24 ms·
IPv6 Is A Disaster (but we can fix it)
- remram 3y ago"The writing is on the wall" because cloud providers charge a few dollars a month for IPv4?
- stop50 3y agoto be short: most stuff didn't work because they cling to their ipv4 address.
- NoZebra120vClip 3y agoI wonder if he disabled IPv4 support in the kernel and stacks, or if he simply removed the IPv4 address from network interfaces and A records from DNS?
- stop50 3y agoIf the host has no v4 it switches to v6 if possible. Disabling the support is not needed
- NoZebra120vClip 3y agoVery ambiguous reply. Which host? The remote or the local? What do you mean "has no v4"? No A record? No v4 address on an interface? Which hardware and OS are you describing? Clearly the blog post illustrated some examples where switching to v6 was not happening, so it seems to contradict your comment right off the bat. There are many implementations of dual-stack IPv4/v6. In fact, they are more divergent than IPv4 implementations, because the latter often derives from the BSD-RENO codebase, while IPv6 was introduced after Linux became King, so Microsoft, Apple, and Linux (and lots of router/firewall vendors) have ostensibly developed IPv6 stacks separately, some being more open than others. They're not all going to work the same way with fallbacks/failovers.
- aidenn0 3y agoIf (a host trying reach a remote service) has (no route to the address indicated by the A record) then it will try a AAAA record if one exists. > Which hardware and OS are you describing? This is how it's supposed to work on all OSes; on any recent BSD (excepting perhaps Apple?) or Linux setup, it should work this way. > Clearly the blog post illustrated some examples where switching to v6 was not happening In those situations it was for connecting to services that do not advertise a AAAA record.
- NoZebra120vClip 3y agoNo, actually it does not work that way. You have it backwards, first of all: IPv6 AAAA record is queried first, then the connection is attempted, and then a fallback may happen to an A record and an IPv4 connection attempted. https://www.rfc-editor.org/rfc/rfc5220.txt https://www.rfc-editor.org/rfc/rfc5220.txt I'm not sure why you specified "if a host has no route to the address", because that's a very specific and transient failure. Furthermore, the dual-stack handling necessarily happens in the application, so this is not an OS or kernel-level decision, it will be subject to each individual app's behavior: https://issues.apache.org/jira/browse/SERF-190 https://issues.apache.org/jira/browse/SERF-190 As you can see from RFC5220, IPv6 is preferred over IPv4, unless an option is set to swap those around. Of course, certain configurations can confound this preference order, such as ULA IPv6. "No route to host", as should be obvious, is only one of many errors that could prevent an app from establishing an IPv6 connection. It would seem that they should handle most failures as an occasion to fall back to IPv4, unless configured not to.
- Dagger2 3y agoThat is also not accurate. Clients query both the A and AAAA records simultaneously up front, sort the replies according to the RFC3484/6724 rules, and then try each address in turn. The rules are somewhat involved but they roughly boil down to "sort v6 addresses first if the client has a non-ULA v6 address, otherwise sort v4 first". However, note that the very first rule in 6177 is "avoid unusable destinations" so not having a route to an IP may factor in to the sorting. A machine with no v6 will(/may) still query AAAA records, but it will attempt to connect to any A records first before trying any AAAA records. (This sometimes exhibits as people seeing software like apt-get report connection failures to v6 addresses and then blaming v6 for it, even though the problem is that they only have v4 and the v4 is broken.)
- bell-cot 3y agoMy IPv6 philosophy: If any "new" computer technology has been around even half as long as IPv6 ( https://en.wikipedia.org/wiki/IPv6_deployment#Major_milestones https://en.wikipedia.org/wiki/IPv6_deployment#Major_mileston... ), with even a tenth of the "you gotta start using this!" push from the Big Boys - and yet still is very widely avoided/resisted, and the older-tech alternative commands a price premium due to widespread demand...gosh, that "new" technology must absolutely suck, eh?
- Nextgrid 3y agoI don't think it's fair to blame the technology. The problem is that the computing industry has changed. The things that IPv6 would enable (direct end-to-end connectivity) is now seen as a negative by the industry that has since pivoted on rent-seeking, walled gardens and restricting user's potential. The industry is now even legally making money on many things that would've been considered outright malware just a decade ago. People being able to host things themselves, or local-first apps that communicate directly without the need for any middlemen is a negative for the industry. The industry wants there to be a technical need for a middleman, so they can provide that and seek rent over it. There is no user-level demand for IPv6 because the industry is no longer making any apps/devices/services that would take advantage of end-to-end connectivity (even if it was available now - let's say in a hypothetical world where IPv6 adoption is 100%) since it's more profitable not to, so as a result there is no pressure on ISPs to offer it.
- AndreasHae 3y ago> The industry is now even legally making money on many things that would've been considered outright malware just a decade ago. Sounds a bit over the top. Can you name some examples?
- unethical_ban 3y agoInstagram, for one.
- Nextgrid 3y ago
- NoZebra120vClip 3y agoFor an IPv6 advocate, this guy sure set up a lot of NAT. And while he claimed he's going IPv6-only, he set up public access via IPv4. That won't convince anyone to switch or upgrade. I understand that he's building a usable service and just trying to git 'er done, but it's a lot of hacks, so I'm glad they're documented in this here blogpost. I hope that he can continually probe the edges to find out when real IPv6 support becomes available, and can gradually remove the hacks for a purer experience.
- mduggles 3y agoI mean my intention was to go pure, hence finding the Docker IPv6 registry and doing the IPv6 stuff with the bridge interface. My hope is folks know of workarounds and I’ll do them and update the post.
- ClashTheBunny 3y agoWhat would you suggest they have done? I feel like excluding IPv4 folks is a large reason why IPv6 continues to fail. I feel like this is a pretty good compromise between pushing IPv6 and not being an IPv6 hermit in the IPv6 desert.
- NoZebra120vClip 3y agoAt this point, I feel like the onus should be on IPv4-only clients to adapt to an IPv6 world, by enabling proxies and translators that enable them to access IPv6 sites until their support comes up to speed. This could be done on the ISP/enterprise level, but it is more counterproductive to tell IPv6 adopters and promoters that we need to bend over backwards and hack in NAT and purchase/rent/lease public IPv4 addresses, when this is not our problem anymore. I feel like the more juicy services that are IPv6-accessible-only, the more it will drive consumer demand, and will light a fire under people who are responsible to update the support and ensure that IPv6 works, even when IPv4 doesn't.
- WorldMaker 3y agoThis is sort of happening. Consumer "demand" is already showing IPv6-first usage in part because the (non-evil/braindead) consumer ISPs to avoid CGNAT scenarios have been moving to IPv6-first or IPv6-only with NAT64 gateways. This is especially the case in US mobile carriers who are generally some of the largest ISPs at this point by volume of US consumer traffic. It's mostly the Enterprise level that has failed to get the message and is failing the IPv6 internet. Even just the examples in this article: It makes zero sense that GitHub still has no AAAA records (and is increasingly slow and lethargic on mobile carriers via NAT64 gateways; it is not just that their mobile app is only so-so, it's also their networking is slow). It makes zero sense that Docker put its AAAA records on weird secondary domains instead of their main domains. Now that all of the major cloud providers are charging for IPv4 address space on a per-hour scale that might see reflection in bottom lines in IT budgets, maybe there will be a fire finally lit under Enterprises to consider using more and better IPv6.
- garganzol 3y agoIt depends on a country. I was at places where IPv4 is the default choice. I also visited countries where IPv6 is a standard practice. As a consumer, you really do not see much difference, IPv6 works surprisingly well if not better than IPv4.
- WorldMaker 3y agoMost US mobile carriers are IPv6-first or IPv6-only with big NAT64 gateways. One of those countries these days is the consumer parts of the US.
- LUmBULtERA 3y agoI have Verizon FIOS and my area STILL does not have ipv6.
- hot_gril 3y agoSince the main problem was address space, they should've just expanded it. Let everyone keep their old v4 addresses (with 0-padding), focus on the protocol upgrade, and give new users longer addresses for cheaper. You wouldn't even need DNS changes initially. Instead, v6 became a whole new thing with additional goals like removing NAT (which I'm not even convinced is a good idea), so of course there'd be way more friction. Like, I said this elsewhere, Cloudflare public DNS is 1.1.1.1. If I switch to ipv6, I get to use 2606:4700:4700::1111. You telling me that's an upgrade?
- TheLoafOfBread 3y agoI agree. Instead of just making v4 addresses bigger (and related services around the protocol as well - ICMP, DNS, ...) a committee spawned jack of all trades, master of none IPv6 incompatible with current IPv4 stack.
- bauruine 3y agoIPv6 is compatible with IPv4 there are millions of devices with only an IPv6 address that work just fine.
- hot_gril 3y agoNo, I only have a v4 address with my ISP and cannot use a v6-only device at home.
- bauruine 3y agoIPv6 is backwards compatible to IPv4 but not the other way around. If you have a solution how to address a 128bit IPv6 address with the 32bits available on v4 I'm sure many people are eager to talk to you. It's just not possible.
- hot_gril 3y agoWith a 6-to-4 gateway then yeah. But at that point you're using v4.
- aidenn0 3y agoI think if every hosting company that charges for ipv4 addresses offered complementary (or at least much cheaper) NAT64, then paying for an ipv4 would be only needed for ingress traffic, and ipv4 addresses could be dropped for most VMs.