29 ms·
I spent a week without IPv4 to understand IPv6 transition mechanisms
- amrb 4y agoHe also has a video for the topic https://www.youtube.com/watch?v=e-oLBOL0rDE https://www.youtube.com/watch?v=e-oLBOL0rDE
- speedgoose 4y agoWhy should I spend the time and energy to deal with IPv6 when disabling it fix many issues ? The listed advantages are not worth the troubles in my experience.
- ec109685 4y agoWould have been great if the post quantified the advantages. For networks (order of preference): IPv6 only > IPv4 Only > Dual Stack.
- anderiv 4y agoIt's not so much that the advantages of IPv6 are all that compelling. Rather, it's more that the mechanisms put in place to deal with a nearly-exhausted IPv4 pool (NAT, and CGNAT in particular, etc.) are not great, and any opportunity to negate the need for them ought to be pursued.
- speedgoose 4y agoBut you still need these mechanisms for the time being. And personally, I do like NAT. I'm not a fan of exposing my internal networks to the internet. Having everything hidden behind a single address is neat.
- anderiv 4y agoAs has been discussed ad nauseam, getting rid of NAT does not mean all your hosts are exposed. You would still have a firewall, and managing that firewall is much more straightforward when one doesn’t have to deal with address or port translations.
- speedgoose 4y agoBut my internal network structure will still be exposed.
- api 4y agoI've run dual stack at home and at work for years and have had no issues. You might have issues if you have really old junk that's just broken.
- mynameisvlad 4y ago[flagged]
- speedgoose 4y agoMy current internet provider doesn't support IPv6 so I'm good. I noticed that removing the AAAA records in the DNS configurations of my domains magically fixed a lot of weird network issues reported by the users.
- screamingninja 4y agoIncreased number of available IP addresses, improved security features, simplified network management, reduced network complexity, and support for new technologies. The adoption of IPv6 will lead to cost savings, improved network performance, and increased scalability. Scalability may not matter in the typical home network, but in an enterprise environment, the cost of up-keeping the network backbone is significant.
- everdrive 4y ago>simplified network management I keep hearing this, but it doesn’t seem more simple to me. My ISP won’t reserve me a /48, so I can’t control the management ips of devices on my network. The solution is apparently to set up dynamic dns, which I have no interest in doing.
- screamingninja 4y agoJust split that /64 into smaller /80 subnets. If I were your ISP, I would be upset too. The apparent issue here is that you're falling back to what's familiar- static IP addressing. How about mDNS?
- jlokier 4y agoYou can't use a smaller subnet than /64 for devices that use SLAAC for address allocation. (Unless you're putting them behind an IPv6 NAT, so thry can have their oen private /64).
- CaliforniaKarl 4y agoOr setting up things like stateful DHCPv6: https://serverfault.com/a/714923 https://serverfault.com/a/714923 It's not great, but it's an option!
- everdrive 4y agoI guess what I meant is that my ISP won’t hand out a stable IPv6 allocation. Ie, my entire address range changes weekly.
- ip26 4y agoThe advantage mostly falls to the infrastructure. In theory it performs better, but only marginally, which is quickly overwhelmed by simple issues like inferior routes. As an end user, frankly I stopped caring long ago.
- czbond 4y agoGreat idea. Now a question for the group. What are the non-network team business benefits to IPv6 over v4? That is what drives adoption.
- api 4y agoIPv4 is now stretched to the point that you often end up requiring multiple layers of NAT, such as carrier-grade NAT plus endpoint NAT. That reduces the reliability of pretty much all protocols and makes any protocol doing peer to peer communication really hard or even impossible to run. The latter includes tons of games, video chat, peer to peer VPNs, decentralized social networks, and so on. These problems will only get worse from here on out, but they're not as visible to people outside networking because this degradation of quality of service is a slow creep. The IPv4 Internet just gradually gets more and more limited in capability and less reliable for anything beyond the most basic use cases. IPv4's address space is simply too small. There are already almost twice as many people on Earth as there are possible IPv4 addresses, and that assumes perfectly efficient utilization of IP addresses which is pretty much impossible. In reality there are probably 8-10X as many humans as viable IPv4 addresses. If every human being tends to have a computer and a phone that means there's at least 20X more devices than IPs.
- cesarb 4y ago> If every human being tends to have a computer and a phone that means there's at least 20X more devices than IPs. You know, that used to be only "if every human being tends to have a computer", since phones didn't have an IP address. Now it's "a computer and a phone". A few years down the line, you'll have "a computer and a phone and a watch", then "a computer and a phone and a watch and a standalone VR headset", and so on.
- PeterisP 4y agoI get that there are people in the world with severe lack of IPv4 addresses and this is a valid reason for them to switch to IPv6. However, assuming that I and my organization have enough IPv4 addresses (without requiring any of the tricks of multiple layers of NAT), is there a sufficient reason for us to justify the effort/expense of changing what works?
- cooljacob204 4y agoI recently upgraded my lab and network to support IPV6. I wish I had waited two weeks so I could have read this first.
- deleted 4y ago[deleted]
- soebbing 4y agoI am quite happy that all those shady IoT devices cannot be reached from the internet directly when I am using IPv4 and NAT - what would be the best way forward to keep it that way in a IPv6-only future? The best idea I can come up with (at least right now) is: put all less trustworthy (read: Closed source) devices into a special legacy IPv4 network and only use IPv6 on my workstation and little Raspis?
- nickstinemates 4y agoNetwork segmentation, i.e use of vlans is the traditional way to solve this.
- Godel_unicode 4y agoNot sure why you’re being downvoted, this is a very good answer. Maybe because you left out the implied “and then firewall off that vlan”?
- soebbing 4y agoYeah, it seems to be the common consensus to just block everything going in and just make exceptions, where you really want to offer a service to the internet. Makes total sense, thinking about it. I guess, all those years of just sitting behind a NAT makes one forget all these networking basics if you're not using them regularly. Moving closed-source IoT devices into a special vlan, with some even more rigid rules (something like: only allow http/https traffic into the internal network) might be an additional level of security. Thank all of you for your replies!
- nijave 4y ago>cannot be reached from the internet directly Stateful firewall that allows outgoing connections and blocks incoming (or maybe blocks both) In general, you probably don't want to allow unsolicited incoming connections to any devices, regardless of IoT.
- cnorthwood 4y agoYou'd probably do it in the same way you'd do it with NAT, by using a stateful firewall blocking inbound connections (it's just that you get this for "free" with NAT)
- bittermandel 4y agoIs there any risks of nodes assigning same IP if there's no central DHCP?
- screamingninja 4y agoUnlike in IPv4, in IPv6 there is a lower risk of nodes assigning the same IPv6 address if there's no central DHCP. This is because IPv6 uses a unique interface identifier (IID) that is automatically generated by the node based on its MAC address and a random value. This makes it highly unlikely that two nodes on the same network would generate the same IID and therefore, the same IPv6 address.
- CaliforniaKarl 4y agoFor some time now, it's not unusual for systems to have multiple, publicly-routable IPv6 IPs. Right now my macOS system has four randomly-generated IPv6 IPs, which are being used for internet traffic. New IPs are generated regularly, and old ones eventually get removed. And thanks to Duplicate Address Detection, before a new randomly-generated IP is used, a check is made to ensure it is not in use by someone else.
- ilyt 4y agoNot if you don't have same MAC in the network . SLAAC reserves bottom 64 bits for autoconfiguration, and while incredibly wasteful it does ensure every MAC can have its own IP address
- riobard 4y agoDon't worry coz DAD (Duplicate Address Detection) will come to your rescue :p
- teddyh 4y agoFirstly, normally nodes base their automatic IPv6 address on their MAC address, so there will be no conflict between these, since MAC addresses are supposed to be unique to the hardware. Otherwise, it’s a random 64-bit number (actually a few less bits, but not many). It’s very unlikely a collision will happen. And even if it does, there is a protocol (Duplicate Address Detection) to detect it, and avoid it.
- screamingninja 4y agoThe IPv6 transition is challenging because it requires coordination and cooperation from many different stakeholders, including site admins, CDNs, network designers, and device manufacturers. However, as the author realized, IPv6 is ready for prime time and offers significant benefits over IPv4. Looking forward to the transition to IPv6 for unlock its full potential for a more secure, efficient, and connected internet.
- j1elo 4y agoMicrosoft's GitHub Actions (continuous integration) runner machines do not have IPv6, and cannot be used for things like unit tests that require an IPv6 network interface for whatever thing they are testing. Add that to the list of thousand cuts.
- jhoelzel 4y agoI have built a couple of dual stack Kubernetes clusters already and they work much better to be honest. Most of the problems are solved and especially for node-based-ranges it works really well. Even in ipv6 only mode calico will manage amazingly and so do my OpenWRT routers. HOWEVER, My ISP regularly messes up with its ipv6 routing (deutsche Telekom (so as big as it can get for me) and if that's not the problem, the mesh networks on my (current gen) fritz networking equipment (very widely used in de) eats itself and sometimes just routes my traffic to nirvana. This is especially bad with online gaming services like xbox live, who for the love of themselves don't have a fallback to ipv4 implemented, once ipv6 drops. "i have an ipv6 so I'm gonna use it no matter what". Therefore I have dual stack vpns hooked up to my office network which connect to the datacenters I am using. My private network is ipv4 and sadly will remain like that for a while.
- martinald 4y agoYeah I found the same on Hyperoptic in London. Works fine 99.9% of the time, but occasionally ipv6 drops until I restart the router/restart the WAN connection. Which of course I barely ever notice because most stuff switches back to ipv4. I think unless we start seeing ipv6-only stuff this will be the case, there's really no incentive for a lot of testing/debugging on at least consumer ipv6 connections until stuff actually breaks. Would be cool if Google added a 'ipv4' warning to Chrome similar to how they do with HTTPS (maybe not as strong though). That would drive a lot of adoption.
- miyuru 4y ago> Would be cool if Google added a 'ipv4' warning to Chrome similar to how they do with HTTPS (maybe not as strong though). That would drive a lot of adoption. You can kinda already do this by setting search to ipv6.google.com Images search does not work on that domain, looks like the new Google devs don't know about it.
- cooljacob204 4y ago> My ISP regularly messes up with its ipv6 routing Can you expand on this? I recently upgraded my network to support ipv6 but a big concern I have is what if they (Verizon Fios) change my assigned block? How can I make sure my PI hole and server has the same static IP address?
- TekMol 4y agoI still think IPv6 can be safely ignored. This articles section "here are some reasons you should start using IPv6 within your own network" seems to comfirm this. None of the 6 "reasons" speak to me.
- mgbmtl 4y agoHere's an easy one for you: if you have a gigabit connection, most home routers can barely handle the load of NAT. That's why gamers push for IPv6. It's mentioned in the article but few people realize how inefficient NAT can be at gigabit and more. My ISP router could do max 800 mbps, which isn't so bad, but it degraded when we were multiple people using the link. With IPv6 it's much less of a problem, we can easily saturate the 1gbps without the router having a meltdown.
- TekMol 4y agoI don't even know what type of connection I have. I only know the speed is way more than I need. fast.com says 50 "Mbps". Whatever that is.
- lxgr 4y ago> if you have a gigabit connection, most home routers can barely handle the load of NAT. I remember reading about this as well. Wouldn't that also apply to stateful firewalling, though? Or is NAT inherently more computationally difficult (e.g. due to having to recompute IP and/or TCP/UDP checksums) than checking a state table?
- 4y ago
- thesuitonym 4y agoEveryone always goes with the "You don't need NAT, everything is globally routable!" argument, as if that's something that anybody wants. Everything on my network is going to go through my firewall anyway. I don't want anything on my network to be globally routable. Of course, this is not a good reason to not use IPv6, don't get me wrong. It's a problem that's easy to overcome, I just think it's not a good way to get people excited about the transition.
- ArchOversight 4y agoThat's what a firewall is for, NAT does nothing here.
- IshKebab 4y agoIn theory, sure. In practice firewalls can be misconfigured. NAT doesn't have that problem.
- deleted 4y ago[deleted]
- justeleblanc 4y agoNAT cannot be misconfigured? Really?
- lxgr 4y agoUnconfigured/not activated firewalls usually fail reachable; without explicit port forwarding or exposed hosts, NATs fail unreachable.
- wolrah 4y ago> Unconfigured/not activated firewalls usually fail reachable Local firewalls on devices, maybe, but network firewalls generally are default-deny on untrusted interfaces, and between 0 and 1 interfaces are trusted by default. Back in 2007 Apple's Airport Extreme Base Station shipped with a firmware that defaulted to allowing all IPv6 traffic, which was quickly pointed out in the tech media and fixed in a patch a few months later. A few of the garbage pile combo modem/router devices distributed by ISPs have had similar issues over the years as well. That's not normal behavior though, when it's observed it's rightfully considered a security flaw and tends to get the kind of attention vendors don't want. If you know of a mainstream device that would "fail reachable" as you claim here, name and shame please. > without explicit port forwarding or exposed hosts, NATs fail unreachable. I work in VoIP and can say from plenty of direct experience this is not true. In the modern work from home era I've had to deal with a lot of the aforementioned garbage pile consumer devices and a recurring issue with some of our clients who had older phones is that their users' home routers did the laziest NAT possible and literally just opened a two way hole on port 5060 (SIP) so as long as the phone was communicating with our server and keeping the pinhole open *ANY* other traffic that hit port 5060 was also sent to the phone, which meant they got all kinds of "phantom calls" from bots looking for unprotected SIP relays. Newer phones generally have an option to only accept SIP messages from trusted servers, but older ones sometimes don't so when combined with badly implemented NAT that happens. And yea, obviously that's a consequence of a particularly bad NAT implementation, but your complaint is about an issue that would only occur in a particularly bad IPv6 implementation.
- Steltek 4y ago> The biggest hurdle to implementing IPv6 on your own isn’t usually ISP support, router support, or client support. I'm fully ready to start using IPv6 but my packets won't get past my antiquated ISP. That seems like a pretty big hurdle, no?
- trabant00 4y agoIt's been ~10 years since IPv6 became "ready for prime-time" and I wouldn't touch it unless I absolutely have no other choice. In practice you are going to run into bugs and problems at every level, from client software to the OS networking, your router, your ISP, their ISP, their router, their server and so on and so forth. I absolutely support other people using it to iron out all the kinks, so that I can finally do it without headaches in 10 more years.
- daper 4y agoI've given a try to IPv6 in a company with few tens on servers in a 2 DCs, an office + additional location, 3 ISPs in total. For me the real challenge is not just different way to write an IP address or doing NAT. The challenge is that IPv6 changes a lot of unexpected things: - Our ISPs support IPv6 but routing quality is way worse than IPv4 including occasional inability to connect to some networks or greater latency than IPv4. I had to create tickets with such issues understood that most probably they just don't have IPv6 BGP sessions to all their upstream providers they connect. - How the VPN (an employee / road warrior setup) should be configured since from the routing perspective you don't need a VPN to connect from your home to the office? Assuming both have proper IPv6 connection and all devices in the office and your laptop have a globally addressable IP address. Employee can have IPv4 or dual stack at his home, where is dual stack in the office. Very confusing. Looks like Fortigate also don't have an idea and decided to not support such case. - You have to be careful with site-to-site VPN since even your internal services like database are now globally addressable. You really need proper firewall rules / routing policies to not leak unencrypted packets over internet. - SLAAC is cool but doesn't provide DNS configuration. (there is RFC8106 but is it supported by all OSes?). You need DHCPv6 for that. You have to choose: use only DHCPv6 or SLAAC + DHCPv6 or just relay on the vast that DNS will be proviedd by DHCP IPv4 in a dual stack setup. - The way of providing high availability gateway address in a network is different. You need router advertisement where you can provide priorities. That actually is much better than any other VIP mechanisms (no issue with MAC table updates, etc.) but you need to know that. - OSPF works a bit differently. For example: there is no authentication in router communication in OSPF itself, you are supposed to use IPSec. The list is longer unfortunately...
- joshspankit 4y ago> You have to be careful with site-to-site VPN since even your internal services like database are now globally addressable. I’d bet that this will be the source of some gnarly leaks in future. If it does my bet would be it’s going to follow the “API keys on GH” trajectory.
- apearson 4y ago> SLAAC is cool but doesn't provide DNS configuration. (there is RFC8106 but is it supported by all OSes?) For the most part, yes it's supported by major OSes. (ND RDNSS) https://en.wikipedia.org/wiki/Comparison_of_IPv6_support_in_operating_systems https://en.wikipedia.org/wiki/Comparison_of_IPv6_support_in_...
- ajross 4y ago> You should stop thinking of NAT as a security mechanism and think of it as the emergency address exhaustion prevention that it is. I hate this attitude. This is isomporphic to saying "stop thinking of system call interfaces as a security mechanism and think of them as an address space sharing mechanism". It's not technically wrong, but it's wrong in practice. Even the most naive NAT can't misroute an inbound packet. If you have an internal host and it doesn't talk to anything outside the firewall, then no one else can reach it. They have no name for it, the packets won't go. You get this even if you don't understand how it works. You get this even if the router has no idea about the host. Give everything a unique address and now the router needs to know who is safe and who isn't. That's a decision point that requires configuration by human beings, and human beings get stuff wrong. No, NAT is your friend. Use NAT. Use it even if you're an IPv6 nut.
- kazen44 4y agowhy would NAT not be any configuration compared to Firewall rulesets? heck, they even inventend protocols to do automatic NAT setup (UPNP) because configuring NAT by hand confuses people a lot.
- ajross 4y agoI'm sorry, I don't follow. Our grandparents have working, secure NAT setups that no human being needed to configure. I've never once seen a "firewall ruleset" configured by a non-geek.
- justeleblanc 4y agoReally? I changed ISPs the other day. Got my new modem/router. You know what I did in terms of firewalls? Nothing. You know what I have? A firewall that blocks all unknown incoming connections. Does it work? Yes. Did I even have to do anything besides plug in the box? No.
- dragoncrab 4y agoHappy you. All the 3 ISPs I dealt with in Hungary in the last 10 years provided 0 firewall capability for IPv6 in their integrated router/modem. Once you start assigning the addresses, every compatible IoT gadget you have is reachable from the public web. In this state, IPv6 is a pure security stepback for average residential users with 0 upside. I can't take any comment seriously who is speaking of configuring a stateful firewall in a residential environment.
- dan1234 4y agoI'd love to embrace ipv6, but my ISP's official line, for as long as I can remember, is 'planning it, details to come'. I don't expect them to move forward on it until significant sites become ipv6 only as they've admitted that they have more than enough ipv4 addresses for their subscriber base, so there's very little incentive for them to do anything atm.
- tinus_hn 4y agoYou can request free IPv6 connectivity through the Hurricane Electric tunnel broker at ipv6.he.net
- dan1234 4y agoThanks, I've actually looked at that in the past, but I'm not sure what their throughput is, and I'd have to configure each device individually as the router I have can't be configured for it. I think I've still got my HE IPv6 t-shirt somewhere, from when I completed their readiness quiz so years ago! Edit: I actually decided to set up a tunnel, just to see how well it worked, and it turns out my ISP supplied router won't forward the protocol 41 packets anyway, so that's a total no-go. I suppose I could probably set up a small VPS and Wireguard vpn, then forward the IPv6 packets that way?
- toast0 4y agohttps://route48.org/ https://route48.org/ provides 6 in 4 tunnels and wireguard is an option. Their webpage is a mess, but more info is available behind the login, IIRC. I got part way through and then decided to just use a Hurricane Electric tunnel because HE has presence at the nearest internet exchange and it was more familiar.
- KomoD 4y agoMy ISP went "we're planning it", "it's in progress", "we cancelled it", "there's not enough demand", and they're a pretty large ISP in my country.
- bityard 4y agoQuestion from a (relative) IPv6 newbie that wasn't addressed in TFA: Let's say I have a very small home lab. I have a handful of hosts that get their IP addresses via DHCP from my router. In the router, DHCP and DNS are tightly coupled such that the router essentially always knows the MAC address, IP address and hostname of each device. Now I want to run IPv6 on this network as a first-class citizen. Since DHCPv6 is apparently frowned upon by v6 purists, and not all devices on my network support it, that leaves SLAAC. My understanding of SLAAC is that each node essentially picks its own globally unique IP instead of asking a router for the IP. My question then is: is there some standard for the DNS server on the router to somehow know the v6 IPs of the hosts on the network so that it can automatically create the right A records?
- samcat116 4y agoIn what way is DNS and DHCP tightly coupled? Automatically creating A records for DHCP hosts is not normal in my experience, especially for consumer routers. If some device your using supports this it could work for IPv6 as well as devices will broadcast on the network for routers when using SLAAC I believe.
- vetinari 4y agoMany home devices use dnsmasq as their DHCP server and DNS resolver, and it can optionally use hostnames from the DHCP part of its business during resolving DNS too. The point GP had that it won't work, then DHCPv6 is not used.
- justeleblanc 4y agoIt's not usual for your router to create A or AAAA records for the hosts connected to it. Look into Multicast DNS.
- jacob019 4y agoMaybe not, but it's super convenient and well supported by isc-dhcp-server/bind9. I do it on all my networks.
- 1970-01-01 4y agoMy #1 gripe with IPv6 is that it is too big. You never ever will use all the octets.
- justeleblanc 4y agoThat's pretty much the whole point.
- xnyanta 4y agoYou will use the octets when you find out how useful they are to build a structured addressing plan.
- sp0ck 4y agoMy experience with IPv6. I have option to enable full dual stack with my ISP. After doing this I noticed that YT/FB/Google were significantly faster, however my kids started to complaing that some games began to have connectivity issues. Minecraft have problems to start. On a number of sites load time was noticebly longer. Switching off IPv6 as a experiment on one of kids PC solved all issues. My conslusion is that it is not worth to enable IPv6 and spend time to diagnose constant issues with random pages and services.
- justeleblanc 4y agoI don't think this anecdote proves anything.
- hot_gril 4y agoIt doesn't say a lot. What says more is how often you seek home networking advice and one of the first troubleshooting steps is to disable ipv6 (though restarting the router is probably first).
- mritun 4y agoIf we’re talking anecdotally, I am running dual stack IPv6 and have had zero issues with Minecraft or any other game on my network on Xbox, Switch, iOS and PC.
- Gigachad 4y agoMinecraft does not support v6 but I wonder what caused the issues. Maybe the presence of v6 support caused DNS to give a v6 address and this caused problems? Seems unusual.
- xnyanta 4y agoMinecraft absolutely supports IPv6. The server doesn't bind to v6 by default but will happily do so and work if you tell it to.
- 4y ago
- orcajerk 4y agoThere's a reason most haven't moved to ipv6. ipv6 is a solution looking for a problem. What we really need is an ipv7 that takes the best of ipv4 and ipv6 instead of trying to force ipv6 down a reluctant user group.
- growse 4y agoIt's not that the reluctant user group doesn't like IPv6, they don't like change.
- hot_gril 4y agoMy public IPv4 is something like 14.63.323.85, private is 192.168.1.2 (others are .3, .4, etc), DNS is 1.1.1.1. My public v6 would be like 2345:0425:2CA1:2020:1100:0567:5673:23b5, private is fc00::::903A:1C1A:E802:11E4, DNS 2606:4700:4700::1111 (don't forget those consecutive colons). It's not that I don't like change, it's that I don't like changes that make things plainly worse for me.
- cornholio 4y agoYou can't have the best features of the two - in the sense of interoperability - because they are different on a fundamental level: it's impossible for IPv4 nodes to talk to IPv6 nodes without understanding the much larger address space. There were proposals back in the day (early 90s) for IPng (IP Next Gen, as IPv6 was called back then) to be a hierarchical routing algorithm, that could have kept backwards compatibility with IPv4 and transparently allow seamless operation and routing of IPng islands over IPv4 infrastructure, taking full advantage of the address space expansion. Think of a sort of CGNAT that instead of stateful hacking with port numbers and the like, would have dedicated fields in the IPv4.x packet, allowing the gateway to statelesly route between the two domains (public IPv4 internet and internal 10.x.x.x network), while maintaining end-to-end connectivity. Alas, the ITEF guys really wanted a clean slate design and willfully ignored the economic problem, that IPv6 is only useful when everybody upgrades, and as a consequence nobody upgrades. It's probably one of the most costly failures in the history of computing, along with the NULL pointer, 640kB and the likes.
- deleted 4y ago[deleted]
- dmuth 4y agoIf you want to test to see if you're successfully sending out IPv6 traffic, I have an endpoint for that: https://httpbin.dmuth.org/ip/v6 https://httpbin.dmuth.org/ip/v6
- deleted 4y ago[deleted]
- superkuh 4y ago>There seems to be a lack of drive (judging by forum posts) to enable IPv6 on internet services by admins, either because they don’t care to, or it’s more work to manage a public IPv4 and public IPv6 presence If you run a mailserver adding ipv6 support is far more risk to your domain's mailserver reputation than it is worth. And if you're just a human person and not a megacorp that new ipv6 address, even if it it doesn't immediately hurt you, will take a very long time to get accept, longer than an ipv4.
- dheera 4y agoYeah I have zero motivation to deal with IPv6. I also have all my IPv4 addresses memorized, and IPv6 addresses are too long to remember with all the hex-double-colon nonsense. If they could have turned 1.2.3.4 into 1.2.3.4.5.6 I'd probably use it, but instead they opted for some scary stuff that looks like d0ff::eefa::0010::faff:::://::92::0 which I'd rather not look at. Product management fail. Anyhow, IPv4 still works for me, so I have no pressing need to even try to understand these hex-colon monstrosities. My DNS server is 8.8.8.8. Why the hell isn't the IPv6 DNS server 8888:8888:::8888:8888? Instead it's 2001:4680::... wtf?
- bushbaba 4y agoThe biggest miss of ipv6 was on usability. is a large contributor for the slow adoption.
- Symbiote 4y agoIf you would like to write IPv6 addresses in the same style as IPv4, they would look something like 208.255.238.250.0.16.239.109.89.54.222.189.74.21.22.9
- dheera 4y agoAnd that's the problem! Who can memorize all that? I mean look, a few days ago Comcast had an outage and I plugged my phone into my USB port to tether it for internet access. It hijacked my DNS entirely, and I couldn't turn on my damn lights or change my thermostat which were on my LAN. Thankfully I know their LAN IPv4 addresses from memory, 10.10.10.x and 10.10.10.y, and I was able to issue CURL commands directly to their local, non-cloud APIs to manipulate them. With IPv6 hell knows what their hex-colon monstrosities would be.
- olddustytrail 4y ago> Addresses are 128 bits long and written as 8 four-letter hex blocks separated by colons (i.e. fd69:beef:cafe:feed:face:6969:0420:0001) I suspect you mean "e.g." rather than "i.e."
- MagicMoonlight 4y agoWe should just make an IPv5 which takes a current address: 216.3.128.12 and makes it 0.0.0.0.216.3.128.12 So any address of the current length you just treat it as if it has zeroes in front, otherwise you use the longer length which allows for many more addresses. Problem solved.
- throitallaway 4y agoIPv6 became a draft standard in 1998; good luck with introducing "IPv5." Most operating systems/devices have IPv6 for a very long time now, we just haven't been forced away from IPv4 yet. IPv4 addresses are getting to be increasingly expensive (and CGNAT really sucks); eventually a market tipping point will be reached.
- aidenn0 4y agoYou're leaving out what happens if an ipv4 only host gets a packet from an ipv5 host. It only knows how to respond to a 4-byte address. If you manage to solve that problem, you'll probably have invented something a lot like NAT64, which TFA talks about.
- hot_gril 4y agoDrops the packet and the sender retries with v4. Ipv6's solution to packet fragmentation has the hosts retry too, iirc. But I'm a little rusty on this subject; would this actually work?
- skywhopper 4y agoFrom my POV, IPv6 overshot and tried to solve too many non-problems while addressing the only real issue with IPv4, the address space. That fact alone explains the relentless failure to adopt IPv6, because it’s not just a matter of adopting IPv6. Nearly every assumption about networking changes, all the tooling is different, and the risks and concerns are all changed. There was an easier path to follow, but we missed that chance 20 years ago, and now we’re likely stuck with a dual stack mess for the rest of our careers.
- AtlasBarfed 4y ago"although software support is virtually a requirement these days" Who's fault is this again? ------------- "- IPv6 is absolutely ready for prime-time and has been for awhile BUT "- About half of the internet sites I rely on support IPv6 natively, so there needs to be more pressure on site admins and CDNs to support IPv6 natively" That is a contradiction. ----------- "There seems to be a lack of drive (judging by forum posts) to enable IPv6 on internet services by admins, either because they don’t care to, or it’s more work to manage a public IPv4 and public IPv6 presence" Again, who's fault is it that its so hard? What is the payoff for the extra work? ----------- - Networks should be designed IPv6-first instead of IPv4-first, and this design approach largely solves most of the major issues K thanx, but that's not the way virtually every company works. Mayyyyybe a startup? This is unrealistic. ----------- "Other operating systems are bit of hit or miss" so... IPV6 is NOT NOT NOT ready for prime time, is that what you are saying? ----------- What dream world are the ipv6 people living in? I love this. Who should be implementing ipv6 stacks in OS's? Probably ipv6 people, but ... where are they again? The amount of blame is crazy. A protocol switchover of this magnitude is about outreach and assistance. The ipv6 crowd has NEVER displayed that, just arrogance, dismissal, and waited for things to get "so bad" in ipv4 that it transferred. Which is why ipv6 people HATE HATE HATE NAT. It has delayed their grand moment by decades. ... In an ideal world, the ip++ protocol would have been easier, not harder. BLog posts wouldn't be victim blaming, throwing around NAT64, 464XLAT, DNS64 DNS64 kills me. WHy is there a totally different service for ipv6? Isn't DNS just a key-value store? People put all types of crap into DNS, including, I believe, ipv6 addresses. Why isn't there a DNS record type that basically lists both an ipv4 and ipv6 for a name, along with negotiation information? Might that make transition a lot easier? Maybe it does, but it isn't in this article. Just ... all the same problematic attitudes, no progress on issues, my way or highway, and denial.
- creatonez 4y agoI don't know where you got this narrow view... reading too many amateur blog posts? Many of the companies/organizations in the IPv6 space are some of the most friendly and easy to work with in the industry
- redog 4y agoI think ipv6 could happen if subsidized for long enough. Something like, I'll-sell-you-my-v4-blocks-at-a-later-date-forfreeipv6-bandwidth-today-as-a-service ... Re-Send them nostalgic AOL CDs as the advertising...
- saul_goodman 4y ago"Apple has excellent IPv6 support on their devices, fully supporting automatic configuration of 464XLAT on devices with NAT64, and overall an excellent attitude to forcing IPv6 support from developers" Other operating systems are bit of hit or miss" My iPhone works, what's wrong with the rest of you for not doing this??!! But in all seriousness, I think this will be a security nightmare for quite a while if there is some forced conversion to ipv6. I realize IPv6 wasn't created yesterday, but I assume it's got plenty of security holes waiting to be discovered until I see otherwise. The only way you are going to see it be used by end-users is if the various *nix distros roll out IPv4-less images. Same for Windows/etc. Otherwise you are begging for a security nightmare of epic proportions with software that is accidentally using the wrong stack by default, firewalls not filtering anything as expected, etc. And who thinks it's a good idea to make all the things globally accessible? It's an internet of shit out there already, this would make it even worse.
- deleted 4y ago[deleted]
- somerandomqaguy 4y agoI've still got some misgivings about IPv6. Biggest one for me personally is that my current ISP doesn't give stable prefix. Power outages or firmware updates requiring a router reboot thus can cause the PD to be changed and potentially break firewall rules that are sensitive to the PD. In an absolute worst case, it also means that none of your hosts can reach the internet anymore if for whatever reason they're not updated of the prefix change. No, the ISP is not supposed to that. But I don't see them changing this behavior any time soon. Yes there are ways to mitigate (ULA, mDNS, DNS, DHCPv6, etc) but now you're introducing additional complexity that didn't exist before into the network when I keep hearing how Ipv6 is supposed to reduce complexity. And IPv6 is complex enough to make my head spin without considering those workarounds. Other issue I can think of off the top of my head is how to deal with an organization that would requires multi-WAN fail over or load balancing? The only solutions I've see thus far are far beyond my level of skill and budget. I assume also that there's similar problems when asking about a load balancer between multiple gateways to the internet.
- mixdup 4y agoYeah, there are a lot of situations where NAT is actually preferable. Not everyone is going to need inbound ports, and the stability you get by having internal addresses is a feature, not a bug Tie all your network config to your IP space provided by your ISP and now suddenly it's a pain to migrate to a different ISP Or, if you want to carry your own IP space, now you have the administrative overhead of managing that (and, now you have to go with higher-end business internet service that may be more than you need, just to support bringing your own IPs)
- willbudd 4y agoI feel like if you want a robust ID for your machines, using DNS instead of hardcoded IP adresses is a better idea. That way you can move services from edge to cloud and vice versa with a single nameserver update, instead of having to do so on every single edge. Or, if you want to keep things local, run a lightweight nameserver on your LAN to resolve .home or .lan domains. Much nicer to type fridge.home in your browser than 192.168.1.57 or some such.
- homero 4y agoMany cell phone networks are always ipv6 using xlat
- NegativeK 4y ago> There seems to be a lack of drive (judging by forum posts) to enable IPv6 on internet services by admins, either because they don’t care to, or it’s more work to manage a public IPv4 and public IPv6 presence Yup. I work at a large, complicated infrastructure organization. Our firewall guy has a lot on his plate. Having him manage the security concerns for IPv4 and IPv6 is a bad idea when considering the tasks we have and the labor available. Similarly, having the networking team implement IPv6 on top of their already significant projects results in less time available to do other things. I look forward to the day when IPv6 is easy and universal, but I can completely understand why many admins aren't bothering.
- arka2147483647 4y agoWhenever i read these ipv6 discussions, i cant help to think there is a huge disconnect between users and designers of ipv6: - Designers think globally routable internet is a huge achievement - Users just want to hide their devices from the hellscape that is modern internet, with all its threats These are fundamentally different approaches
- fulafel 4y agoI'm a user and I think they are compatible requirements and support each other well. The alternative, having ambiguous addresses, makes systems hard to reason about and monitor, and add compplexity - eg when inevitably "internal" networks end up connected to each other in various kinds of reorganisations resulting in misconfigurations because nobody can tell anymore what the ambigous rule about a 10.xx address meant. Complexity and anbiguity are main enemies of security because you can only secure what you can understand well. NATs are also hard to reason about in that there's no real spec about what kind of incoming traffic they allow and when. The NAT function is designed to facilitate communication in face of connectivity hurdle presented by the addressing, not limit communication.
- arka2147483647 4y agoPerhapse so, but i think psycologically, having your devices ’hide’ behind a NAT feels a lot more safe than having them out in the wild with only some firewall rules to protect them. Secondarily, to many users both ipv6 routing and NAT are both incomprehensible. I think most home/sme IT admin people who have to maintain everything in their home/company are not in a position to learn everything about ipv6. Having a solution like NAT where you just cant connect from the outside (unless forwarded) really simplifies many things. Many people are not in a position where they can understand networking fully.
- jeroenhd 4y agoAs a user, I like that my router doesn't need to alter my traffic mid transit to connect to outside networks. With attacks like NAT slipstreaming your devices are already globally reachable in any real network anyway. That, or FTP/SIP doesn't work, because ALG exploitation can be mitigated by just disabling those protocols. Just ask the average gamer behind CGNAT how they feel about the security NAT provides them (and what kind of NAT they need), or your average network application developer about the joys of setting up handshake servers to punch holes through NATs. The curse that is NAT has led to ridiculous workarounds like Nintendo telling people to put their Nintendo Switch in the DMZ if multiplayer doesn't work.
- shmerl 4y agoping6 news.ycombinator.com ping6: news.ycombinator.com: Address family for hostname not supported And it's not even the worst possible example. Try github.com.
- jeroenhd 4y agoMy experience with IPv6 is that routing generally goes faster and the network breaks down less. The statelessness of it all just makes it work. The fight between your average video game and NAT has caused me so many problems over the years (including port forwards to receive traffic because whatever NAT punching mechanism the game used didn't work). Running dual stack does cause some weird debugging ("why can't my laptop connect to github while everything else works? Oh, DHCP broke") but that's mostly because of problems with the IPv4 part of the network. I think going IPv6 only isn't the way, not yet anyway. DS-Lite seems to be working fine as a replacement, though: CGNAT for IPv4 and normal IPv6 for real connectivity. Full fat dual stacks would be better, but realistically I don't think that's going to be brought to the masses. For hosting stuff, not having to remember what SSH port maps to which server in my home lab is a nice addition. Being able to directly reach LXC containers is also quite useful, as is using separate addresses for individual hosted services. I don't know why everyone here has such terrible ISPs. Unstable IPv6 prefixes, broken routing, weird custom allocations, your ISPs all seem so cursed! No wonder people are so mad at IPv6, your ISPs are sabotaging your internet.
- J-Kuhn 4y agoI agree, IPv4 has its problems. That is why we transition to IPv6. Dual Stack doesn't "solve" anything. You still run IPv4. With all the downsides, especially every machine will still need an (RFC 1918) IPv4 address. (Microsoft is running out of their internal 10.0.0.0/8: https://www.arin.net/blog/2019/04/03/microsoft-works-toward-ipv6-only-single-stack-network/ https://www.arin.net/blog/2019/04/03/microsoft-works-toward-...) The goal of the IPv6 transition is to disable IPv4. NAT64+DNS64 or 464XLAT allows us to disable IPv4 on devices before the entire internet is ready.
- jeroenhd 4y agoI would love full transitions to be easy enough to work. DNS64 breaks DNSSEC without updates to the spec, so that's not going to fly for me today. A competent DNS configuration would fail to resolve my IPv4 domains at the very least (though all of my public domains have an AAAA record, obviously). The only solution is to do DNSSEC validation at the DNS64 level which in my opinion defeats the purpose of DNS security all together. For internal networks, IPv6 seems like an obvious choice. If you already have company wide subnets, you may as well set up some ULAs/GUAs and use IPv6 internally. Full IPv6 may be better but people worry about adversaries mapping internal networks for some reason so NAT66 may be necessary to placate those fears. The problems you still keep around by using some kind of dual stacking (DS-Lite being the cheapest) ensures compatibility with servers and entire countries that haven't even begun upgrading their networks yet. You incur the IPv4 penalty, for sure, but only towards services that don't have IPv6. This provides an incentive for the world to move on without breaking existing infrastructure entirely.
- clarge1120 4y agoHahahaha! 'd69:beef:cafe:feed:face:6969:0420:0001'