4 ms·
Spot on with part 2. Ignore all the folks saying IPv6 is "simple" or works well. I am absolutely no expert, but could get my head around ipv4, but IPv6 - I alw
by tempnow987 4y ago
Spot on with part 2. Ignore all the folks saying IPv6 is "simple" or works well.
I am absolutely no expert, but could get my head around ipv4, but IPv6 - I always end up running into a fuss. I really wish they'd expanded address space to 64 bits, a few other tweaks, and called it good. Maybe call it IPv5? Is there any chance of doing something like this.
So many things that are so trivial or well known in IPv4 are a total nightmare pain with IPv6. Some quick examples:
Internet service providers will happily give you a block of static IPv4 addresses for a price. ATT goes up to a 64 ip address block easily, even on residential. Almost impossible to get a static block of IPv6 in the US.
Let's say you are SMB, you want WAN failover. With IPv4 this is simple. You can either get two blocks of static for your upstream, and route them directly as appropriate to your servers, or go behind a NAT and do a failover option. Whent the failover happens, your internal network is relatively unaffected.
Now try to do this with IPv6? You can't get your static IP's to do direct routing with, and NPT and anything else is a mess, and the latency in having your entire network renumber when the WAN side flaps is stupid and annoying.
In many SMB contexts folks are very used to DHCP, they use it to trigger boot scripts TFTP, zero touch phone provisioning and lots more, pass out time servers and other info and more. The set of end user devices (printers, phones, security cameras, intercoms, industrial iOT) that can be configured and supported with IPv6 is so poor and the complexity is so high.
Not all ISP's offer prefix delegation to end user sites. Because you have an insane minimum subnet size with ipv6 a lot of things that for example you just need two IPs (think separate network for customer premise equipment) now need a 18,446,744,073,709,551,616 addresses.
The GSE debacle means instead of a very large 64 bit address space we got an insane 128 bit address space. Seriously, how about 96 or anything else a bit more reasonable.
Even things like ICMPv6 - if you just let it through the firewall you could be asking for trouble, but blocking it also causes IPv6 problems. Ugh. Oh, it's simpler than IPv4 they say.
- rany_ 4y ago> Even things like ICMPv6 - if you just let it through the firewall you could be asking for trouble, but blocking it also causes IPv6 problems. Ugh. Oh, it's simpler than IPv4 they say. This causes issues on IPv4 as well, the only difference is that a lot of the dirty hacks and workarounds were removed for IPv6 so that people are forced to deploy it properly.
- tempnow987 4y agoFirst, ICMPv6 has more features - and can drive network configuration and reconfiguration. I've seen ICMPv6 stuff for things like discovery, address configuration, PMTU, ARP RARP type stuff, maybe some multicast group management? Where is this in ICMPv4? "forced to deploy it properly" = giant headache. I'm tired of IPv6 folks saying it's a pain in the neck because it's "proper". With ICMPv4 if you really needed / wanted, you could basically drop ICMPv4 at the firwall edge (with TCP MSS clamping etc). And the attack space with ICMPv4 coming through I don't think was TOO bad. When folks say they don't need to filter ICMPv6 for things like RS / RA / NS / NA traffic that seems SO SO sketchy to me.