39 ms·
Who the hell is giving their Roku a public IP? How is this remotely a problem? This is 100% not the fault of Roku, and 100% the fault of the ISP. The ISP should
by hitpointdrew 4y ago
Who the hell is giving their Roku a public IP? How is this remotely a problem? This is 100% not the fault of Roku, and 100% the fault of the ISP. The ISP should have an IPv6 to IPv4 gateway built into their modem/router. You have a WAN port that is IPv6 and an LAN port that IPv4.
IPv6 for local networks, makes no sense is completely unnecessary, and is a hill I will die on. IPv4 is here to stay.
- blibble 4y ago> IPv6 for local networks, makes no sense is completely unnecessary, and is a hill I will die on. IPv4 is here to stay. my mobile phone in the UK on one of the big 4 carriers only has IPv6 addresses and only has IPv6 connectivity (using 464XLAT)
- deleted 4y ago[deleted]
- ArchOversight 4y agoThe ISP said they got only a limited set of IPv4 addresses, those are assigned to their CGNAT gateways. Which are expensive, especially for an Indian Reservation, not the deep pockets of some MSP. The users are behind CG-NAT. But instead of using IPv6 which is cheaper (no need to maintain CG-NAT, translation devices, or deal with traffic that is being routed way more expensively) the Roku devices are only streaming over IPv4. Each new user that adds an IPv4 only device adds additional load the CG-NAT and additional capacity will need to be provisioned. That is an additional expense and burden. Most of my traffic at my house (on Comcast) is over IPv6, because most if not all streaming services now support IPv6 for content delivery, so the small amount of data that may need to go over IPv4 when the majority can go over IPv6 reduces the load on IPv4.
- zamadatix 4y agoRealistically they are already running a large scale NAT device anyways, otherwise the v6 only clients wouldn't be able to reach v4 only internet services (hello HN server), and if they had planned to CG-NAT from the start it probably could have all been done on the same pair of internet edge routers for much less than 300k additional expense.
- Symbiote 4y agoAs the article says, the Roku traffic is the overwhelming majority of that ipv4 traffic. HN and similar mostly-text websites would barely show up on the statistics.
- zamadatix 4y agoNAT scales in both dimensions, you're just as likely to need a larger box for a larger connection table as you are a larger bandwidth.
- noAnswer 4y agoAt some point you also need more IPv4-addresses. There are only 65535 ports to be mapped.
- zamadatix 4y agoAt some point but remember it's not "after 65535 connections per IP" it's "after 65535 connections of the same type to the same IP per IP". That is to saythese NATs where 156.78.92.154 is a single public address on the NATing box: 156.78.92.154:6781<->8.8.8.8:53 UDP 156.78.92.154:6781<->8.8.8.8:53 TCP 156.78.92.154:6781<->8.8.4.4:53 TCP 156.78.92.154:6781<->8.8.4.4:53 UDP Can all exist simultaneously even though only 1 port is in use and we haven't even started changing the destination IP or ports yet (e.g. 80 and 443 as the destination won't double count and thousands of web servers on different addresses can be accessed via the same source port). With CG-NAT you can usually support somewhere around 30k customers on the free /24 you get from ARIN for having only IPv6 and needing space to translate in (for new orgs like new ISPs this is assigned immediately out of a reserved block, bypassing the waitlist for existing orgs trying to get free reclaimed space).
- ArchOversight 4y agoIt's also about ports. If I have 10 Gbps of IPv4 flow but my devices are licensed for and operate on 1 Gbps, I need to license 10 1 Gbps ports. When I was last working at an ISP, various CG-NAT solutions charged not just based on the connection table, but also there was various licensing for various slide-in cards. If the ISP is having to buy additional hardware/additional ports on upstream providers just to power their CG-NAT that is an additional cost. If the POP where you have your CG-NAT doesn't have more bandwidth available you end up running your ports hot... so now you either need to rent a new location, get your connectivity up there and start figuring out how to route the traffic. It's not as simple, and it all costs copious amounts of money. Especially if your IPv6 can more easily be distributed across multiple POP's with multiple forms of connectivity and traffic shaped using BGP or other solutions thereby reducing the load on a single upstream port.
- brokencode 4y agoWhy does the IPv4 address need to be publicly exposed outside of a customer’s LAN? I thought you could set up NAT on a router to translate local IPv4 addresses to something IPv6 that is exposed publicly. Is this simply bad planning from the ISP where they didn’t handle it correctly? Or is there something I’m not understanding about NAT? I think in an ideal world all devices would be using IPv6. But I thought it would be common knowledge among network engineers that many devices still use IPv4, so you have to either handle it somehow or tell your customers that some of their devices simply won’t work.
- zamadatix 4y agoCG-NAT (NATing centrally at the ISP's internet edge) is cheaper/simpler than something like 464xlat (NATing v4 locally over v6) since you can do the former on 2 boxes instead of 20,000. That said the 2nd option is much cooler :).
- ArchOversight 4y ago464XLAT still requires IPv4 boxes on the edge to translate IPv6 traffic back to IPv4. Whether that is two boxes or 20,000, the same is true for other CG-NAT solutions. Someone somewhere is bearing the cost of translating.
- zamadatix 4y agoUsually you need a special box at the consumer side to do 464XLAT, it's not something you can just ask your customer's Netgear to do and it's usually more expensive if you want to provide it as the customer's rented router. CG-NAT however looks completely normal to all gear (other than the particular numbers assigned) except the 2 edge boxes. It's the ultimate cost saving kludge.
- cmeacham98 4y agoMost modern OSes (I know for a fact Android, iOS, and Windows) support automatically doing the 4->6 translation on their side (as a matter of fact, some cellular networks in the US are ipv6 only). I'm unsure if consumer routers would pass on the appropriate RA flag to tell the OS they need to do this in their default configuration however.
- lmm 4y ago> IPv6 for local networks, makes no sense is completely unnecessary, and is a hill I will die on. IPv4 is here to stay. Why would you make everything gratuitously complicated by having two separate forms of addressing? All that IPv4 gains you is new and exciting ways to mess up your networking. Just give every device a normal public address (of course you probably want to firewall off inbound traffic from the WAN to the LAN, but that's got nothing to do with addresses) and have a normal network rather than some bizzare frankenstein mashup.
- acedTrex 4y agoA pipe dream, but the best case seems to be a total standardization on v6
- znpy 4y ago> you probably want to firewall off inbound traffic from the WAN to the LAN But all modem/routers are doing it anyway, they might as well do that on ipv6. Effectively all router appliances (at home and soho level) are linux appliances, and the firewall is built into the kernel (and in use anyway).
- phpisthebest 4y agoSorry I do not trust the likes of home router vendors to implement a linux firewall correctly While people may say "NAT is Not security", it is in fact a layer (ahd huge one) in the security onion, that ipV6 is likely going to increase drastically the amount of ransomware and other malware on the public internet simply because that NAT layer is gone
- yamtaddle 4y agoI remember what it was like when lots more home computers were routable from the public Internet, because having a NAT router between them and there wasn't a nearly-100%-adoption thing yet. In fact, I worked at an ISP (dial-up and DSL) in that era. It was indeed a shit-show. Adding a NATting router to those set-ups instantly increased their security tremendously. Sure you could use a proper firewall, but the router w/NAT Just Works.
- dijit 4y agolink local ipv6 can be deterministic (no more shuffling IPs around!) and no more silly dhcp services running on anaemic hardware. Ditto for NAT, where devices can reach v6 endpoints (though stateful firewalls should stick around!). Honestly, I really hate change. but ipv6 does have some upsides and rather than complicate things, embracing actually simplifies things. The issue is that we have a lot of sunk cost on how we bolt on shit to ipv4 to make it passable in the modern day, and we begrudge having to relearn what we think is solved.
- bonsaibilly 4y agoCongratulations on completely failing to understand how CGNAT loads work & their costs, and jumping to a wildly incorrect understanding of the situation
- tpmx 4y agoPrediction: CGNAT processing costs for gigabit subscribers will become neglible in the medium term (3-5 years). Not that it's wildly expensive today...
- bonsaibilly 4y agoYou are literally posting this comment on a story about CGNAT processing costs being wildly more expensive than a small ISP cares to deal with. To the point where they’re willing to buy and distribute AppleTVs to reduce costs. Even if that price decreases in real terms, washing a whole bunch of traffic through a big-ass NAT is always going to cost more than just not doing that.
- tpmx 4y agoThe cost of an IPv4 address is around $50. Annualized it's a few dollars. So, that's the baseline for where CGNAT makes financial sense. That's a lot less than the cost of an Apple TV.
- outworlder 4y agoYeah, and that's currently the top comment. Which leads me to believe that the main barrier to IPV6 is just that people don't want to re-learn anything.
- JohnFen 4y ago> the main barrier to IPV6 is just that people don't want to re-learn anything. I disagree, actually. I think the main barrier is that networking folks have been pretty bad at explaining this to non-networking folks. IPv6 isn't exactly simple to understand. I'm a reasonably network-savvy guy, and I'm sure that I understand less about IPv6 than I think I do. I just don't know what parts I'm not understanding properly, and what parts I just don't know about. It's pretty hard to find good explanations of this stuff that aren't aimed at networking experts.
- bastardoperator 4y agoNot going to lie, I just turn IPv6 off on my router because I don't fully understand it and because I pay a little extra for a block of 3 IPv4 addresses.
- ehPReth 4y agowho cares if it's "public" if it's firewalled; likely by default
- lillecarl 4y agoHow do you reach all 2^128 ips when you only have 2^32 destinations? IPv6 makes sense everywhere.
- Narkov 4y ago> IPv6 for local networks, makes no sense is completely unnecessary, and is a hill I will die on. IPv4 is here to stay. This is a position of privilege. The developing world would like access to the Internet and lack access to the (mostly) exhausted IPv4 space. Should we not work to make Internet access ubiquitous?
- JohnFen 4y agoHe's talking about running IPv4 on his LAN, not the internet. That wouldn't use up any of the internet's IPv4 space and wouldn't affect other internet users.
- 1ncorrect 4y agoHills sparsely populated with corpses are equally fascinating and comical.