3 ms·
No such thing as a "NAT firewall"... and v6 was designed this way because nothing else really works. Almost all existing code that was written to handle v4 was
by Dagger2 4y ago
No such thing as a "NAT firewall"... and v6 was designed this way because nothing else really works.
Almost all existing code that was written to handle v4 was written to handle addresses of exactly 32 bits, not addresses of arbitrary length. Longer addresses therefore required writing new code to handle them. v6 is close enough to v4 that you can write code that can handle both families, but neither the existing code or the new code was under the control of the people designing v6.
You use dual stack because it's maximally compatible with existing devices and code. There are plenty of ways to run single-stack v6 if you want to, but they all have some compatibility issue or another (and the compatibility issues stem from the way v4 was designed, not the way v6 was designed).
v6 addresses use : rather than . because they could otherwise be confused with DNS. For example, a string ending in ".be" could have been a v6 address or a subdomain of the .be ccTLD.
IP packets do start out with a version field, so your "one if-then to identify the packet type" requirement is exactly what v6 already does.
> Or simply have the ipv4 as the first part and the wrapped packet has another 128-256 addressing bytes.
You've invented 6to4. It already exists, but people seem to prefer native.