5 ms·
As a general rule, if you're deploying IPv6 subnets sized as anything other than /64, you're doing it wrong
by darkr 3y ago
As a general rule, if you're deploying IPv6 subnets sized as anything other than /64, you're doing it wrong
- tsimionescu 3y agoThe only reason for that "rule" is SLAAC.
- darkr 3y agoActually it's primarily due to NDP and EUI-64. Eliminating ARP is a very good thing for reasons of scalability, reliability and security.
- tsimionescu 3y agoNDP doesn't impose any restrictions on IP addresses, it uses special prefixes anyway. EUI-64 is a part of SLAAC, not NDP. Finally, NDP is not really any more secure at least than ARP (at least not if you don't implement SEND as well, which I'm not sure if anyone does, at least in consumer networks). Not sure about reliability or scalability either.
- p1mrx 3y agoI think SLAAC's /64 limit functions as a "trojan horse" forcing ISPs to give everyone at least 64 bits of address space. Most would allocate /112-/128 per customer if it were slightly easier. Designing the internet with lots of unused space at the edges will probably be useful in 100 years.
- tsimionescu 3y agoRegardless of the /64 limit, I expect DHCPv6 will win out in the consumer side (with ISPs giving customers pre-configured wifi routers with DHCPv6 already configured). SLAAC is both very complicated, and its privacy extensions are anyway not something ISPs have been friendly to even if it weren't such an extra hassle.
- p1mrx 3y ago> and its privacy extensions are anyway not something ISPs have been friendly to That is an argument for forcing ISPs to support SLAAC, so it's difficult to bill a customer based on the number of devices in their home. ISP-friendly often means user-hostile. If ISPs can deploy device-counting DHCPv6, then router manufacturers will respond with IPv6 NAT, and then the IPv6 landscape will be as shitty as IPv4.
- tsimionescu 3y agoDevice counting has always been possible with IPv4 routers, and yet I don't know of a single ISP which does this. To be clear, I'm talking of ISP-provided (usually wifi) routers, which at least in my country are extremely common. Those could receive an IPv6 prefix and do DHCPv6 inside your own network.
- p1mrx 3y agoThe concept of an IPv4 NAT router exists today because people in the '90s wanted to connect multiple devices without permission from their ISP. SLAAC lets you extend a network without permission using ND Proxy, whereas DHCPv6 IA_NA can only be extended using NAT. So I think SLAAC is good because ND Proxy is less evil than NAT.
- imoverclocked 3y ago> whereas DHCPv6 IA_NA can only be extended using NAT. Pedantically, it doesn’t force that but it can, right?
- chungy 3y agoIt's all too common for ISPs to give you just a single /64 going into your home. So if you want to define subnets within that, you're "doing it wrong"? Nah. Just use DHCPv6 and be happy.
- ArchOversight 3y agoName and shame the ISP! And update your DHCPv6 Prefix Delegation request for a larger prefix (try /60, that seems to be a common supported PD size for most at home ISPs).