2 ms·
In Germany, the TV-cable based ISP all have started deploying CGNAT. If you live in a densely populated area with many Vodafone customers, their CGNAT gateways
by avhception 2y ago
In Germany, the TV-cable based ISP all have started deploying CGNAT.
If you live in a densely populated area with many Vodafone customers, their CGNAT gateways tend to be overloaded, so in peak hours you sometimes experience packet loss.
Of course Vodafone won't admit that it's a structural problem instead of isolated cases.
At one point, I was forced to use a shitty DSL provider, "e-on highspeed" (formerly "Innogy") because they had exclusive rights to the VDSL DSLAM in my area.
For a while, they didn't even offer IPv6 alongside the CGNAT v4.
And when they did, it broke randomly (remote gateway dead).
By the way, does anybody have a clue on how to get SLAAC addresses into local DNS?
I can't create static records because my current ISP keeps changing my assigned prefix.
I'm still on v4 for my local fileservers and stuff like that because of this problem.
- Arnavion 2y agoThe easiest way is to use a ULA on the LAN side instead of the ISP-assigned prefix, and set up NAT66 at the router to convert delegated prefix <-> ULA. It sucks having to use NAT with IPv6, but at least it'll be stateless NAT. Then when your delegated prefix changes you will only need to update the NAT rule, meanwhile everything within your LAN that was using ULA-prefixed addresses to talk to each other will continue working. For my own homelab, I give all my machines and VMs static IPs instead of using SLAAC, which also makes it straightforward to register them in DNS, and memorize them in the worst case.
- simoncion 2y ago> The easiest way is to use a ULA on the LAN side instead of the ISP-assigned prefix, and set up NAT66 at the router to convert delegated prefix <-> ULA. You don't need to not use your ISP-assigned globally-routable prefixes. You can use both a ULA and a globally-routable prefix. In my years of experience with fully-functional IPv6 service, I've never noticed an address selection problem... machines always use the globally-routable address as the source for off-LAN communications and (because it's what's in my local DNS) the ULA address for on-LAN communications. The single pitfall I've seen is if your ISP ever "shuts down" [0] that globally-routable prefix, and your border router isn't configured to reject traffic from fc00::/7 going out through the WAN interface, your border router will happily pass traffic out the WAN interface from your not-globally-routable ULA range. > For my own homelab, I give all my machines and VMs static IPs instead of using SLAAC, which also makes it straightforward to register them in DNS... I just configure my machines to use either MAC-based or DUID-based SLAAC address generation, rather than that stupid "privacy addressing" stuff. [0] By this I mean by stopping advertising it, refusing to renew a DHCPv6-PD lease, or similar.
- jeroenhd 2y ago> does anybody have a clue on how to get SLAAC addresses into local DNS I use an ULA for that (a private /48 that's not routable through the internet). I have a random server in my network (doesn't need to be a router) advertise it through radvd (though some routers also offer that ability). I then put the static address (not the random IPv6 privacy address) in local DNS. If you don't pick any "easy" ULAs, you can have multiple devices announce multiple ULAs on the same network and everything will keep working just fine (unlike multiple DHCP servers). The benefit of an extra ULA inside your network is that you don't need to set up NAT or NAT66. The downside is that your ULA services won't be reachable from the outside. I solved that with a Wireguard VPN, but you may need something more complicated. You could consider using something like HE.net's free IPv6 ranges to add an extra prefix into your network that's reachable even when your prefix changes, but that needs some automation (and you want to configure it in a way that devices won't try to route to the internet over that prefix, or streaming services will stop working and your network will probably slow down a bit). I used https://it.jason.tools/ipv6-ula-generator https://it.jason.tools/ipv6-ula-generator to generate a random enough ULA, then put this into my /etc/radvd.conf: interface vmbr1 { AdvSendAdvert on; AdvDefaultLifetime 0; MinRtrAdvInterval 3; MaxRtrAdvInterval 10; prefix fdae:5594:90d5::/64 { AdvOnLink on; AdvAutonomous on; AdvRouterAddr off; }; RDNSS fdae:5594:90d5:0:215:5dff:fe01:d119 { AdvRDNSSLifetime 3600; }; }; Maybe some of those timeouts aren't correct, I don't know for sure, but this seems to work fine for me. The RDNSS entry is for automatically assigning a DNS server, that's optional as well of course. Alternatively, using mDNS also works more often than you'd expect, either over IPv4 or IPv6. Try `yournashostname.local` and you may just find it works out of the box. If it doesn't, you can probably install avahi-daemon on there to make it work.
- justsomehnguy 2y ago> By the way, does anybody have a clue on how to get SLAAC addresses into local DNS? The main difference between v4 and v6 (which reaaally trips v4 entrenched folks) what it's absolutely normal to have dozens of different addresses on the interface. As other said, just pick your own ULA subnet and use addresses from it.
- throw0101a 2y ago> By the way, does anybody have a clue on how to get SLAAC addresses into local DNS? As others have mentioned, ULA is one option. > I can't create static records because my current ISP keeps changing my assigned prefix. I'm still on v4 for my local fileservers and stuff like that because of this problem. Perhaps worth looking at: * "Reaction of IPv6 Stateless Address Autoconfiguration (SLAAC) to Flash-Renumbering Events", https://datatracker.ietf.org/doc/html/rfc8978 https://datatracker.ietf.org/doc/html/rfc8978 * "Improving the Robustness of Stateless Address Autoconfiguration (SLAAC) to Flash Renumbering Events", https://datatracker.ietf.org/doc/html/draft-ietf-6man-slaac-renum https://datatracker.ietf.org/doc/html/draft-ietf-6man-slaac-...