a communication path to IPv4-only services. In return they get external reachability of their host by having an RFC 1918 address which can be reached through NAT64. That means the IPv4-only peer is now reachable through a static IPv6 address even though it started out having only IPv4 access tyhrough NAT. "
- dundarious 5y agoWould be great to have an explanation of how that works. Where is that v6ified rfc1918 address specified? Does that mean a v6 host running v6peer can just ping that rfc1918 address and get to the v4peer behind a NAT?
- progval 5y ago> It's for people on broken IPv6-only networks (i.e. basically nobody). It's for people on any IPv6-only networks. They are few, but are growing in numbers; ideally the whole internet will one day, and this could help. Not to mention it is cheaper to get servers without IPv4 connectivity, eg. https://news.ycombinator.com/item?id=29471986 https://news.ycombinator.com/item?id=29471986
- cmeacham98 5y agoYou can help the network by running an ipv4-only node. The people that benefit from this help are people on ipv6-only networks.