6 ms·
Is there a reason why adoption has been so abysmally slow? Like surely all the big players have updated their networking equipment by now, and surely every pie
by stackghost 6mo ago
Is there a reason why adoption has been so abysmally slow? Like surely all the big players have updated their networking equipment by now, and surely every piece of enterprise-grade kit sold in the last 20 years has supported v6.
The only arguments I've ever heard against ipv6 that made any sense are that:
1: it's hard to remember addresses, which is mayyyyybe valid for homelab enthusiast types, but for medium scale and up you ought to have a service that hands out per-machine hostnames, so the v6 address becomes merely an implementation detail that you can more or less ignore unless you're grepping logs. I have this on my home network with a whopping 15 devices, and it's easy.
and 2: with v6 you can't rely on NAT as an ersatz firewall because suddenly your printer that used to be fat dumb and happy listening on 192.168.1.42 is now accidentally globally-routable and North Korean haxors are printing black and white Kim Il Sung propaganda in your home office and using up all your toner. And while this example was clearly in jest there's a nugget of truth that if your IOT devices don't have globally-routable addresses they're a bit harder to attack, even though NAT isn't a substitute for a proper firewall.
But both of these are really only valid for DIY homelab enthusiast types. I honestly have no idea why other people resist ipv6.
- nubinetwork 6mo ago> Like surely all the big players have updated their networking equipment by now My home isp can't even do symmetrical gigabit, let alone ipv6...
- esseph 6mo agoThat's extremely common unless on "active" fiber (vs GPON, DOCSIS3, DSL, most fixed wireless, satellite, mobile, etc.) Your wifi isn't symmetrical either.
- Hikikomori 6mo agoThose are designed to have static asymmetrical bandwidth though, *dm split gives ISP side more of possible shared bandwidth. Wifi bandwidth is shared and dynamic so client can use all of it.
- esseph 6mo ago> Those are designed to have static asymmetrical bandwidth though Yes, that's why I said that? > *dm split No idea what you're trying to say here.
- direwolf20 6mo agoIgnore all the excuses like longer addresses and incompatible hardware. The actual reason is that everyone hates change.
- crote 6mo agoSure, the data plane supports it - but what about the management plane? I wouldn't be surprised if ISPs did all the management tasks through a 30-year-old homebrew pile of technical debt, with lots of things relying on basic assumptions like "every connection has exactly one ip address, which is 32 bits long". Porting all of that to support ipv6 can easily be a multi-year project.
- Sesse__ 6mo ago> Porting all of that to support ipv6 can easily be a multi-year project. FWIW, as someone who has done exactly this in a megacorp (sloshing through homebrew technical debt with 32-bit assumptions baked in), the initial wave to get the most important systems working was measured in person-months. The long tail was a slog, of course, but it's not an all-or-nothing proposition.
- Hikikomori 6mo agoThis is true, I worked for an old ISP/mobile carrier that started in the 80s about 10-15 years ago. They had basically any system you could think of still running, from decently modern vmware with windows and linux to hp-ux, openvms, sunos, AIX, etc. Could walk around and see hardware 30 years old still going, I think one console router had an uptime of 14 years or so. One time I opened a cabinet and found a pentium 1 desktop pc on the floor still running and connected, served some webpage. The old SMSC from the 80s on DEC hardware was still in its racks though not operational, they didn't need the space as the room couldn't provide enough power or cooling for more than a few modern racks. The planning program for fiber, transmission, racks, etc, required such an old java that new security bugs didn't apply to it, and looked and worked like an old mainframe program. The core team supported ipv6 for a long time, but its rather easy to do that part. The hard part is the customer edge and CPE and the stack to manage it, it may have a lifetime of 2 decades.
- mjcl 6mo agoComcast actually implemented IPv6 10-15 years ago so that they could unify the management of all of their cable modems. Prior to that they had many regional networks using with modems assigned management IPs in overlapping private IPv4 ranges.
- noirscape 6mo agoThe big reason is that domestic ISPs don't want to switch (not just in the US, but everywhere really.) Data centers and most physical devices made the jump pretty early (I don't recall a time where the VPS providers I used didn't allow for IPv6 and every device I've used has allowed IPv6 in the last 2 decades besides some retro handhelds), but domestic ISPs have been lagging behind. Mobile networks are switching en masse because of them just running into internal limits of IPv4. Domestic ISPs don't have that pressure; unlike mobile networks (where 1 connection needing an IP = 1 device), they have an extra layer in place (1 connection needing an IP = 1 router and intranet), which significantly reduces that pressure. The lifespan of domestic ISP provided hardware is also completely unbound by anything resembling a security patch cycle, cost amortization or value depreciation. If an ISP supplies a device, unless it fundamentally breaks to a point where it quite literally doesn't work anymore (basically hardware failure), it's going to be in place forever. It took over 10 years to kill WEP in favor of WPA on consumer grade hardware. To support IPv6, domestic ISP providers need to do a mass product recall for all their ancient tech and they don't want to do that, because there's no real pressure to do it. IPv6 exists concurrently with IPv4, so it's easier for ISPs to make anyone wanting to host things pay extra for an IPv4 address (externalizing an ever increasing cost on sysadmins as the IP space runs out of addresses) rather than upgrade the underlying tech. The internet default for user facing stuff is still IPv4, not IPv6. If you want to force IPv6 adoption, major sites basically need to stop routing over IPv4. Let's say Google becomes inaccessible over IPv4 - I guarantee you that within a year, ISPs will suddenly see a much greater shift towards IPv6.
- ENGNR 6mo agoIt's frustrating that even brand new Unifi devices that claim to support IPv6 are actually pretty broken when you try to use it. So 10 years from right now even, unless they can software patch it upwards.
- stackghost 6mo agoInteresting, what's broken for you? I have some unifi gear and it handles v6 no problem.
- deleted 6mo ago[deleted]
- cyberax 6mo agoIPv6 is a recursive WTF. It might _look_ like a conservative expansion of IPv4, but it's really not. A lot of operational experience and practices from IPv4 don't apply to IPv6. For example, in IPv4 each host has one local net address, and the gateway uses NAT to let it speak with the Internet. Simple and clean. In IPv6 each host has multiple global addresses. But if your global connection goes down, these addresses are supposed to be withdrawn. So your hosts can end up with _no_ addresses. ULA was invented to solve this, but the source selection rules are STILL being debated: https://www.ietf.org/archive/id/draft-ietf-6man-rfc6724-update-23.html https://www.ietf.org/archive/id/draft-ietf-6man-rfc6724-upda... Then there's DHCP. With IPv4 the almost-universal DHCP serves as an easy way to do network inspection. With IPv6 there's literally _nothing_ similar. Stateful DHCPv6 is not supported on Android (because its engineers are hell-bent on preventing IPv6). And even when it's supported, the protocol doesn't require clients to identify themselves with a human-readable hostname. Then there's IP fragmentation and PMTU that are a burning trash fire. Or the IPv6 extension headers. Or.... In short, there are VERY good reasons why IPv6 has been floundering.
- yangm97 6mo agoThe reason: Skill issue.
- philipallstar 6mo agoHow do the working IPv6 deployments cope with these issues?
- cyberax 6mo agoThe simple answer is: they just don't deploy IPv6. These days you can use ULA and third-party monitoring tools instead of DHCP.
- dwattttt 6mo ago> For example, in IPv4 each host has one local net address, and the gateway uses NAT to let it speak with the Internet. Simple and clean. I assume you mean "interface", not "host". Because it's absolutely not true that a host can only have one "local net address". EDIT: a brief Google also confirms that a single interface isn't restricted to one address either: sudo ip address add <ip-address>/<prefix-length> dev <interface>
- Dagger2 6mo agoHas it been abysmally slow? What's the par time for migrating millions of independent networks, managed by as many independent uncoordinated administrators, to a new layer 3 protocol? We've never done this before at this scale. Maybe this is just how long it takes?
- alibarber 6mo ago> 1: it's hard to remember addresses fd::1 is perfectly valid internal IPv6 address (along with fd::2 ... fd::n)
- holowoodman 6mo agofd::1 is somewhere in the reserved ::/8 space where various stuff like old ipv4 mapped addresses and localhost reside. What you probably mean is something like fd00::1, but that is something you shouldn't use, because 'fd00::/8' is a probabilistically unique local address (ULA) block. You are supposed to create a /48 net by appending 40 random bits to fd00::/8. Of course, if your fair dice roll lands on all zeroes, and you are ok with probable collisions in case of a network merge, you are fine ;)
- ninkendo 6mo agoIn home networks, the idea of merging with someone else's network is... most certainly not worth worrying about. Maybe you marry someone or become roommates with someone who also picked fd00::/8? And you still want two separate subnets? Other than that I don't see a scenario where it matters. Granted, if you're doing this in a corporate setting (where merging with someone else's address space is a lot more realistic), then yes definitely pick a random 40 bits. But at home? Who cares. Same as using 192.168.1.0/24 instead of a random 10.0.0.0/24 subnet... it's not worth worrying about.
- holowoodman 6mo agoI'm having my own and my girlfriend's router (in different flats) connect to each other with a wireguard tunnel, so I can print on her printer. Non-colliding addresses make this a lot easier. But yes, renumbering also isn't a lot of work.
- deleted 6mo ago[deleted]
- nottorp 6mo ago> But both of these are really only valid for DIY homelab enthusiast types. I honestly have no idea why other people resist ipv6. Simple. The "homelab enthusiast types" are those that usually push new technologies. This is one they don't care about, so they don't push it. Other people don't care about any technology if it's not pushed on them.
- boredatoms 6mo agoNothing stops you running a NAT for v6 too, its just people tend to choose not to when given the choice
- ok123456 6mo agoI set up NAT66 recently with DHCPv6. The IPv4 and IPv6 addresses are practically the same, except IPv6 has a prefix and a double colon as the last separator. This really should be how SOHO routers do IPv6 out of the box. Most people don't want 1:1 addressing for their entire home or office.
- boredatoms 6mo agoQ on your setup Are you using ULA prefix for the nat66/dhcp6, are you also allowing GUA address assignment via slaac? Im wondering how it works out with source-selection
- ok123456 6mo agoYes, so each device has two IPv6 and one IPv4 address.
- lxgr 6mo ago> it's hard to remember addresses We desperately need a standardized protocol to look up addresses via names. Something hierarchical, maybe. > with v6 you can't rely on NAT as an ersatz firewall Why would you not just use a regular firewall? Any device that is able to act as a NAT could act as a firewall, with less complexity at that.
- stackghost 6mo ago>Why would you not just use a regular firewall? No idea, but people do it. Every time this comes up on HN there are dozens of comments about how they like hiding their devices behind a NAT, for security
- lxgr 6mo agoJust because people regularly bring up a non sequitur doesn't mean there actually is a problem. "I have a device acting as both a NAT and a stateful firewall, why are you making me switch to IPv6 and in the process drop both the NAT and the stateful firewall?" is a non sequitur.
- stackghost 6mo agoI think we're talking about two different things, or maybe I just don't understand your reply. What I'm saying is this: There exist people in the hobbyist space who believe that when their devices only have private IPv4 addresses such as 192.168.0.0/16 that this meaningfully increases their network security, and that if their raspberry pi has a globally-routable v6 address that this weakens their network security, even though this is bogus because NAT is orthogonal to network security considerations, and that this belief contributes to IPv6 hesitancy.
- bananamogul 6mo ago"Is there a reason why adoption has been so abysmally slow?" Just the obvious one: the people who designed IPv6 didn't design for backwards compatibility.
- jampekka 6mo ago> Just the obvious one: the people who designed IPv6 didn't design for backwards compatibility. Nor for easy transition.
- Dagger2 6mo agoHow so? The same working group published e.g. https://www.rfc-editor.org/rfc/rfc1933 https://www.rfc-editor.org/rfc/rfc1933, and it's hard to see how v6 could have been designed for backwards compatibility in ways that it wasn't already. I've asked lots of people to describe a more backwards-compatible design, and generally the best they can manage is to copy the way v6 does things, ending up with the same problems v6 has. This has happened so often that the only reasonable conclusion is that it can't really be done any better than it was.