7 ms·
Show HN: A Short IPv6 Guide for Home IPv4 Admins
- imoverclocked 2y ago> Some runs of zeros can be condensed as ::. Only one run of zeros can be condensed as :: because two or more would be ambiguous.
- Latty 2y agoI believe the point the post is making is that there are some runs of zeros that can't be condensed, not that you can condense multiple runs in a single address.
- ThePowerOfFuet 2y agoAll runs can be, but you can pick only one, so you should do pick the longest one.
- Latty 2y agoTo be clear, I think the technicality the author is alluding to is that it is not all runs, because some runs of zeroes are significant, you can't condense the zeroes in "ff00:..." for example, for obvious ambiguity reasons. I believe using "some" was just a way to allow for that while not describing the rules in detail.
- redundantly 2y agoIt's weird. Personally I've yet to make the jump to IPv6 because it seems too complex, doesn't make sense, so I don't want to spend the mental effort learning it when I have no need to switch. However, looking decades back I realise I felt the same way when first learning about and working with networks. Nothing about it is intuitive. It's all complex, until it isn't through repetition and familiarity. That said, I still don't want to spend the mental effort on IPv6 yet. I'll deal with it when I have a need for it.
- jetbalsa 2y agoIm kind of in the same boat, I'm on a CGNAT with a apartment community, they don't have IPv6 at all, matter of fact they barely VLAN the apartments / wifi apart. I've rick rolled the entire complex's chromecasts before
- m463 2y agoI hate this trend. It's also impossible to get a static ip address.
- hot_gril 2y agoI'm ok with the opinionated kind of ipv6 this guide puts forth. There are too many other ways to use it that have problems.
- m463 2y agoI think ipv4 is way more manageable. One set of firewall rules, easy to view ip addresses, machines don't leak. I would put the extra braincells to work learning vlans. putting machines in jail is a liberating experience. You can also learn to use privoxy to control IF machines have internet access, who they talk to and when.
- anthropodie 2y ago> I think ipv4 is way more manageable. That's because it's familiar and comfortable. Once you get hang of IPv6 you dislike the idea of fiddling with numbers as protocol takes care of most of things.
- m463 2y agodon't you still have to do ipv4 too? my static ip addresses are ipv4.
- cassianoleal 2y ago> don't you still have to do ipv4 too? This is quite a loaded question. You need some sort of IPv4 to access the IPv4 Internet. You need some sort of IPv4 if you have devices that don't support IPv6. What you need in each case depends. If it's just to access the IPv4 Internet, you might get away with NAT64 and a single public IPv4 on the WAN interface. > my static ip addresses are ipv4. Ok? You can have static IPv6 addresses if you want.
- imoverclocked 2y ago> After your router connects to your ISP, the router can ask for prefix delegation. Some providers (eg: Starlink, when I last checked and a Calyx WiFi hotspot) will only advertise a prefix. I was forced to figure out a way to bring the /64 that is in front of my router (Linux iptables) and expose it to a LAN behind my router. It looks something like [1] Depending on your setup, there may be an easier solution. [1] http://imoverclocked.blogspot.com/2022/05/ipv6-wifi-access-point-nftables-and.html http://imoverclocked.blogspot.com/2022/05/ipv6-wifi-access-p...
- wmf 2y agoIt sounds like you're talking about running a router behind a router which you should try to avoid. If you want to run your own router you should try to put your modem/dish in passthrough mode. Once you do that Starlink works fine.
- imoverclocked 2y agoI would except I have multiple networks that I keep isolated from each other. Also, you can’t pass through from a WiFi connection to an Ethernet network as was my setup with Calyx and Starlink before I had an Ethernet connection.
- move-on-by 2y agoThis assumes your ISP provided modem isn’t straight up user hostile and provides a pass through mode. I’m convinced t-mobile’s awful home internet modem/router is intentionally designed to make using your own router difficult and specifically only provides a /64 prefix delegation to prevent any router-behind-router setups from getting globally routed IPv6 addresses. Not to mention no port forwarding capabilities.
- imoverclocked 2y agoMy blogpost shows how to get around that using an ndp proxy. All my hosts have global IPv6 behind my own router+firewall with only an advertised /64 in front of it. :)
- mannyv 2y agoHow do you run a DNS server when your address isn't technically static? How do clients discover the DNS server in a SLAAC environment?
- wmf 2y agoHow do you run a DNS server when your address isn't technically static? For Internet-facing DNS you don't. For your internal resolver you could create a static address within a ULA (e.g. $PREFIX::1). How do clients discover the DNS server in a SLAAC environment? https://www.rfc-editor.org/rfc/rfc8106.html https://www.rfc-editor.org/rfc/rfc8106.html
- hairyplanter 2y agoRA message can specify a DNS server. Mine specifies the router's ULA, which is effectively static, and it runs unbounded.
- anthropodie 2y agoSomeone correct me if I'm wrong Your link local or ULA is static address and can be used for DNS. DNS server is advertised when prefix is advertised.
- labcomputer 2y ago1. You create a ULA prefix (fc00:/7) on your local network. See https://en.m.wikipedia.org/wiki/Unique_local_address https://en.m.wikipedia.org/wiki/Unique_local_address 2. Then you have your router advertise that prefix. 3. Then you have your DNS server pick a non-temporary address within that prefix (either manually set it, or let the OS pick one). 4. Then you tell your router to advertise that address as the DNS server in the RA. Depending on how you have your network set up, your DNS server will have probably four IPv6 addresses: A link-local one; one on the ULA prefix you created; a non-temporary address on the prefix delegated by your ISP; and one or more temporary addresses on the prefix delegated by your ISP. Outgoing connections (for recursive resolving) will be on one of the temporary addresses from the PD prefix. The DNS server listens on the static ULA address. You need to configure your firewall such that traffic from the delegated prefix can get to the ULA one, and vice versa. This usually just means blocking traffic from the WAN port to the ULA prefix.
- chadsix 2y agoThere are definitely easier ways to get IPv6 if you don't want to deal with the networking. I feel like I'm doing a lot of plugging of IPv6.rs [1], but I guess that's a testament to just how much demand there is for IPv6. [1] https://ipv6.rs https://ipv6.rs
- yjftsjthsd-h 2y agoSo it's like Hurricane Electric but more expensive?
- imoverclocked 2y agoSite local is useful to know about, even if it is technically deprecated. I explained it [1] for a test-setup that has no actual IPv6 connectivity. Without a non-link-local IPv6 address, resolvers will often omit IPv6 addresses in their response. Another big difference between IPv4 and IPv6 is in the localhost address scheme. IPv4: 127.0.0.1/8 - 24 bits of free addresses IPv6: ::1/128 - no free addresses Many people won’t care about this but some local hacks make use the localhost address space for fun and profit. [1] https://github.com/suntong/dbab/pull/10#issuecomment-1603857583 https://github.com/suntong/dbab/pull/10#issuecomment-1603857...
- zdw 2y agoIf you want to run authoritative DNS on your home network and have AAAA lookups for local machines, how do you go about this? Assign the DNS entry just to the ULA of each host?
- khrbtxyz 2y agoReturning both the ULA and global addresses should be okay. This is what my OpenWRT router does without any special setup. wk1 is one of my local machines. $ dig +short wk1 AAAA @192.168.1.1 2601:646:... fd7c:b0fd:fd6a:1::ba5
- hot_gril 2y agoI'm a home ipv4 admin. What I or someone similar would need is the last part that shows how you set up a basic network with some local addresses I care about and a few I want to expose publicly. It's nice that the guide includes the concepts, but the first thing anyone will want to do is just make it work. Step 2 says to set up ULAs. Are these static or dynamic? It says "don't pick numbers." If dynamic, how does step 5 work? If static, what about visitors in my house? Step 3 mentions a LAN DNS. Where do I set that up? I don't recall my router having that option somewhere, and I'd rather not rely on a machine for it.
- wmf 2y agoThese steps depend on whether you're using networkd, netplan, NetworkManager, ConnMan, etc.
- hot_gril 2y agoHuh, whether these addresses are static or dynamic shouldn't depend on that. I just have a typical router at home with a web portal, is that insufficient?
- hairyplanter 2y agoStep 2 answer: To set up ULA, just assign ULA you want to your LAN interface. Default radvd.conf will now advertise that ULA prefix to the lan, and your hosts will auto configure. Are they static? Yes, in the sense that they don't change. Are they dynamic? Yes in the sense that you didn't have to configure the host manually, it just did slaac. Once a host picks a ULA (prefix + id), you can get that from the host. It's the same as getting a mac address of a machine, but instead you get the ULA, and add it to your firewall rules. Step 3 answer: I run unbounded on the router.
- hot_gril 2y agoThanks, I get it now. Guess LAN DNS can be optional since the ULAs can be memorized.
- devman0 2y ago
- philsnow 2y agoHow does this: > With IPv4, when your router connects to your ISP, you get one public address for the WAN, and you use a picked private address like 192.168.0.0/24 for your LAN. With IPv6, since you want a globally routable address for hosts on your LAN also, you need to ask the ISP for a routable prefix. jive with this: > You want to use these ULA for all your LAN communication. If you want to reach your printer or a media server, put their ULAs in the DNS and not the globally routable one. Why have globally-routable IPv6 addresses if you're not going to use them? I was put off initially by the first quoted paragraph because while the hard-outside-chewy-center security model is not a strong model, it is easy to reason about especially when you have very heterogeneous devices on your home LAN, including ones you don't control the OS of. I like using private addresses for my home LAN and even if I had an IPv4 /24, I wouldn't give addresses from it to machines on my LAN. I use wireguard to access things on my LAN, with a somewhat-janky split-horizen DNS setup where the DNS server is on my LAN, so I have to be connected to wireguard to even resolve the names.
- anthropodie 2y ago> Why have globally-routable IPv6 addresses if you're not going to use them? Because globally routable addresses are not static. Your prefix may change.
- philsnow 2y agoI guess I mean, the gist only motivates the use of globally-routable addresses for externally accessible services. If a particular service/device isn't going to be accessed externally, there's no need to give it one.
- cqqxo4zV46cp 2y agoA big part of why I see people talking past each other on this is, IMO, because the solution that seems ‘cleaner’ depends on one’s mental model of networks / IPv6. These can and do differ. One person’s “I need justification to have non-globally-routed addresses” is another person’s “I need justification to have anything else”.
- rkagerer 2y agoCan someone elaborate on this: For a given prefix, the interface will always pick the same identifier, (in fact, the eui-64 algorithm will pick the same identifier across multiple prefixes) How does the algorithm typically work? Is there a loss of privacy since identifiers are reused across prefixes? If I replace my NIC or install a different OS on my machine will the address change?
- hairyplanter 2y agoEUI-64 uses the NIC MAC to derive an address. Linux by default uses it, and it's fine for servers. There are other more privacy sensitive ways to generate obfuscated addresses. But none of these matter, because RFC 4941 says a new random address is used for each request. If you surf the web on a server with a static address, it'll create hundreds of temporary, random addresses to make requests from. The server is reachable by the static address, but outgoing requests come from a random address. I know, weird, right? Concept 2: IPv6 uses multiple addresses. Yes, if you replace the NIC, the address will change. Different OS won't, if it uses EUI-64.
- anthropodie 2y agoAn IPv6 device will use the MAC address of its interface to generate a unique 64-bit interface ID.
- yjftsjthsd-h 2y agoAn ipv6 device can use its MAC address, but these days is more likely to generate one in a way that's more privacy preserving.
- deleted 2y ago[deleted]
- alsetmusic 2y agoI've just got back into building a homelab after a multiyear break. I think I last worked on such a project in 2017. In the time between then and now, I still don't know why I would want to utilize IPv6 on my home network. And my network is necessarily more complicated than most users by extension of the homelab (switches, hypervisors, VM's, etc). I imagine I might be able to go looking for an answer to why I'd want this, but I would have expected the case to have been made casually by now if it had any utility in my home. I never stopped reading technology and computing sites during my sabbatical, though they did become more mainstream. Yet I still have no clue why I'd want this on a home network. This seems like a solution in need of a problem (in the home – I'm not discounting the utility on a global scale).
- deleted 2y ago[deleted]
- hackeraccount 2y agoI think there are problems with ULA. https://blogs.infoblox.com/ipv6-coe/ula-is-broken-in-dual-stack-networks/ https://blogs.infoblox.com/ipv6-coe/ula-is-broken-in-dual-st... I've seen some of that - that said I can't figure out how I'm supposed to do DNS registration with GUA addresses. The only way I know to register addresses in DNS is with DHCP. Should I just have my IPv6 DHCP server advertise the GUA addreses? Is there some other way to do this? I'm actually genuinely confused about this.