4 ms·
The "IPv6 is Hard" source seems to be sarcastic, not serious. IPv6 is ridiculously easy, in the grand scheme of things. What's hard is getting people who shoul
by johnklos 2y ago
The "IPv6 is Hard" source seems to be sarcastic, not serious. IPv6 is ridiculously easy, in the grand scheme of things.
What's hard is getting people who should know better to do what they're supposed to do, without playing games. The very fact that there are people who will argue why IPv6 is unnecessary tells us everything we need to know, because occasionally those people are in the path of deployment of something public. They don't write software which works agnostically with IPv6, they don't implement addressing that's stack agnostic, they don't bother taking the extra five minutes to test with IPv6.
Then you have a corporation that requires manager types to have enough "justification" to actually fix whatever Mr.-IPv4-is-good-enough, and because they don't understand that their own phone uses IPv6 all the time, they don't see a "business case" for it.
The title would be longer, but perhaps more accurate, if it were "Getting know-it-alls to stop stubbornly clinging to IPv4-is-good-enough and getting managers to realize that IPv6 is not only inevitable, but ubiquitous, are hard".
This article's conclusion isn't totally off, but in this case it's something that could easily be fixed by having a junior network admin just simply set things up. It's a trivial problem that's probably there because someone thinks they know better.
- kllrnohj 2y ago> IPv6 is ridiculously easy, in the grand scheme of things. How do I do a guest wifi network with isolation? On ipv4 I just flip a switch and thanks to NATs it just works, always. With ipv6? First I have to figure out what prefix delegation my ISP gives me. How do I do that? Manually, somehow, and hope it never changes. Already not "ridiculously easy" at the first step. Oops, turns out I was given a /64. So now what? Please explain this "ridiculously easy" thing to me, thanks.
- kccqzy 2y agoGuest WiFi network isolation happens below the IP layer: you would use VLANs for that. Setting up a VLAN for the first time isn't ridiculously easy, but it's the same whether you are using IPv4 or IPv6.
- kllrnohj 2y agohint, the problem is doing ipv6 vlans with only a single /64. Spoiler alert: you can't do it while also following spec
- growse 2y agoSure you can, the tradeoff is that you can't reliably do SLAAC (which I agree needs to get deprecated yesterday).
- kllrnohj 2y agoWhich maybe will happen eventually with RFC 9686 & 9663. Those are getting activity and maybe eventually will enable an actual IPv6 future in, oh, another 20 years? give or take.
- deleted 2y ago[deleted]
- ninkendo 2y agoI mean it’s not a great answer, but you could always set up a ULA for your guest network and use NAT. :-P But I’m with you on prefix delegation sucking. Prefixes change, and that makes all your devices’ addresses change. ULA’s solve this. But then you start asking hard questions like “if I’m going to use a ULA anyway, why even use the GUA addresses?” And the answer is shrug. I mean, it’s great that you can give real addresses to your devices when you want to host a service on them, but you can always just NAT your ISP-provided prefix to them anyway. You’ll probably want better addresses for them anyway, as those randomly generated host addresses aren’t easy to remember (may as well just start your public addresses at ::1 and increment from there, routing each one to the underlying ULA.)
- ndriscoll 2y agoDoing stateless NAT through prefix translation is still much more pleasant than stateful port mapping.
- Borealid 2y agoA static NAT is all you'd need for ULA to public 1:1. If you have a static NAT you don't need connection tracking on the router.
- ninkendo 2y agoYou’d need more than a /64 from your ISP if you wanted to do a separate guest network with static NAT though. OP was saying ipv6 makes it hard to do a guest network if all you get is a /64 from your ISP, but stateful NAT can fix that.
- deleted 2y ago[deleted]
- Hikikomori 2y agoSeparate vlan. Filtering on Ap. There's several options here.
- raron 2y agoIPv6 is easy, it was just not designed to handle intentionally adverse ISPs. If ALL customers would get a static /48 and the router provided by ISP wouldn't be industrial waste, you could easily use a different /64 for guest WiFi. (Or even a /56, if for some reason your friend wants to delegate some /64s to VMs running on their notebook.) But in that case these ISPs wouldn't be able to ask more money for "business" internet services. I think this is just the result of negligence from IANA or RIRs, these "suggestions" or "best practices" should be mandatory for ISPs and enforced by RIRs.
- wink 2y ago"If things were different for a lot of people, it would be easy". So it's not easy.
- kllrnohj 2y agoI don't think you can frame it as "adverse ISPs". I mean in some respects yes, but also IPv6 made the assumption that networks want to be shallow & wide, yet that's not where we've ended up. Rather, we now tend to have a lot of depth to the routing tree. Is this because of NATs? Possibly. But also network isolation turned out to be a powerful tool. And every step of isolation is necessarily another subnet. So now the depth of IPv6 is a limiting factor. Great you can have infinitely wide networks, but you can't expect to nest them much anymore. And that's a rather big limitation.
- fuzzy2 2y ago> Oops, turns out I was given a /64. Is that really the case though? I very much doubt it. I get a /56. Dynamic configuration mechanisms exist. I literally do not have to anything except flip a switch. My router even supports Prefix Delegation, so a downstream router/access point can do its thing.
- kllrnohj 2y ago> Is that really the case though? I very much doubt it. It's what AT&T fiber does. Well, they give a /60 to their shitbox, but if you want your own router with a public IP then you're stuck with a single /64 for it at least when doing the "easy" path. You can get some routers to request multiple IPv6 blocks and then you get the freedom of a whopping 7 subnets but you've also left "ridiculously easy" way, waaaay in the rear view mirror at this point anyway
- Spivak 2y agoThe conversation is ridiculously fast. * We can't not support IPv4. * IPv6 clients can connect to v4 only hosts. * Supporting IPv6 is nonzero additional work. * The cost of v4 addresses is on the order of a deli sandwich. * (If not greenfield) We have a working v4 system right now and adding v6 support is entirely risk with no benefit. * (Meant negatively) v6 is substantially different. So we will forever be maintaining two sets of networking stacks that play by different rules.
- kpcyrd 2y ago> * IPv6 clients can connect to v4 only hosts. May I introduce you to my ipv6-only vps
- otabdeveloper4 2y ago> The very fact that there are people who will argue why IPv6 is unnecessary tells us everything we need to know Yeah, it tells us that the IPv6 standard was invented by retarded monkeys who don't know what they're doing. (Yeah, yeah, I know, I've heard it before - akshually it's the rest of humanity who is stupid for not switching to IPv6. If only they were enlightened enough to know they need to throw away all their hardware and switch to an untested network stack for no practical benefit!)
- selfhoster 2y agoTo address some of your points: I've been writing software for pay for several decades and do not want IPv6. Phones use IPv4 and IPv6 and you can switch your phone to IPv6 only in the networking settings, run like that for a month and observe multiple weird and bad behaviors. I don't want IPv6 for several reasons, it looks like it was written by an alien and it inherently is privacy busting. I know many whose job it is to track people as closely as possibly will object but it's true, IPv6 is mainly only wanted by people whose job it is to track people.
- Dagger2 2y agov6 is not inherently privacy busting. It's just an IP. Worry about browser cookies and phone apps sending tracking IDs, not the randomized and non-persistent IPs they're sending them from.