12 ms·
Do You Need IPv4 Anymore?
- superkuh 2y agoYes. It's a bit like, "Do you need a car?". If you're only going very popular places public transport might work. But to be able to surf the 'net you need ipv4.
- deleted 2y ago[deleted]
- p_j_w 2y ago>If you're only going very popular places public transport might work. This exception doesn't apply to cities that have their acts together.
- munchler 2y agoRight, as long as you don’t try to visit less-developed areas outside the city.
- mcpherrinm 2y agoWell, as this post discusses, the end devices don’t need IPv4 to talk to IPv4-only services.
- superkuh 2y agoYou do though. It's only consuming generic content from generic websites that works with ipv6 cnat. Try to actually participate in the 'net (ie, host a video game server, do some peer to peer task, port scan to explore, etc) and you find out very fast you have no ports and can't do anything. "End devices" are not mindless consumers of content like this very naming and article suggest. They are participants in the internet, if you let them. It's a shame kids are growing up today without being able to participate. Most are going to be intellectually stunted by it.
- mcpherrinm 2y agoThere’s not enough v4 addresses to go around, so if you want to “participate in the net”, then the approach of assigning public IPv6 addresses to end devices is better, not somehow worse.
- greyface- 2y agoThe article accepts this premise, but argues that you only need it on the provider's edge, not on end-user devices. > First of all, let’s start with stating the obvious: most devices will have to talk to legacy services. This post will not argue against this, despite excuses for this decreasing. > Luckily, IPv6-only devices can still talk to IPv4-only ones, and this is getting easier than ever before.
- jrm4 2y agoTo me this feels like "stop driving that car and fly this plane instead!"
- cjen 2y agoI was surprised today to find that Spectrum doesn't enable IPv6 by default. Only figured this out after way too long trying to ssh into my IPv6-only Hetzner instance. Ended up just paying for an IPv4 address to avoid the hassle. I don't think this is "the year of IPv6" but it might be its decade.
- qazxcvbnmlp 2y agoI was dealing with this the other day. Spectrum was giving me IPv6 - annoying when developing an IPv4 service. Ended up switching router to one that only support IPv4 and it reverted back to IPv4. If I plug my MacBook directly into the modem, get ipv6.
- eqvinox 2y agoIt seems you're running a "service" on a customer line? That's not exactly what they're selling them for... (Though I agree there should be no such distinction, in a real P2P internet)
- raddan 2y agoSpectrum also sells business internet service, where you can have static IPs, speak to real engineers, etc.
- eqvinox 2y agoI'm hoping/assuming/guessing those won't have that odd IPv4/IPv6 switching behaviour...
- nobody9999 2y ago>I'm hoping/assuming/guessing those won't have that odd IPv4/IPv6 switching behaviour... As a Spectrum Business customer, I wish I could tell you whether or not that was true, but IPv6 isn't available to me at all. I'd happily (okay, not happily, but I'd be willing to do so) pay for an IPv6 block (I currently pay for five static IPv4 addresses -- one of which is eaten by Spectrum's required router, the other eaten by my own router, but that's a different discussion..Grrr!), but I can't even do that -- as it's not even on offer here (NYC). It seems that there's wide disparity in how/where Spectrum implements its IPv6, so YMMV.
- move-on-by 2y ago> Since a lot of mobile networks (5G, 4G, etc.) in the world are IPv6-only, and have no IPv4, there’s luckily a solution for this already. Ha! I have an iPhone 15 and when I switch to mobile I get an IPv4-only address! My mobile provider is Verizon. I assume results are going to vary drastically based on region. I feel there are a lot of assertions in this article without any real data to back them up. If it makes any difference, AS6167.
- kingforaday 2y agoIn your case is it CGNAT IPv4? Typically see that these days on mobile or cellular based ISP carriers.
- move-on-by 2y agoI don’t believe so. The netblock is 174.192.0.0/10. I think CGNAT is all 100.64.0.0/10?
- deathanatos 2y agoNot the parent, but in my case, it's a DS-Lite address.
- betaby 2y agoIt's 464XLAT most of the time for mobile operators.
- jdofaz 2y agoI get IPv6 on verizon
- brirec 2y agoI have IPv4-only AS6167 on my Verizon iPhone as well, but I was under the impression the reason I only have IPv4 is a limitation from also having a static IPv4 address on my phone.
- throw0101c 2y ago> Ha! I have an iPhone 15 and when I switch to mobile I get an IPv4-only address! My mobile provider is Verizon. APNIC 34 (2017) presentation on Verizon and IPv6: * https://www.apnic.net/wp-content/uploads/2017/01/vzw_apnic_13462152832-2.pdf https://www.apnic.net/wp-content/uploads/2017/01/vzw_apnic_1... Also, a 2017 presentation on T-Mobile US going IPv6-only: * https://www.youtube.com/watch?v=nNMNglk_CvE https://www.youtube.com/watch?v=nNMNglk_CvE
- loeg 2y agoMy ISP is still IPv4 only, sadly. So, yep.
- NewJazz 2y agoName and shame! Also ask nicely, maybe today'll be the day they offer up a v6 route :p
- cchance 2y agoIf your getting a public IPv4 i wouldn't be complaining lol, if it's cgnat or ds-lite or something then sure bitch, but if your ISP has the ip space to give you public IPv4 for free i'd be happy lol
- spurgu 2y agoIPv4 will be around forever. It'll just get more expensive.
- kingforaday 2y agoStill lots of dark areas [1] and lots of unnecessary allocated space to original adopters. I wonder if the Governments will ever exercise an Eminent Domain on IPv4 one day? 1. https://www.caida.org/archive/id-consumption/census-map/ https://www.caida.org/archive/id-consumption/census-map/
- jsheard 2y agoA lot of those early adopters are self explanatory but how did Ford end up with an entire /8? Merck and Eli Lilly? Prudential?
- jdsully 2y agoThey asked for it and at that time you didn’t really need to justify it.
- deleted 2y ago[deleted]
- eqvinox 2y agoThere is no government control on IP address space. The only actual binding is to the 5 RIRs*, and if you want to see how eminent domain would fare there... Take a look at the current AfriNIC situation :( (* Legacy space doesn't even have that)
- kristopolous 2y agoAnd certainly on local networks. It's way more convenient to work with. The only thing I can see replacing it is if something I'll call "easyip" came around - something even more convenient than ipv4 for networks of under, say a few hundred devices
- djha-skin 2y agoI find IPv6 to be a very mobile centric technology. As a back-end developer and infrastructure engineer I don't see the point of it. If I used IPv6 everywhere in my server room outsiders could see the topology of my internal Network. NAT isn't an annoyance on the server side, it's a requirement for security. I have yet to meet an infrastructure engineer or even hear of one who switched to IPv6 on purpose because they thought it was better. They always switch because they have more than 65k servers or to support mobile better. I feel like the people in charge who say that we should all move to IPv6 are the same people that we should that say we should all move QUIC and for the same reason: mobile clients like it better. But it's just not useful on the server side.
- shrimp_emoji 2y agoDo security properly. You're just relying on a kludge that fucks up addressing which was only invented because there weren't enough addresses.
- thriftwy 2y agoProper security is when everything is closed off and inaccessible by default. IPv6 where your home network or backend infrastructure is a transparent glass house is a failure by design. I hope I never get to be a DevOps and support that. Or have IPv6 in my home network. One bad firewall rule or insecure port open, and you get ransomware in your face.
- NewJazz 2y agoProper security is when everything is closed off and inaccessible by default. I have met a lot of infrastructure engineers who do that... then never give the people who need access access. So the system just sits and collects dust. You have users. Acknowledge them. The network shouldn't even be the primary security boundary to begin with. One bad firewall rule or insecure port open Firewall !== routing. Nobody said you can't run a border firewall on your home network.
- 2y ago
- Am4TIfIsER0ppos 2y agoYes because 6 is garbage around here. 2+ minutes to establish a connection to some servers. The comparison with public transport in another comment is apt. The bus is only once an hour.
- mtmk 2y agoReminds me of the day when RIPE NCC announced that they had run out of IPv4 addresses. [1] [1] https://www.ripe.net/manage-ips-and-asns/ipv4/ipv4-run-out/ https://www.ripe.net/manage-ips-and-asns/ipv4/ipv4-run-out/
- m3kw9 2y agoGlad the title wasn’t “IPV6 is all you need”
- M2Ys4U 2y agoHalf[0] of AWS's services don't work with IPv6, despite Amazon charging extortionate rents on IPv4 addresses. So... yeah, for that reason I do need to keep using IPv4, at least until either 1) AWS gets its act together; or 2) my employer moves away from AWS (which is very unlikely). [0] Hyperbole... but probably not that unrealistic.
- db48x 2y agoYea, the AWS situation is pretty dumb. We know full well that under the hood, every component that Amazon uses to build those services supports IPv6. When you star using some AWS service, it starts up a fleet of compute instances behind the scenes to handle the traffic you’re going to send it. If the developer of the service remembered to check the “IPv6” checkbox for those instances then the service will support IPv6, otherwise it won't. But as the article points out, it doesn't really matter. You could run a NAT64 service of your own, inside the VPC that AWS gives you. Your own systems can then be IPv6–only, saving you money while still using AWS services that still don't support IPv6.
- zhuzhu 2y agoCan you tell github about this?
- zhuzhu 2y agoCan you tell Github about this?
- mdaniel 2y ago$ dig -t AAAA gitlab.com. gitlab.com. 300 IN AAAA 2606:4700:90:0:f22e:fbec:5bed:a9b9 It's not that I excuse them, and doubly so now that they're owned by Microsoft (which for sure supports IPv6 on their control plane), but I'm just saying they're not the only game in town
- mastax 2y agoRelated question: I asked my ISP for IPv6 and they gave me a static assignment like this: WAN: A:B:C:D::1/126 LAN: A:B:110::/48 I tried to read up on this but am still confused. Why are they giving me WAN and LAN addresses? I thought the whole point of IPv6 is that you give your devices publicly routable IP addresses. If an address is publicly routable, what's "LAN" about it? I haven't been able to find a working configuration for Unifi, though their IPv6 support is like 20% implemented at best. And no, the LAN subnet isn't in the ULA or link-local space.
- Arnavion 2y agoTraffic for that /48 will be routed to your router. You're free to divvy up that /48 into /64 subnets on your LAN. Eg you can make one subnet A:B:110::/64, another A:B:110:1::/64, and so on all the way to A:B:110:ffff::/64. ("Making a subnet" == setting up at least RA to advertise that prefix, along with DHCPv6 / SLAAC options as you want.) Then LAN devices on those subnets can use any IP in the /64 for themselves. In your case it's a static assignment, but otherwise it can be assigned via DHCPv6-PD (when your router asks for a WAN IP using DHCPv6, it also gets told that some prefix like your /48 has been "delegated" to it). The result is the same.
- mastax 2y ago> Traffic for that /48 will be routed to your router. Okay, now it makes sense. I'm not sure how else I expected it to work.
- xnyanta 2y agoIf you want your devices on your LAN to have publicly routable IP addresses, by definition they need to be GUA. I think you just mis-understand what end-to-end connectivity means. Your "WAN" is a small transit subnet between your router and your ISPs, while the "LAN" is the actual public ip space you will be assigning to your end devices. >If an address is publicly routable, what's "LAN" about it? Routable or not, it's LAN because it's in your network behind your router. It's just an identifier.
- deleted 2y ago[deleted]
- turnsout 2y agoI run a server and have yet to adopt IPv6. My logic is: people can type in a URL and get to my site. Am I missing out on anything by continuing to pretend that IPv6 doesn't exist?
- patrakov 2y agoYes. You are missing out on information security auditor complaints. They are happy now because your server complies with one more bullet point (in particular, 3.7, "Disable IPv6") from the CIS benchmark: https://github.com/skylens/CIS/blob/master/CIS_Distribution_Independent_Linux_Benchmark_v2.0.0.pdf https://github.com/skylens/CIS/blob/master/CIS_Distribution_... /sarcasm
- ianburrell 2y agoThe big reason to support IPv6 to learn about it and get ahead of the curve. If your hosting provider support IPv6, it should be easy to add IPv6 address to server and DNS. You will also need to check your software doesn't assume IPv4 addresses. With single server, there aren't the networking advantages to using IPv6 internally.
- chaz6 2y agoAs new ISP's and enterprises start up who cannot obtain legacy IPv4 address space, there are going to be more and more people who will not be able to access an IPv4-only resource without using some form of tunnel.
- turnsout 2y agoIf you can’t access IPv4, I don’t think you’re going to make it as an ISP
- orangeboats 2y agoSome ISPs are now providing "IPv4 as a service", i.e. they are IPv6-only throughout their entire network infra and can easily pull the plug on IPv4. "When" is the only remaining question.
- deleted 2y ago[deleted]
- slotrans 2y agoI can't reach any IPv6 addresses from Comcast/Xfinity soooooo...
- ianburrell 2y agoDid you enable IPv6 on your router? A lot of routers ship with it disabled. Comcast has supported IPv6 for a decade. I've been using it that long, I'm using it access this site.
- labcomputer 2y agoErr what? I won't say many nice things about Comcast, but they treat IPv6 as a first-class network citizen and actually follow all the best practices for IPv6 (like DHCP-PD'ing /56's by default). Their support for IPv6 is top notch.
- 1vuio0pswjnm7 2y agoNo SNI: https://web.archive.org/web/20240411000150if_/https://blog.daknob.net/do-you-really-need-ipv4-anymore/ https://web.archive.org/web/20240411000150if_/https://blog.d...
- kkfx 2y agoI do not need IPv4, BUT I need IPv6 with a global per host, without tricks to avoid my free use of hosts, just to keep the users "a bit out of internet"...
- beAbU 2y agoI recently moved to Ireland. Here I have Virgin Media fiber, and I was pretty upset to learn the router was very locked down, and I can't even port forward. I have a bunch of services that I host from home, and with my previous provider (and country) I had a static IP with all the associated DNS and DMZ stuff to make it work. I was about 2 days into a VPN rabbit hole when I discovered that Virgin gives out IPV6 AND IPV4 IPs, and that the v6 ones are publically routable! I was able to access my hosted service by plugging in the server and going to it's IPv6 address on my phone. Some quick Cloudflare IPV4 to IPV6 proxying later and I'm up and running as before. Can now access the service from any internet network (even IPV4 ones). No more DMZ, port forwarding, etc. Happy days. So yes, I moved away from V4 in about an afternoon, no issues. I'm not sure if the IP is static though. The server has a reserved V4 IP for internal stuff, I hope the router is clever enough to then keep the V6 one also static. With the address space being so large, I guess giving clients entire blocks of addresses that are static is perfectly fine?
- oguzkonya 2y agoDo you have a blog post or something detailing your experience? I'm in the exact same situation (Ireland, Virgin, self-hosting) and after a week of struggling I couldn't find a way to expose my services. I'm happy to run everything locally at the moment as I only have a media server but I'm interested in running a few websites and services.
- smackeyacky 2y agoTailscale can solve this problem
- deleted 2y ago[deleted]
- beAbU 2y agoIs it possible to use tailscale to punch out to the public internet, having the service available behind normal DNS, accesible by clients that are not part of your tailnet?
- exabrial 2y ago[flagged]
- JackSlateur 2y agoHave you ever managed a compagny-sized network ? No you didn't, or you'd know the bunch of real-world issue IPv6 solves. Also, IPv4 has nothing to do with "identification", does not work like that, is not used like that, does not matter in any ways, nor does ipv6
- exabrial 2y agoYes, roughly 8,000 clients, 4 remote sites, 2 clouds, 2 colos, one private datacenter, for a major financial firm. The whole thing was much easier on a single protocol stack: only one set of firewall rules to manage.
- orangeboats 2y ago>do you really think Roomba is going to allow you to directly connect to your vacuum without going through them? Absolutely not, they will _never_ give up that control. This is such a strange chain of reasoning. 1. With IPv4, IoT management must go through a centralized service due to NATs. 2. With IPv6, IoT management may go through a centralized due to corporate greed. You see the difference there? This reasoning is unsound because it's more or less "we shouldn't eat because we'd choke on food". >Ipv4 is a very important protocol because it accidentally protects against casual identification from the Facebooks, Apples, Googles, Amazons, etc Coincidentally, if the world is stuck on IPv4 then hobbyists/"privacyists" will be the group of people who are hurt the most. Hosting a service is becoming more difficult when CGNAT is imposed on everyone, everywhere. It shouldn't be difficult to imagine a future (as a matter of fact, it is happening now) when, to host a server, you _must_ rent a VPS or something from the tech companies since it's impossible to do it from home. Does your VPS provider allow you to host Tor services? Run BitTorrrent?
- hitpointdrew 2y agoNo one will ever convince me that running a local IPv6 network is a good idea. IPv6 from your ISP, fine, but once internal IPv6 is overly complex and unnecessary. Despite the claim to the contrary NAT is a feature, not bug. The future for IPv6 is that Firewalls/Routers will handle IPv6 for the public addressees, then NAT to internal IPv4's.
- orangeboats 2y agoComment #42069 on "HN doesn't understand the Internet Protocol". This opinion is frequently repeated here on HN but -- you CAN'T use IPv4 internally and expect to talk to external IPv6 hosts. How would this IPv4 internal host (say 192.168.1.10) send a packet destined to 2001:db8::1? You can't stick a 128-bit IPv6 address into your IPv4 packet - there are only 32 bits available for the destination address inside its header. NAT is not magic, it cannot extract a 128-bit number out of your 32-bit number.
- hitpointdrew 2y agoThis patently false, you should do more research before you make comments to inflate your ego. For your education: https://en.m.wikipedia.org/wiki/NAT64 https://en.m.wikipedia.org/wiki/NAT64
- orangeboats 2y agoIronically, you are the one who needs to do more research. I have deployed NAT64 in multiple networks before. NAT64 is used when you have _internal_ IPv6 hosts who want to reach the _external_ IPv4 hosts. In order words, 2001:db8::1 can send something to 198.51.100.1 but not vice versa. Your proposal is that we use IPv4 _internally_ since you think "internal IPv6 is overly complex" and we should "NAT to internal IPv4's". It doesn't exist since IPv4 is inherently forwards incompatible. "HN doesn't understand the Internet Protocol" strikes again.
- ianburrell 2y agoIPv6 internal network is simpler and probably a good idea for a brand-new network. The big advantage is that don't have to worry about subnet size. No deciding how big subnet is going to be, and either making it too small and having to resize or making it too big and wasting space. IPv6 is more complicated in that supports multiple addresses, but that is an advantage. For internal use, assign ULA addresses and route those over VPNs. For accessing Internet, computers use the ISP assigned addresses. Then assign fixed addresses from hosting provider to load balancers and external servers. This means that only Internet only sees random addresses; they know the provider but that is known with IPv4.