6 ms·
Can we let IPv4 and NAT die already?
by staringback 4y ago
Can we let IPv4 and NAT die already?
- greyface- 4y agoNo. Even in IPv6-only-land, multihomed networks without PI space will have good reason to NAT.
- ArchOversight 4y agoIf you generate a ULA address using the algorithm that is recommended the likelihood of a collision in IPv6 addressing space in networks is absolutely miniscule.
- greyface- 4y agoIf you're using ULAs, you don't NAT to avoid addressing collisions; you NAT so that your traffic is routable on the Internet. If you try to pass traffic sourced from a ULA to your upstream without NAT, it or its response is going to get dropped on the floor.
- ArchOversight 4y agoYou wouldn't route traffic over the NAT using ULA to the outside world. You'd use GUA space for that. Collisions between two private networks is very low was my primary point, and thus NAT is not a thing that needs to exist.
- greyface- 4y agoYes, exactly. And if you have two upstreams, there's no single GUA prefix that makes sense to use in all situations. You make your routing decision, then you NAT (er, sorry, NPTv6, which is Totally Not The Same Thing As NAT) to the GUA prefix corresponding with the network that you're egressing from. If you don't need Internet connectivity, yes, NAT-free ULAs work fine.
- akira2501 4y agoNAT requires kernel connection tracking. NPT explicitly does not. There's a lot of useful implications to this.
- greyface- 4y agoStateful NAT requires kernel connection tracking. Stateless NAT does not, and is still a form of NAT. It's sometimes used in IPv4 networks, even!
- akira2501 4y agoDidn't you mean stateful NAT when you were making the comparison?
- greyface- 4y agoThat wasn't my intent, but I see how it reads that way now. The parenthetical was me griping about naming, not meant to update the meaning of the sentence. In the dual-upstream scenario, I'd use stateless NAT with a single on-link prefix (GUA or ULA).
- labcomputer 4y ago> you NAT so that your traffic is routable on the Internet Erm... why the hell would you use NAT for that? One of the features of IPv6 is first-class support for multiple IP addresses on a single interface. Your interface should have a one (or more) routable IP addresses that should be used for packets traveling to the public internet and one (or more) ULAs for reaching internal networks.
- greyface- 4y agoThis is how it was envisioned, yes, but in practice there are issues with source address selection when you have multiple prefixes on-link for multihoming purposes. See https://www.rfc-editor.org/rfc/rfc5220 https://www.rfc-editor.org/rfc/rfc5220 for a description of the problem.
- throw0101c 4y ago> If you're using ULAs, you don't NAT to avoid addressing collisions; you NAT so that your traffic is routable on the Internet. Note that "IPv6 NAT" really should be NPTv6: * https://en.wikipedia.org/wiki/IPv6-to-IPv6_Network_Prefix_Translation https://en.wikipedia.org/wiki/IPv6-to-IPv6_Network_Prefix_Tr... It allows for 1:1 mapping of external IPv6 addresses to internal IPv6 addresses, without the silliness of port mapping and such. Of course your firewall/network device can still have a default-deny rule so that only responses to internally-initiated requests get through. Stateful firewalls are still effective (and were invented before NAT).
- sgjohnson 4y agoBut why would you use ULA addresses for anything other than internal networking? What benefits does it provide exactly? And even for internal networking, why not just use properly addressable IPv6 addresses? Because you're gonna need a firewall either way. I have a couple of /40s to my name. My internal network has an assignment of /48. It's not announced (and is also firewalled off, not that it matters, since there's no routing table entry for it). The chance of collision is nil, because nobody should ever be using addresses within my IP space. Endpoints that require external connectivity simply have 2 addresses on it. One that's routable, and one that isn't.
- greyface- 4y ago> What benefits does it provide exactly? Address stability. If you use the prefix your ISP gives you via DHCPv6-PD or whatever, it might change on you, and then all of your hard-coded configs are wrong. > And even for internal networking, why not just use properly addressable IPv6 addresses? It costs $250/yr (and hours of bureaucracy navigation) to do this in the ARIN service region. If you've got a prefix, it's certainly a good way to use it! But we can't expect everyone to get PI space.
- ninkendo 4y agoI finally decided to learn IPv6 and deploy it on my home network this year, and the lack of stability in the prefix I get from my ISP has been by far the biggest letdown. It basically neuters the whole “you don’t need NAT any more!” dream of IPv6. I’ve taken to having both a ULA prefix and a public prefix for hosts in my subnet, but the public one is basically worthless because it changes seemingly every week. I had to put a ton of effort into making a templated pf.conf updated by a dhcpcd hook so that my firewall rules update automatically, but it’s still a shitshow. When my prefix changes, my router doesn’t seem to want to rescind the old RA’s so now I have two public prefixes floating around and half my hosts can’t get to the Internet any more. I had to drop the lifetime to <1hr to mitigate it but it’s a complete joke. If ipv4 fallback didn’t work I’d have a broken network every week. At this point I’m considering just using NPTv6 and dropping the concept of routable IP’s for my internal hosts altogether. It’s just not worth it. At which point, it’s a stretch to even say IPv6 is worth it.
- MrStonedOne 4y ago[dead]
- groestl 4y agoThis will never happen, I'm afraid :/
- ok123456 4y agoJust give it another 25 years.
- yjftsjthsd-h 4y agoIPv6 started rolling out... let's call it in 2000, which is probably a touch late but close enough, and https://www.google.com/intl/en/ipv6/statistics.html https://www.google.com/intl/en/ipv6/statistics.html puts it at 43% of traffic, but that's positive biased (because it's only traffic on the public internet). So... I'm going with no, as a society we can't and/or won't.
- sgjohnson 4y ago> I'm going with no, as a society we can't and/or won't. But we definitely should. The number of IPv6-only networks is growing by the day. The next generation of tinkerers and internet engineers will have no IPv4 address space at all, because it makes no sense whatsoever paying $14k (at current prices) for /24 of legacy IP address space. Unfortunately, the best we can hope for is for giant corporations like Cloudflare, Microsoft and Amazon to buy up most of the IPv4 space.