3 ms·
If anything, IPv6 is extremely easy to use, especially with SLAAC: On any kind of standard network, you turn on IPv6 on your machine, and, given physical connec
by 9dev 6mo ago
If anything, IPv6 is extremely easy to use, especially with SLAAC: On any kind of standard network, you turn on IPv6 on your machine, and, given physical connectivity, bam! You're on the internet.
It only gets complex if you try to micro-manage it.
- nslsm 6mo agoSo, like ipv4, but you lose the protection and privacy afforded by the NAT?
- 9dev 6mo agoIPv4 requires a DHCP server. It requires assigning a range of addresses that's usually fairly small, and requires manual configuration as soon as you need more than 254 devices on a network. The range must never conflict with any VPN you use. And there's more. Compare to IPv6: Nothing. All of these just go away. And concerning the NAT: That's just another word for firewall, which you still have in your router, which still needs to forward packages, and still can decide to block some of them.
- deleted 6mo ago[deleted]
- nslsm 6mo agoThe dhcp server is in the router, just like you need a router for slaac.
- nobody9999 6mo ago>IPv4 requires a DHCP server. Windows[0]: Static IP configuration is as simple as typing an IP address into the pretty dialog box. No DHCP required. Linux[1]: # ip addr <ip4 address> <subnet mask> <device> will set a static IP address >It requires assigning a range of addresses that's usually fairly small, and requires manual configuration as soon as you need more than 254 devices on a network. Is 65,536 (172.16.0.0/16) or 16 million addresses (10.0.0.0/8) "fairly small"? Are DHCP servers unable to parse networks that "big"? >Compare to IPv6: Nothing. All of these just go away. They most certainly do. But they're not "problems" with RFC1918 addressing and aren't "problems" at all with IPv4. There are many issues with IPv4 and the sooner it dies, the better. But the ones you mention aren't issues at all. If you're going to dunk on IPv4, then dunk on it for the actual reasons it needs to go, not made up "problems."
- MindSpunk 6mo agoNAT is not a security device. A firewall, which will be part of any sane router's NAT implementation, is a security device. NAT is not a firewall, but is often part of one. Any sane router also uses a firewall for IPv6. A correctly configured router will deny inbound traffic for both v4 and v6. You are not less secure on IPv6.
- general1465 6mo agoMisconfigured firewall is a gaping hole. Misconfigured NAT is not letting data from outside into your local network. So firewall is actually worse than NAT.
- Dagger2 6mo agoEven a correctly-configured NAT will let connections in from outside, and a lot of people don't understand this. Personally I'd count "your security thing doesn't actually do the thing it's supposed to do" as being pretty bad on the security scale. At least people understand firewalls.
- general1465 6mo ago> Even a correctly-configured NAT will let connections in from outside, and a lot of people don't understand this. Yes, that's called port forwarding and it is normal thing. You actually want that.
- Dagger2 6mo agoIt will let them in without a port forward in place. The port forward just rewrites the IP on an incoming connection, nothing more.
- general1465 6mo agoIf you can reuse opened connection, but that will work with firewall too.
- baq 6mo agoWhat protection? What privacy? Smoke and mirrors, mostly. NAT is a firewall with extra steps. IPv6 reduces complexity. Privacy (illusion of it, anyway, just like in ipv4 NAT) is handled by private addresses. …and if you really want to, NAT for ipv6 just works.
- Dagger2 6mo agoIt's the illusion of a firewall too. NAT changes the apparent destination address of a connection, it doesn't filter them. If a connection arrives with the destination address already set to one of your machines, NAT won't prevent it.
- nottorp 6mo ago> especially with SLAAC Oh no, last time I asked on HN I got 24 to 48 easy steps involving a lot more acronyms than this (please don't repeat them). IPv6 is easy to use only if you let your one router manage everything and you give up control of your home network. Edit: again, please don't help. There have been HNers trying to help before, but my home network is non trivial and all the "easy" autoconfiguration actually gets in the way.
- 9dev 6mo agoThere are no more acronyms. SLAAC means automatic client configuration. That's the only one you need. > give up control of your home network. What does that even mean? What do you gain by deciding your Apple TV should be at 192.168.0.3? With IPv6, you can just `ping appletv` and it works fine. What more "control" do you need?
- XorNot 6mo agoI mean generally I want fixed IPs on my local network for robustness. With IPv6 I actually want it more and it becomes possible since we can just use the MAC address as an IP address. I have IPv6 service at my ISP right now but I'm hesitant to turn it on on my local network because it does make my firewalling concerns much more critical.
- 9dev 6mo ago> I mean generally I want fixed IPs on my local network for robustness. What do you mean by robustness? Isn't it really stable hostnames that you want? I don't understand how fixed IPs increase resilience (to what?). > I'm hesitant to turn it on on my local network because it does make my firewalling concerns much more critical. Block everything coming in from outside the network. Allow established connections. That's all there is to it.
- nottorp 6mo agoYou're assuming there is only one internet connection in my home network, for example. The "easy" trick where your ISP gives you routable addresses does not work when there's more than one exit. Still want to help? :) And really... everyone is pushing for SSL everywhere - among other things so that the ISP doesn't MITM your traffic. Why would you allow the ISP to know what machines are inside your home network then?
- kristopolous 6mo agothe internet, in very large volume, disagrees. Am I not allowed to document the widely held common sentiment?
- 9dev 6mo agoYou are allowed to state your opinion, as am I. My issue with your opinion is that is grounded in false belief and a lack of knowledge, and rehashing it here reproduces those opinions in others.