17 ms·
I have fully implemented IPv6 in my home network. I have even implemented an IPv6-Only network. It fully works, including accessing IPv4 only websites like git
by hairyplanter 2y ago
I have fully implemented IPv6 in my home network.
I have even implemented an IPv6-Only network. It fully works, including accessing IPv4 only websites like github.com via DNS64 and NAT64 at my router.
The only practically useful thing about my IPv6 enabled network is that I can run globally routable services on my lan, without NAT port mapping. Of course, only if the client is also IPv6.
Other than this one use case, IPv6 does nothing for me.
It doesn't work from most hotels, nor from my work lan, nor many other places because most "managed" networks are IPv4 only. It works better at Cafes because they are "unmanaged" and IPv6 is enabled by the most common ISPs, like ATT and Comcast and their provided routers.
Based on this experience, I think IPv6 is less valuable than us HN audience thinks it is. Private networks, NAT, Carrier Grade NAT are good enough, and internet really doesn't care about being completely peer-to-peer.
I think the adoption rate reflects this--it's a linear growth curve over the last 25 years. It should have been exponential.
I think cost of IPv4 reflects this--it is now below the peak, and has leveled off.
As surprising as it seems, IPv4 exhaustion has not been a serious problem. Internet marches on. IPv6 is still a solution looking for a problem, and IPv4 exhaustion wasn't one of them.
- Dylan16807 2y agoNAT is mostly okay, but carrier grade NAT where you can't forward a port causes real problems. IPv4 exhaustion is a real problem, it's just not enough to motivate people much.
- saurik 2y agoHave you tried using PCP to forward the port? I was under the (maybe-incorrect, and if so I would really like to learn) impression that most major CG-NAT setups supported it.
- Dylan16807 2y agoI suppose I can try that some time. I can find absolutely zero mentions of that for the ISP, just the option of buying a static IP.
- kortilla 2y agoNah, many carriers don’t support it. I’ve always had to resort to STUN
- matrix2003 2y agoSTUN also isn’t guaranteed if the router is strict. IPv6 removes a lot of these unknown and strange ways that IPv4 infrastructure can break things.
- kortilla 2y agoYep, my point was just that STUN works far more frequently than explicit port forwarding protocols. Part of the reason (for better or worse) is that most major console networks (Xbox live, PSN, etc) will grade your connection poorly if STUN doesn’t work. Customers who otherwise don’t know about networking do complain to ISPs about this sort of thing.
- orangeboats 2y agoPCP is not widely deployed in South East Asia at the very least. Relying on it is not feasible.
- kijin 2y agoIf it was a real problem, market pricing would reflect the increasing severity of that problem. The truth is that people who care about port forwarding are such a small minority -- especially now that P2P file sharing has lost its hype -- that they don't make a visible dent in the rate of IPv4 exhaustion.
- Dylan16807 2y agoThe market price is only something like 5 or 10 dollars a month, but anyone having to pay that to be accessible is an embarrassing failure of the system. It doesn't matter whether it's a big dent in the number of IPs or not.
- kijin 2y agoThere are billions of people out there who can access the internet, and make themselves accessible through the internet the way they want, just fine without a dedicated IP address. Maybe you have a definition of "access" that is different from the usual one. That's fine, but let's be honest, it's not the usual definition.
- Dylan16807 2y agoSomeone being able to connect to their device is the definition I use. What's your definition? Being able to relay through a third party is a different thing.
- minitoar 2y agoMost people are totally fine relaying everything through a third party. A vanishingly small number of email users host it themselves.
- IcePic 2y agoBut is it "well off people not having a problem paying a buck or two directly or indirectly to an american corporation to be able to bounce traffic" which you refer to as "most people"? I can see how a few billion other people would have problems with that concept for many reasons apart from the obvious financial one. And for everyone that does pay this "internet tax", it only strengthens the position of said corporations to be able to buy up even more of the available routable ips. It's not hard to see that the end result is very much not in the consumers favor, regardless of how unnecessary it feels for customers currently to have a real ip when all they want is kitten animations on social media.
- arp242 2y agoThe main problem I had when I was on CGNAT was not so much port forwarding (annoying, but solvable), but with being banned from all sorts of stuff. The address is shared with so many people and one person did something stupid or malicious or whatnot. Sometimes you don't even know if you're banned or not. For better or worse, IP blocks are still very common. It's easy to complain about this, but there aren't really any good methods to deal with persistent abuse.
- GoblinSlayer 2y agoCGNAT is a small tor.
- Arnt 2y agoAh… that makes it sound as if we've reached a phase where IPv6 has no significant problems and saves a little bother compared to IPv4. Switch to v6 ⇒ escape false alarms from tools like fail2ban.
- josephg 2y ago> IPv4 exhaustion is a real problem, it's just not enough to motivate people much. Well, its only really a problem if you're poor. Rich people don't care - IPs are still cheap enough when you live in a wealthy country & have a decent job. The people affected by IP address exhaustion are largely the exact set of people who can't do anything about it.
- nlitened 2y agoWhat country is that where poor people can’t afford an IP address? Is it a real place?
- josephg 2y agoFrom the article, IPv4 only has 3.03 billion unique, routable addresses. The world population is 8.2 billion. So there's only enough IPv4 addresses for 1 unique address per 3 people on the planet. But of course, in reality, huge swathes of the IP address range are held by big companies (like amazon), universities and the US military. Its very common for whole streets or neighbourhoods to collectively share a single IPv4 address. Its required, as a result of simple math. You'll even see this in some parts of the US and UK.
- otabdeveloper4 2y agoIn reality an IP address costs about $2 a month at market rates.
- josephg 2y agoSo? Is your argument that it’s so cheap that everyone should get an IP? That would be mathematically impossible. If more people wanted an IP, the price would just rise. The same percentage of people (less than 1/3) would have one. They would just pay more. It’s like buying land in a city like SF. Demand can change the price, but the supply remains the same.
- 2y ago
- ozim 2y agoIt is enough for Amazon/Google/FB/Netflix - they start to choke on IPv4 and they also don't want to pay up insane amounts for holding IPv4 ranges. When they switch to IPv6 they have more cheaper addressing. Once they force it down by making faster services via IPv6 all the ISPs will follow right away because everyone will want to have their Netflix/YT streams load faster.
- BrandoElFollito 2y agoI had to reluctantly deploy ipv6 on my home network because of ISP requirements + will to use pihole. Ipv6 is hard. I had to learn quite a bit to make it work and not only I see no value, but it is significantly more difficult to use dire to the address length. I think IPv6 is a missed opportunity, it was probably designed by experts that did not take into account the population that will use it (not the one users who do not care, but the layer above them)
- qwertox 2y agoWhat requirement could an ISP impose on you for you to be forced to migrate the intranet to IPv6 (because of PI-hole)? You could always place a small NAT-enabled router between your ISP's device and your home network. The only problem I could see would be the lack of a (semi-)static public IPv4 address, which one could solve by renting a VPS.
- BrandoElFollito 2y agoMy ISP is the French "Free". They provide a router that is difficult to swap with my own (it is possible, but it is way easier to switch it to a bypass mode). With this router comes a TV box that requires IPv6 to work. When I replace DHCP/DNS with Pihole I need to account for that. While this is not a complex setup once you understand IPv6 you still need to learn it. I work in IT so I tried to get myself to IPv6 several times but never had any reason to do so (despite self-hosting a lot and generally being a nerd). I had to do that this time and my uninformed opinion is that it could have been done so that it is much simpler for advanced users (but not yet networking experts)
- albuic 2y agoSo you had to learn IPv6 the same way you learned IPv4. The question is: was it harder ? It seems you wanted to know IPv6 without learning it because you thought it would be the same as IPv4. And yes the Free boxes are hard to work with if you don't want to mess with vlan and still have TV services.
- erinaceousjones 2y agoFun reasons why my home network is still on IPv4: IPv6 drains my girlfriend's phone battery :-) Something to do with Router Advertisement intervals being too short, though I don't get why that only affects her ~5yo android phone. And IPv6 is so complex, I haven't figured out if the RA interval is something I can or should tweak, whether that comes from the PiHole or whether I'd have to flash OpenWRT on my router, or whether my ISP ultimately controls that upstream. Like, I can't figure out as easily where the boundary between me and "the internet" ends with things like the /64 prefixes and SLAAC and RDNSS and all the other acronyms. Yeah, yeah, I should RTFM, and eventually I might figure out what makes a "good" home IPv6 network. But I can't be arsed to do that in my free time yet, and neither can most software companies cough cough Google/Android and that one guy causing IPv6 drama in the android team Like.... Ehhh... I'll come back to it in a few more years. "Are we IPv6 yet?"
- BonoboIO 2y agoNever would have guessed that ipv6 could be a battery drain
- kiwijamo 2y agoI have an Android on my IPv6 network with no issues, and this is across several different router vendors with different defaults for RAs. Maybe it's not an IPv6 issue and you're barking up the wrong tree?
- erinaceousjones 2y agoProbably definitely barking up the wrong tree, yes. I happened upon a forum post somewhere about Sony Xperia XA2 battery drain on networks where router advertisment intervals were every 10 seconds or something. Who knows, maybe I dreamed it. Nonetheless, I disabled IPv6 again and that, somehow, was the smoking gun that solved the "my phone always runs out of charge overnight when I stay connected to your wi-fi" problem.
- yjftsjthsd-h 2y ago> I have even implemented an IPv6-Only network. It fully works, including accessing IPv4 only websites like github.com via DNS64 and NAT64 at my router. What did you use to implement that? I found it surprisingly difficult to find software to do NAT64 on Linux.
- hairyplanter 2y agoI use tayga.
- russfink 2y agoThis was true 25 years ago and is still as true today.
- throw0101c 2y ago> Private networks, NAT, Carrier Grade NAT are good enough, and internet really doesn't care about being completely peer-to-peer. CG-NAT adds a cost that not everyone can easily afford: > We learned a very expensive lesson. 71% of the IPv4 traffic we were supporting was from ROKU devices. 9% coming from DishNetwork & DirectTV satellite tuners, 11% from HomeSecurity cameras and systems, and remaining 9% we replaced extremely outdated Point of Sale(POS) equipment. So we cut ROKU some slack three years ago by spending a little over $300k just to support their devices. > First off I despise both Apple and that other evil empire (house of mouse) I want nothing to do with either of them. Now with that said I am one of four individuals that suggested and lobbied 15 other tribal nations to offer a new AppleTV device in exchange for active ROKU devices. Other nations are facing the same dilemma. Spend an exorbitant amount of money to support a small amount of antiquated devices or replace the problem devices at fraction of the cost. * https://community.roku.com/t5/Features-settings-updates/It-s-2022-and-still-no-IPv6/m-p/854673/highlight/true#M35732 https://community.roku.com/t5/Features-settings-updates/It-s... * "Roku devices don't support IPv6 in 2023 and it's costing ISPs", https://news.ycombinator.com/item?id=35047624 https://news.ycombinator.com/item?id=35047624
- WarOnPrivacy 2y ago> Grade NAT are good enough CGNAT would cripple every customer I've ever had, going back to the beginning of broadband. Everyone one has had something on-premises that needs to be accessible. Nearly always, it's multiple things that are critical to operations. However. if someone wants to forever keep 100% of their accessible data in someone else's silos... and be forced to pay 3rd parties to access anything located on their own premises (ex:cameras) then imprisonment behind CGNAT might feel 'good enough' to them.
- koyote 2y agoI recently moved to a 'cheap' ISP because I could get double the speed for half the price. They use CG-NAT and it's been awful. I don't need to forward any ports but seemingly because I share an IP with a billion people I get Captchas everywhere (Google, Cloudflare etc.). I was even blocked from accessing Reddit without an account at some point.
- NelsonMinar 2y agoStarlink uses CGNAT. It's awful, I'm regularly getting CAPTCHAs on random websites. They now support IPv6 but only with dynamic address allocations so you don't get a lot of advantages from it.
- imoverclocked 2y agoI hadn’t put that quite together. I wonder how many people would value IPv6 if they knew it meant less CAPTCHAs.
- alwayslikethis 2y agoI'd imagine that to be short lived. IPv6 having such a huge address spaces means the IP reputations are even more worthless than IPv4 so eventually the bots would use it too, and if the ratio of bots to real users become too high sites may refuse IPv6 traffic altogether.
- matrix2003 2y agoIt’s a little different though in that rather than an IP having a bad reputation, it’s usually a /64. That’s how I have seen IPv6 reputation managed since it’s a common network slice & NAT is not really used anymore.
- preisschild 2y agoYou can block ipv6 /64 subnets just like you can block IPv4 /32 IPs.
- 2y ago
- thayne 2y agoWell there are serious network effects at play.IPv6 would be a lot more valuable if it was more broadly deployed.
- tims33 2y agoWhat do you see as the key points that create a lot more value?
- ignoramous 2y ago> internet really doesn't care about being completely peer-to-peer Internet (I mean, the IETF) does care a lot about the end-to-end principle, however. It is true that "misbehaving" NATs break e2e badly. It is also true that IPv6 can also be put behind such NATs.
- lmm 2y ago> The only practically useful thing about my IPv6 enabled network is that I can run globally routable services on my lan, without NAT port mapping. Of course, only if the client is also IPv6. A couple of other practically useful things: - You never get address collisions when connecting to someone else's VPN, or connecting to your home network via VPN from someone else's private network (if you've set that up) - If there are two people living in your home, they can play online games against a mutual friend who doesn't live in the home without anything breaking I think you're right that IPv6 isn't a game-changing improvement for most people. It gets rid of some annoyances, it's the obviously correct thing to do for new networks (and cheaper than setting up CGNAT), but fundamentally the pile of hacks on IPv4 is "good enough" for most use cases.
- ktosobcy 2y agoso for anyone that "just browses the web" (which is overwhelming majority) there is virtually no difference/benefit? I don't play online games, don't use VPN, have a couple of services on my local RPi that has port forwarded on router and that's it... ipv6 could be handy when testing some service on my laptop and trying with external services but this happens so rarely that it's not an issue... on the flipside, whenever I enable ipv6 I usually run into problems :|
- GoblinSlayer 2y agoNo gaming allowed. In true communism you don't need entertainment, because you love your job.
- ktosobcy 2y agowhat? the world doesn't end with fortnite or whatever brain-rot is currently popular (on utterly locked up platform with excessive anti-cheat)... there is a gazzilion of super entertaining games that you can play locally... :shrug:
- GoblinSlayer 2y ago
- rendaw 2y agoMy anecdote with an ipv6-only home network (linux router): Doing NAT64 runs into MTU issues and the behavior I observed is chrome would resend the request but only after 30s, firefox and other programs entirely failed to resend requests that were rejected due to MTU issues. Once I got the rejection, retrying in firefox or whatever would work though, so it seems like the path MTU was cached somewhere at the OS level. Reducing MTU manually seemed to fix the problem, but isn't that supposed to be automatic? Why didn't the kernel do the resends? Old iPads, Androids just don't work, I'm not sure why. My iPhone 11 would connect to the network but declare itself disconnected after 24h or so (some lease or dns expiry which it doesn't renew?). Steam hardcodes an ipv4 address for login... !! I'm not sure what to make of that, and the fact that it was reported around 10 years ago and they still haven't fixed it. Is it even using TLS? I needed to make docker dev containers use host networking, because otherwise they'd get ipv4 addresses and try to do ipv4 traffic which couldn't be tunneled by default over ipv6. Other than that it basically worked. There's fundamentally only two different ways ipv6 can be configured from an ISP: SLAAC with no delegation, so you essentially share a network with other customers, or DHCPv6 delegation. Unlike IPv4 which has a million different offerings: PPPoE, DSLite, MAP-E, DHCP, etc etc and many of those aren't supported by linux. I signed up with an ISP that claimed to support NAT64 (Biglobe) but they only support it on their SLAAC ipv6 + PPPoE ipv4 setup, not on their DHCPv6 PD + MAP-E setup, so I had to switch back to SLAAC. At this point in time the NAT64 support seems to be have been a lie... But anyways, to control my network DNS settings despite that I made a program to rewrite RA (and various other packets) with my own DNS server information.
- atoav 2y agoI work in media technology, and the amount of equipment in that field (think: room control systems, touch panels, projectors, media players, remote controled power switches) that does only support IPv4 is staggering. As it might be wise to banish those devices into an isolated net anyways that might not matter too much — but a transition to IPv6-only has many places where hard- and software is the blocking factor.
- cyberax 2y ago> It doesn't work from most hotels Most? I have not seen a _single_ hotel that supported IPv6. Not one. And I always check, just for fun. I've been to one hotel (in Menlo Park) that used to give out public IPv4 addresses automatically, and several hotels (The Venetian, Bellagio) where you could request a public IPv4 as needed. BTW, I'm also looking for a SIP provider that supports IPv6. So far I haven't found any in the US.
- School-Cotton 2y agoHow does requesting a public IP address at a hotel even work? I’m sure if I called the front desk at any hotel and I asked about IP addresses they’d have no idea what I was talking about. Do big fancy hotels have a dedicated IT help desk line?
- wvh 2y ago> I have fully implemented IPv6 in my home network. I could have written this message in 1999. That's 25 years ago (as you alluded to). That's a long time to hold your breath.
- ozim 2y agoCan it be that IPv4 price now leveled off because big players are getting ready to switch to IPv6 any time and not buying up anything that is available? If GooG/FB/Amazon force IPv6 how long will it take for ISPs to switch? I think in one week where some people cannot reach GooG/FB and any ISP that was dragging his feet has implemented IPv6 by the end of the week. I expect IPv6 adoption will blow up any time now as past performance is not indication of future changes ;) because there is much more required on the server side than it was ever before. ISP and home use could live with NAT but servers not really even if you can handle bunch of services on a single IP address, there is just limited traffic you can squeeze onto a single server.
- simiones 2y agoTFA is suggesting almost the exact opposite. "Servers" are moving more and more to an architecture where the service is a distributed collection of machines all over the world sharing only a DNS name; multiple servers share the same physical box, relying on TLS SNI to decide which particular content is intended. While NAT itself would be a problem, the reality is that a service no longer needs some unique IP: the same public IP can be shared by Netflix and Max, and the only relevant thing is that the incoming connection specifies which of the two is intended through the DNS name.
- ozim 2y agoSNI took the pressure a notch down. It was introduced 2012 and graph in article was showing peak of price of IP address in 2021 - where everyone was watching Netflix all day or was in video calls. SNI is not solving video streaming problem you just need more physical networking gear to handle streaming and more public IP addresses.
- 7bit 2y ago> Other than this one use case, IPv6 does nothing for me. IPv6 was not created for you, but it benefits you. NAT is computationally expensive and it does have a real impact for large organizations with thousands and tens of thousands of devices. Such as large universities or you know ISPs.
- wildguyd 2y agoThis statement above is the point…. Your networking requirements are quite modest compared to those whom IPv6 is essential.
- pmarreck 2y agoDon't forget that Hetzner and other hosts are also charging extra for IPv4 addresses now, while IPv6 is free. Also, you're speaking from the privileged perspective of a first-world country- many other countries missed the boat on IPv4 addresses and are limited to IPv6, which also probably explains why global uptake continues upwards despite the US stagnating. I have never gotten github access from my IPv6-only Hetzner-hosted machine. I don't have control over their router(s) and I am not an experienced network admin who would know how to set up something that would let me simply fucking "git clone" from that machine. I would end up having to set up something janky. The fact that Github is IPv4-only in 2024 is atrociously bad and hopefully handing over business hand-over-fist to their closed-source and open-source competitors. I love having access to all my internal machines over IPv6 from anywhere without having to use janky hacks. I'd be able to self-host boutique and portfolio websites for example (at least from IPv6-enabled clients), without having to use (and pay for) an external host just for the sake of access. The fact that hotels and work LANs don't permit access is a "hotel and work LAN" problem, as well as a chicken-and-egg one. If enough people request it (perhaps work people want some cheap Hetzner hosts for dev environments and traveling devs want access to the same machines), the Sysops That Be will make it happen- They are certainly educated enough in the space to enable it. You are neglecting the cost savings and the non-Western perspective, as well as the "simple developer, not devops expert" perspective.
- exabrial 2y agoTo give ipv6 some credit, there are some very useful things like flow labels. But I agree completely with the rest of your sentiment. IPv4 is "good enough", but we could do some things to extend its usage further. First, adopt service location in DNS, and being to retire it at the TCP port-number layer. Then we could run more than one website per ip address, and this would significantly increase resilience against censorship. Rotating ports for censored websites is a significantly easier task than rotating IPs for them since it does not involve routing changes. This could be done with "here and now" technology.
- cyberax 2y ago> To give ipv6 some credit, there are some very useful things like flow labels. They are not useful, as you can't depend on them.
- exabrial 2y agoWasn't aware of this actually, whats the issue with them?
- cyberax 2y agoIf you're using solely the flow labels to do load balancing, malicious clients can force traffic to come through only one load balancer by setting the same flow label. You need to add the source IP/port into the mix. But they alone are in practice enough for decent load balancing.
- wildguyd 2y agoYou are correct that - for many common environments - IPv6 lacks a compelling case for deployment. However, that is not universally true: for those organizations closer to the core of the Internet (with corresponding larger traffic and growth rates), the premise that you can carry all the traffic through CGNAT fails (simply review communications on the nanog mailing list from organizations such as Comcast, T-mobile, ATT, Google, MSFT Azure, Amazon, Verizon, etc.) to see clear evidence of such…. IPv6 solves their IPv4 exhaustion problem and has allowed the Internet continue to grow - if you’re not seeing a similar need, then it is simply that you are not at the core of the Internet.
- saidinesh5 2y ago> internet really doesn't care about being completely peer-to-peer. I think this is mostly the way it is because of all the NAT headaches that come with IPv4. We regularly see the limitations of Dropbox/Google drive when we just want to share that large birthday video with our friends/family. Imagine them having a secure link to your device that you can revoke any time. Same with all the home automation / iot devices / cctv cameras that have no excuse not to be local first/need you to install an ad infested app.