7 ms·
One of the features of IPv6 is address autoconfiguration, obviating the need for a central authority like DHCP on v4. However, that only works with a /64 prefi
by pilif 3y ago
One of the features of IPv6 is address autoconfiguration, obviating the need for a central authority like DHCP on v4.
However, that only works with a /64 prefix and given that larger sites might want to have multiple subnets, that’s why most assignments are /56 or /48.
But still. If all assignments were /48s, that would still leave room for 281 trillion networks which even I believe is enough for the foreseeable future.
If the number space is so big, it makes sense to take advantage of it if that allows for other additional features (like SLAAC)
- londons_explore 3y ago> However, that only works with a /64 prefix Well it should be redesigned so it works all the way down to individual addresses.
- greyface- 3y agoYou can use DHCPv6 instead of SLAAC if you need autoconfiguration on sub-/64 prefixes.
- scheme271 3y agoSome systems like android don't support anything but SLAAC
- ale42 3y agoIMHO it means that they are not fully IPv6 compliant. Corporate networks often have DHCPv6 rather than just SLAAC.
- bert64 3y agoThey are fully compliant, SLAAC is part of the standard whereas DHCPv6 is an optional extra. DHCPv6 also does not work without RA. DHCPv6 just assigns an address, a routable prefix, dns servers etc, it does not assign a subnet or any routes, you need route advertisements for that.
- ale42 3y agoSeen like this, you can also argue that DHCP is an optional extra for IPv4, but it almost essential in most networks. Sure, IPv4 has no SLAAC that can be a valid alternative, but still, given that SLAAC doesn't solve every use case...
- lmm 3y ago> Well it should be redesigned so it works all the way down to individual addresses. Why? What's wrong with how it works at the moment?
- Kab1r 3y agoI actually have the issue where my ISP gives me a single /64 and it makes it difficult to split between multiple LANs.
- lmm 3y agoPublished guidance says they're meant to give out at least a /56. I don't know that making autoallocation work on smaller subnets would help with this problem - ISPs that currently give out the smallest possible subnet would probably just switch to whatever the new smallest possible subnet was.
- Kab1r 3y agoThere probably is a way to ask my ISP for a larger block, but I think it would be nice to be able to subnet a /64 regardless.
- lmm 3y agoCIDR and the resulting address space fragmentation was the problem that IPv6 was originally meant to solve; allowing splitting into random-sized subnets makes routing more complex and worse. And if you made the routable part of an IPv6 address longer than 64 bits then that makes the routing much more compute-intensive. 64 bits in the local part of the address is sort of overkill, but a 128 bit address isn't really any harder to use than a 96 bit address, and it means things like, well, being able to automatically assign the local part based on the MAC address, which only works if the local part of the address is more than 48 bits.
- londons_explore 3y agoYou can still use a shorter hash of the Mac address. Collisions are very unlikely, and a quick ARP packet should detect them if they do happen.
- pantalaimon 3y agoThere was a proposal for that: https://www.ietf.org/archive/id/draft-mishra-6man-variable-slaac-08.html https://www.ietf.org/archive/id/draft-mishra-6man-variable-s...
- ta1243 3y agoBut they aren't all /48s. Upthread there's a post about /16s already being allocated.
- avhception 3y agoI still haven't figured out how to get these auto-configured addresses into my home network's DNS (or any DNS, for that matter).
- soupbowl 3y agoIt is pretty easy on OPNsense but it's virtually impossible on many other types of routers. Meraki and Asus as two examples of that.
- avhception 3y agoI'm actually running dnsmasq from a FreeBSD host. How would dnsmasq know about the self-configured addresses? I guess I could run DHCPv6, but it's next to impossible to get any kind of prefix delegation going with my ISP anyway. At the moment their router hands out the v6 addresses and I use v4 for dnsmasq.
- mort96 3y agoI don't understand why getting rid of DHCP is desirable. DHCP provides a nice central place where you can map MAC addresses to IP addresses instead of configuring it ad-hoc on every device which needs a static IP address (if you're lucky and the device even supports static IP!). Checking "Does my interface have an IP address?" is also a really really useful and quick analogue for "is the gear related to the LAN pretty much working or is something broken/misconfigured?". As it is, all my interfaces just have these random IPv6 addresses configured which don't work most of the time. I don't get it.
- dijit 3y agoFWIW; SLAAC works by setting the local part to the mac address. So, if you have knowledge of your mac address (which is what you say you are using for DHCP) then you will know the fe80::<> IPv6 IP too, which, while not globally routable is probably what you want based on this comment.
- mort96 3y agoWait SLAACs aren't globally routable? I thought the whole idea behind IPv6 was to not use NAT?
- dijit 3y agoThere's an education here that unfortunately I don't have the time to give you. SLAAC is the replacement for DHCP, it provides a local prefix address (fe80::) and optionally (and, crucially: additionally) provides a publicly routable IP if there's a public prefix available. You can think of the subject being split into two components: As a base: You will get a local IP On top: you get DNS/Public routing. Here's a bit more about how it works: https://www.networkacademy.io/ccna/ipv6/stateless-address-autoconfiguration-slaac https://www.networkacademy.io/ccna/ipv6/stateless-address-au...
- throw0101d 3y ago> Wait SLAACs aren't globally routable? It is not the host-component of IPv6 that determines routability, it is the prefix. If you have a link-local prefix (fe80::/10) then it is not global, if it is a private prefix (fc00::/7) then it also may not be global; if it is part of IANA's unicast allocation (2000::/3) it is global (firewall permitting).