5 ms·
I was hoping with IPv6, getting an address space as an individual would go back to how it was in the early IPv4 days, but alas you need to be a multihomed indiv
by candiddevmike 8mo ago
I was hoping with IPv6, getting an address space as an individual would go back to how it was in the early IPv4 days, but alas you need to be a multihomed individual with tons of usage instead of just a sophisticated netzien that wants to own their block.
- deleted 8mo ago[deleted]
- dogcow 8mo agoYes, same here. Very frustrating. It is almost as if the powers that be don't want lowly netizens controlling their own destiny.
- direwolf20 8mo agoActually, they don't want to pollute the internet routing table with routes that are fully subsumed into other routes. The effect on address ownership is a side effect.
- zhouzhao 8mo agoActually, they just want to milk the money out of you. It's a matter of how much your willing to pay, as a business customer, it's all possible. Most ISP do not have such pure goals, as to protect the global routing tables ;)
- direwolf20 8mo agoRIRs, not ISPs, allocate addresses at the top level, they make money on each address allocation, and they still won't allocate addresses to you if you don't multihome because they have a duty to conserve resources. When you get PI addresses your LIR/ISP just passes your data on to the RIR.
- dboreham 8mo agoJust like many industries there's a retail side and a wholesale side. You're asking to get a wholesale product from a retail channel. If you become a wholesale customer you can get what you want, for a price.
- zhouzhao 8mo agoI feel you. Us nerds have been ignored by modern day home user contracts.
- nine_k 8mo agoWhat is the point of owning public address space? Anything in your private network (even if it goes over public internet) should be encrypted and locked up anyway. Something like Wireguard or Nebula only needs a few (maybe just one) publicly accessible address. Inside the overlay network, it's easy to keep IP addresses stable. Anything public-facing likely needs a DNS record, updatable quickly when the IP of a publicly accessible interface changes (infrequently). What am I missing?
- direwolf20 8mo agoThe realistic point is to have your own abuse email contact, to evade the banhappy policies that most server hosts have even when you did nothing wrong. Usually they suspend your account if you don't reply within 24 hours, even if the complaint is obvious nonsense.
- cyberax 8mo agoIt's the only real way of running reliable IPv6 networks with multiple uplinks. Unless you want NATv6.
- kortilla 8mo agoDNS updates are slow. BGP can react to a downed link in <1 sec.
- zamadatix 8mo agoI have both my own multihomed ASN and operate my own nameservers. The latter has usually been about as fast for failover overall in practice. BGP may look to converge near instantly from your 2-3 peer outbound perspective but the inbound convergence from the 100k networks on the rest of the internet is much slower and has a long tail very akin to trying to set your DNS TTL to 0 and having the rest of the internet decide to do it slower for cache/churn reasons anyways. The bigger problem, and where BGP multihoming is most handy, is it's just so much easier to get a holistic in+out failover where nothing really changes vs in DNS where it's more about getting the future inbound stuff to change where it goes. E.g. it's a pain to break an active session because the address had to change, even if DNS can update where the new service is quickly.
- dietr1ch 8mo agoI don't want an address, they should be cheap, meaningless (sans routing, the longer the common prefix, the closer geographically you should be) and not conflated with identifiers. I just want a way to do public-key based discovery. I'm not sure if wireguard + DHT would do though as it'd also mean that it's easy to track your PK (and maybe you through your devices/services announced with PKs). Maybe you can announce your IP in a neat encryption scheme that adds some privacy without increasing costs too much?
- direwolf20 8mo agoBasically Yggdrasil?
- oasisaimlessly 8mo agoLink: https://yggdrasil-network.github.io/ https://yggdrasil-network.github.io/
- dietr1ch 8mo agoOh, that's interesting
- seszett 8mo agoHonestly it's not free but it's really not that expensive. With RIPE it's about 75€ per year for the ASN and being multihomed is not really a problem, there are multiple services that will let you announce through them for free or very cheap. You don't have volume minimums. I do agree it should be simpler, but it is accessible to individuals today.
- protocolture 8mo agoOne of my customers was handing out /64s for a while but it was more hassle than it was worth. I only ever saw one residential customer use it, and he was just smart enough to cause problems. Its one of those things that there needs to be strong consumer demand for, or it will just never happen tbh. From our perspective, what we want more than anything in the universe is to never do NAT or DNS ever again. I would much rather maintain a billing system indicating you rent a small block of IPV6 space, with a nice little static route, over maintaining never ending NAT and DNS logs for the benefit of police forces who cant shit without collecting every micron of data. But NAT is basically security these days, and theres a negative driver in exposing customer routers directly to the internet (in that, if it even supports v6 its likely to be rooted) Customers will leave if telcos do things properly, and theres literally zero reward for being nice about it.
- direwolf20 8mo agoIn some countries you're only required to turn over logs that you chose to collect, but you're not required to collect them.
- seszett 8mo agoInteresting, my two ISPs (one in Belgium, one in France, not business ISPs) hand out fixed /48 blocks to every customer. As far as I know, that's what RIPE recommends, they actively discourage from assigning longer prefixes than /56. The modems they provide handle it without needing anything special from the customers. The devices get IPv6 addresses from this prefix, and are firewalled by default. It's pretty simple so I'm not sure what could go wrong there.
- jorvi 8mo agoQue? 4,722,366,482,869,645,213,696 addresses isn't enough for you?
- direwolf20 8mo agoThey want the address block registered directly to them instead of their ISP
- jorvi 8mo ago> In April 2009 RIPE accepted a policy proposal of January 2006 to assign IPv6 provider-independent IPv6 prefixes. Assignments are taken from the address range 2001:678::/29 and have a minimum size of a /48 prefix. You can have your own PI bloc and move it between ISPs if you so desire. You effectively own the bloc.
- direwolf20 8mo agoQue? Relevance to context? Yes, that's what OP did except PA