8 ms·
> - I don't have a shortage of IPv4. Maybe my ISP or my VPN host do, I don't know. I have a roomy 10.0.0.0/8 to work with. What happens when multiple devices i
by MindSpunk 9mo ago
> - I don't have a shortage of IPv4. Maybe my ISP or my VPN host do, I don't know. I have a roomy 10.0.0.0/8 to work with.
What happens when multiple devices in your /8 want to listen on port 80 and 443 on the public address? Only one of them can. Now you're running a proxy.
> - Every host routable from anywhere on the Internet? No thanks. Maybe I've been irreparably corrupted by being behind NAT for too long but I like the idea of a gateway between my well kept garden and the jungle and my network topology being hidden.
It's called a firewall. You want a firewall. IPv6 also has a firewall. NAT is not a firewall. NAT is usually configured as part of your firewall, but is not a firewall.
> - Stateless auto configuration. What ? No, no, I want my ducks neatly in a row, not wandering about. Again maybe my brain is rotten from years of DHCP usage but yes, I want stateful configuration and I want all devices on my network to automatically use my internal DNS server thank you very much.
DHCPv6
> - My ISP gives me a /64, what am I supposed to do with that anyways?
What are you supposed to do with a /8? Do you have several million computers?
> - What happens if my ISP decides to change my prefix ? How do my routing rules need to change? I have no idea.
What happens if your ISP changes your IPv4 address?
- cj 9mo agoYou're not wrong, yet there's still no compelling reason to make an extra effort to switch to ipv6 when the limitations of ipv4 don't personally affect you.
- preisschild 9mo agoBut at this point you can just leave the factory settings on your devices, which mostly enable IPv6 by default anyways...
- devman0 9mo ago> It's called a firewall. You want a firewall. IPv6 also has a firewall. NAT is not a firewall. NAT is usually configured as part of your firewall, but is not a firewall. Expanding on this. NAT as deployed in most soho/residential settings requires a stateful firewall to track connections + port mapping logic.A stateful firewall is also used for IPv6 edge security and using the same basic posture (out allow, in established/related only) except the only difference is it isn't also doing an address mapping. Nobody is out there saying folks should run a wide open IPv6 edge, and as far as I'm aware no one is shipping IPv6 ready consumer routers that do that (but I'm prepared to be proven wrong in the responses).
- Hnrobert42 9mo agoWow. It's like your reply is doing an impression of IPv6! (I'm just teasing. I hope you are having a happy new year.) Not GP, but: > What happens when multiple devices in your /8 want to listen on port 80 and 443 on the public address? Only one of them can. Now you're running a proxy. I don't want any of my devices listening on the public address, much less multiple. > It's called a firewall. You want a firewall. IPv6 also has a firewall. NAT is not a firewall. NAT is usually configured as part of your firewall, but is not a firewall. That's a non sequitur. I can have a both a firewall and a NAT. The two layers are better than one because at least my address is shouldn't be routable even if I failed to configure my firewall correctly. > DHCPv6 Okay? DHCPv4 > What are you supposed to do with a /8? Do you have several million computers? That's GP's point. Running out of address space is not a problem even on IPv4 with NAT. > What happens if your ISP changes your IPv4 address? Well, an ostensible advantage of IPv6 is publicly routable addresses. I know how to configure my internal IPv4 network with host table entries and so on. If I move to IPv6 then my "internal" network address space is at the whim of my ISP.
- aragilar 9mo agoA NAT is part of a firewall, not a separate thing, so if the firewall is misconfigued, then your NAT may not be working either. On not running out of (private) IPs, I guess you've never had the fun of having to deal with overlapping ranges (because it isn't the number of IPs that's the issue, it's how the ranges are allocated). While this can still happen on IPv6, there are so many more subnets that this is far less likely. Also, a key thing that IPv6 makes obvious (which is also true to some extent of IPv4, but that most systems try to avoid showing) is that each link can have multiple IPs (there will be at least one link-local address), and so while your ISP can provide you a public range, you don't need to use it if you do not want to, you can always use an Unique Local Address (ULA - https://en.wikipedia.org/wiki/Unique_local_address https://en.wikipedia.org/wiki/Unique_local_address), which reduce the chance of overlapping ranges.
- yrand 9mo agoWhy do you think NAT is part of a firewall? NAT and firewall are two completely separate things that can exist independently of each other. Also overlapping ranges are an orthogonal issue that can occur with IPv6 private network range as well. IPv6 brings not only bigger address range but also a big bag of other things that one cannot ignore, are complicated and which are often a source of problems. That's why people stick with IPv4 even at the cost of NAT, because the number of things they have to care about is much smaller.
- makeitdouble 9mo ago> > - My ISP gives me a /64, what am I supposed to do with that anyways? > What are you supposed to do with a /8? Do you have several million computers? The /8 was for private addresses, so "free" and uncontested, while the /64 is a public resource. Looking at it as extraneous or over provided is understandable IMHO, even if mathematically it's not supposed to get depleted. At least it's not doing anything helpful for OP.
- aragilar 9mo agoThe IPv4 10.0.0.0/8 (along with the other private ranges) runs into lots of problems when connecting two private networks (e.g. VPNs, VMs/docker, hotspotting), whereas that /64 will not conflict with anyone.
- tass 9mo agoYes, I can’t even use many 10.x subnets at home because my work VPN configures a huge routing table including many of them. Basically I had no choice but to redo my home network if I wanted to use my new work laptop at home (and I work 100% remote).
- simoncion 9mo agoI "solved" this by running a separate VLAN for work machines that provides addresses in a slightly weird /24 carved out of the 172.16.0.0/12 [0] range. Is it as collision-resistant as a ULA address? No. But -sadly- I've yet to see an Enterprise VPN that wasn't run as an IPv4-only thing, so it's the best I can do. [0] Or whatever the netmask actually is. I'm never sure about the 172.16.x.x space.
- Dagger2 9mo agoI'd be tempted to shove that VPN into a network namespace together with jool, and NAT64 their 10.x subnets into, let's say, 2001:db8:a:b::/96, so that their 10.1.2.3 becomes 2001:db8:a:b::10.1.2.3. Then there's no overlap as viewed from outside the namespace. And if you ever need to use another VPN that also clashes on 10.x, you can do the same thing but map that one into 2001:db8:a:c::/96. Then you've got 2001:db8:a:b::10.1.2.3 and 2001:db8:a:c::10.1.2.3, neither of which clash with either each other or your 10.1.2.3.
- aragilar 9mo agoDHCPv6 sadly has the Android problem.
- superlupo 9mo agoReally? Unbelievable!
- dmitrygr 9mo ago> DHCPv6 Not supported by >50% of mobile devices
- Hobadee 9mo ago> > - My ISP gives me a /64, what am I supposed to do with that anyways? > What are you supposed to do with a /8? Do you have several million computers? Except you can subnet an IPv4 /8. You can't subnet an IPv6 /64. For whatever stupid reason, and despite having 18 quintillion available addresses in a /64, you can't actually do anything useful with it other than yeet a bunch of devices on the same LAN segment. (At least on pfSense, and when I looked into it some, that's apparently IPv6 design for some reason)
- paulddraper 9mo agoYour ISP gives you a IPv4 /32 which you don’t have a prayer of subnetting, you have to NAT. With a IPv6 /64 you can (1) NAT, or (2) better, subnet it and use DHCPv6. The only thing significant about /64 is that’s the smallest unit for SLAAC.
- aboardRat4 9mo agoAndroid only supports slaac.
- paulddraper 9mo agoStrangely it supports DHCPv6 as a server but not as a client.
- aboardRat4 9mo agoIt's not strange. It's Google's plan to push ISPs into supporting SLAAC and giving you at least /64 instead of giving you a single /128 address. It is not a bad thing actually.
- kllrnohj 9mo ago> The only thing significant about /64 is that’s the smallest unit for SLAAC. ...which means you can't subnet it because you have to assume SLAAC might happen since that's the only thing ipv6 requires. Ergo, an ISP only giving you a /64 means you have to nat if you want subnets, and if you have to nat why wouldn't you use ipv4 instead where it's so much simpler?
- everdrive 9mo ago>What happens if your ISP changes your IPv4 address? Absolutely nothing, because the private IPs behind the NAT are agnostic of the public IP.
- lazide 9mo agoActually, all your open connections break (including outbound ones, inbound ones via UPnP which is commonly on by default, etc.)
- everdrive 9mo agoNo, my connections time out for a brief period of seconds or minutes and then everything is fine for the next two years (until my ISP cycles my IP out again) and I don't actually need to do anything to resolve this. I wouldn't even know when my IPv4 address changed because the impact is so minor. uPnP may be on by default but that doesn't mean most people are actually using it for anything.
- lazide 9mo agoAnd what do you think when ipv6 changes addresses? Notably, even less.
- everdrive 9mo agoWhen my IPv6 changes my prefix changes and then my internal devices have new IP addresses and I don't know what those IPs are.
- lazide 9mo agoThat is what link local addresses are for - which you can access your devices on just fine, and don't change. And bonus points - aren't externally routable either. They are also much shorter. [https://en.wikipedia.org/wiki/Link-local_address https://en.wikipedia.org/wiki/Link-local_address] One really nice thing about IPv6 is you can (and do) have many addresses, all of which work. for example, you can add a manual fe80::5 address to one machine, and fe80::9 on another - and use those to access those machines on the local network. And not have to worry about that being externally addressable, or having conflicts, etc. And they won't change when your external addresses change either (unless there is some weird software bug in your OS or something). Though you probably want to use a unique local address range instead [https://en.wikipedia.org/wiki/Unique_local_address https://en.wikipedia.org/wiki/Unique_local_address] as they're more equivalent to the 10.0.0.0/16 type behavior you're expecting.
- dotancohen 9mo ago> It's called a firewall. You want a firewall. IPv6 also has a firewall. NAT is not a firewall. With NAT, I absolutely know my ESP32 is not vulnerable and exposed on the wild wild web. With a firewall, I may have a configuration issue or there might be a bug in the implementation or there might be some UDP nuisance I didn't know about or a dozen other concerns. I don't want to hire a network admin not play one at home.
- KaiserPro 9mo ago> With NAT, I absolutely know my ESP32 is not vulnerable and exposed I mean thats not actually true, uPnP will open ports up, as will misconfiguration. The firewall is still the same in ipv6 vs 4, and has the same problems.
- dotancohen 9mo agoCorrect me if I'm wrong, but UPnP requires my ESP32 to initiate communication. Whereas giving it an IPv6 address would expose it to the entire www even before it attempts communication.
- jech 9mo ago> Correct me if I'm wrong, but UPnP requires my ESP32 to initiate communication. Not quite. Using UPnP, any host on your internal network can open a port for any other host. You may be thinking of NAT-PMP. Additionally, by default UPnP mappings don't expire (unlike NAT-PMP mappings), so if a host crashes with an open port and your ESP32 inherits its IPv4 address, it will be exposed to the Internet.
- dotancohen 9mo agoActually I've never heard of NAT-PMP, so I'm just wrong )) Thank you. I never considered the reused address vulnerability.
- blueflow 9mo agoYour router will open up any port for an ephemeral forwarding if the traffic looks like that forwarding is warranted. Any application can open arbitrary inbound pathways. "Application" also includes the Javascript you run in your Browser. Which is externally controlled. Security folks call those techniques "hole punching" but they are how NAT is expected to work.
- vidarh 9mo ago> What happens when multiple devices in your /8 want to listen on port 80 and 443 on the public address? Only one of them can. Now you're running a proxy. I want to be running a proxy in that scenario, because I don't want any of it accidentally exposed. > It's called a firewall. You want a firewall. IPv6 also has a firewall. NAT is not a firewall. NAT is usually configured as part of your firewall, but is not a firewall. Yes, but it's arguably helpful to have configuration mistakes still leave your internal network unexposed. It's harder to accidentally expose resources when your ISP won't route to them.
- johannes1234321 9mo ago> > - What happens if my ISP decides to change my prefix ? How do my routing rules need to change? I have no idea. > > What happens if your ISP changes your IPv4 address? To my internal net: nothing. All my internal addresses stay the same. All my firewall settings remain the same. Just to the outside world I come from elsewhere (which is good for my privacy, not sufficient obviously, though) However if my IPv6 prefix changes all my IP based access control, which is a layer I use to limit what Internet of Shit devices can do, breaks. I could go to fe80 addresses for my local network, but those won't work across different network segments.
- brewmarche 9mo agoYou should use unique local addresses (ULAs, fc00::/7) not link-local addresses (fe80::/10) for this. Choose a random prefix and advertise it in your network (you can use some website like https://www.unique-local-ipv6.com https://www.unique-local-ipv6.com if you want). This prevents clashing subnets when using VPN like it sometimes happens with IPv4.
- MrDarcy 9mo agoTLS SNI routing has fixed the multiple authorities listening on one IPv4 address port 443. Most ISP’s implement IPv6 by using the single IPv4 address as a v6 prefix. This results in the entire LAN needing to change local addresses every time the public IP changes. In practice this means a single brief power outage causes hundreds of devices to break instead of none. Generally speaking ipv6 is useless for most home network users. Overlapping 10/8 with corporate networks is not a problem, wireguard has solved this in all cases I’ve run into.
- foobiekr 9mo ago"What happens when multiple devices in your /8 want to listen on port 80 and 443 on the public address?" This is a feature not a flaw. The average person doesn't have anything acting as a server, and that's a good thing, because the only servers they'd have would be embedded garbage in poorly maintained or completely abandoned IOT devices with incompetent code that should not be publicly exposed, ever, in anything but a call out model.
- megous 9mo agoFirewall is a feature. Forced NAT that noone in the above described situation wants is just a flaw. And the other solution where you're forced to buy a fucking "public" number out of a grossly insufficient pool of those for $5/month for each of the NATted machines and your router, is a crime against humanity.
- nomel 9mo agoI'm naive with network security, so this is a honest question looking for a practical honest answer: Would my grandma's computer, with its old version of windows, be more or less safe with a NAT without DMZ configured?
- avianlyric 9mo agoUsing a normal ISP issued router, wouldn’t make a lick of difference if it was IPv4 with a NAT or IPv6 without a NAT. They’re all configured out-of-the-box with a default deny firewall. I’m not actually aware of any residential grade router that doesn’t come configured like this. Of course if the router is misconfigured, then all bets are off. But that’s true regardless of IPv4 vs IPv6, because people will just compromise your router first and use that as a launch pad for the rest of your network. Just like to do today with plenty of old residential routers.
- morshu9001 9mo agoNAT is way harder to screw up than a firewall, especially in cases where the defaults were left untouched. Also what the other commenter said about your internal addresses being at the mercy of the ISP.