20 ms·
We're about to hit phase 3 of ARIN IPV4 rationing
- tlb 13y ago... And as the foredeck of the Titanic sinks below the water line, we enter phase 3 of deck chair rationing ...
- SwellJoe 13y agoThe band is still playing. I think that means everything is fine, right?
- unreal37 13y agoUnless I'm misreading it. The rationing rules in effect during Phase 3 are exactly the same as Phase 2. So why the distinction at all?
- ars 13y agoThere are a ton of /8 still assigned to companies that don't need them. Ford, GE, IBM, AT&T (x2), Xerox, HP (x2), Apple, MIT, CSC, Eli Lilly, Nortel, Prudential Insurance, DuPont, Cap Debis, Merck, SITA. All of those can return their /8. That's 18 /8 potentially available. And does the DoD really need 12 /8's? I get that they want to network every person, gun, ship, tank, truck and plane. But none of those need to be on the public internet. (Well, maybe the people do - but 1 /8 should be enough for that.)
- Afforess 13y agoRumormill at IBM is that we bought some random companies a while back just for their IPv4 blocks. You didn't hear that from me though.
- jychang 13y agoDoubt it, everything on IBM is natted to a 10.0.0.0/8 or is running externally to 9.0.0.0/8. Source: I work at IBM, in a division that was another company that was bought out a few years back.
- peterkelly 13y agoI think the suggestion was that they expected those blocks could become very valuable in the future and could thus be sold for a healthy profit. I don't think GP meant that IBM wanted to actually use those addresses themselves.
- wmf 13y agoIBM is using 9/8. AT&T is one of the largest ISPs in the world. Hopefully any legacy space that isn't used will come up for sale soon.
- recuter 13y ago> All of those can return their /8. That's 18 /8 potentially available. If say, Apple is using at least a little bit of that /8 here and there (safe assumption, no?) its going to be hard for them to return it. I'd wager corporations that have /8s have policies that rely on the assumption that they have the whole /8. So I wouldn't hold my breath on getting one back from them.
- ck2 13y agoTime to go around to Fortune 100 companies and say "use it or lose it".
- mfincham 13y agoRecovering additional IPv4 space at this point only prolongs the inevitable problem. The solution is IPv6.
- WatchDog 13y agoIf the data from this study[1] is accurate, recovering address space could prolong it for a long long time. 1. http://internetcensus2012.bitbucket.org/paper.html http://internetcensus2012.bitbucket.org/paper.html
- mfincham 13y agoMuch of that space can't be recovered though because it's just little non-contiguous bits here and there...
- ck2 13y agoYes but for now it's a case of money buys conspicuous consumption and the internet shouldn't work that way. ipv6 will be a lot easier to adopt in 2015 vs 2013 so every year we can claw back makes life easier
- sliverstorm 13y agoNo, I don't think so. Kicking the can down the road doesn't help much, the longer you kick it the more people say "Whatever, they'll keep putting this off for at least a decade, let's just drop IPv6 from Linux 3.2 and put it back in Linux 4.0" and then where are you. IPv6 isn't going to just magically happen if you don't make it happen.
- bigiain 13y agoFive (or ten) years ago, NAT was "the solution" – which helped and worked for longer than the doomsayers predicted. Today, I suspect SNI will be the important stop-gap measure. There's a whole bunch of websites out there on shared hosting with dedicated IP(v4) addresses for their vhost just so they can use SSL certs for https connections. If we can ignore Windows XP users and IE6 users, SNI allows SSL certs on shared IP addresses - if I can think of a few dozen "unnecessary" IP addresses this little web development firm consumes, I suspect big hosting companies could probably find thousands or tens of thousands of similarly used IP addresses. (Having said that, analytics still shows a startlingly high number of WinXP and IE6 users out there. It'd be interesting to see if any of them ever "convert" in ways that'd require SSL certs? I understand why the use of pirated XP and 10 year old hardware are rampant across the 3rd world, for _my_ clients that demographic is almost certainly not likely to be ecommerce customers... That's a bit of a personally skewed perspective though, there's no good argument to be made that says wikileaks/twitter/gmail users on old hard/software shouldn't get ssl protection, but I suspect high-end bed linen online shops wouldn't be hurt at all by using SNI and thereby increasing friction for IE6/WinXP users…)
- mfincham 13y agoSome good information on this from Geoff Huston: http://www.potaroo.net/ispcol/2012-08/EndPt2.html http://www.potaroo.net/ispcol/2012-08/EndPt2.html
- p1mrx 13y agoAnd news.ycombinator.com is still IPv4-only.
- nknighthb 13y agoThe main argument for migrating existing websites to IPv6 in the near-term is merely to aid the policy goal by showing "Hey! IPv6 is in actual use!". On the technical side, there are various transition mechanisms that can ensure even "IPv6-only" clients will be able to communicate with most legacy IPv4 services for years to come. HN is not holding up progress.
- teddyh 13y agoNo, such a thing does not exist. At least not automatically. There are stories[1] about large corporations getting complaints from end customers in Asia about not being reachable - and it turns out the customers only have IPv6. IPv4 FAIL. (Note: APNIC ran out of IPv4 addresses more than two years ago[2], and has had rapid internet expansion in the mean time. Asians are heavy IPv6 adopters.) Such a thing you imagine could conceivably be implemented, but it would be an extra thing for the IPv6-only ISPs to implement, and they do not have the incentive to do so. The current companies with servers do have an incentive to be reachable by IPv6-only customers, and are the only parties who can reasonably solve the situation, by implementing IPv6. 1) https://www.iis.se/blogg/ipv6-nar-sent-inforande-kostar-pengar/ https://www.iis.se/blogg/ipv6-nar-sent-inforande-kostar-peng... (Swedish) 2) https://www.apnic.net/publications/news/2011/final-8 https://www.apnic.net/publications/news/2011/final-8
- nknighthb 13y agoIPv6 doesn't exist automatically, either. If an ISP is going to move their customers to it without setting up the requisite transition mechanisms, I don't see how that's any different than failing to meet the myriad requirements for provisioning a functional IPv4-only network in the modern age. Whom do you blame when an ISP forgets to configure BGP on their routers?
- casca 13y agoThere's always been a vocal group who maintains that the IP addresses that are not visible on the internet should be returned. There are a number of problems with this argument. Firstly, there are legitimate business reasons for having assigned, non-RFC1918 addresses that are only used internally. Interconnecting private networks belonging to different organizations that have overlapping 10.x addresses is a painful process. Sure it's possible to NAT, but given that the IP addresses are effectively an asset of the organization, why not use them? I'm not implying that this is right, but it's how the system was in the past and the cost of changing internal networking and applications could be very high. Secondly, how do you prove that an IP address is accessible on the Internet? Many IPs do not respond to pings and I can easily set up a device that will answer for all IPs behind the corporate gateways.
- p1mrx 13y ago> how do you prove that an IP address is accessible on the Internet? If an address isn't announced in BGP, then for most practical purposes, it's not on The Internet. But I'm sure that if someone acquired the authority to start reclaiming unannounced /8s, the entities holding them would figure out how to announce them quite quickly.
- nwh 13y agoI'd rather just see the massive corporate reservations returned. Why does Xerox need an entire A block, why do Apple, BMW?
- ctrl_freak 13y ago> Why does Xerox need an entire A block, why do Apple, BMW? They don't, but retroactively taking away their /8s would be extremely complicated and expensive for them, not to mention that there is very little benefit from prolonging exhaustion by perhaps 1-2 years at most.
- nwh 13y agoThey could buy the ranges back if they really desired. The results from the Carna botnet show just how sparse the usage of the allocated ranges is. It's practically empty for the entire left upper quadrant. http://internetcensus2012.bitbucket.org/images/hilbert_icmp_map_lowquality.jpg http://internetcensus2012.bitbucket.org/images/hilbert_icmp_...
- jameswyse 13y agoI'd really hoped we'd have more support for IPv6 by now. It's funny, every so often there's a big "We need IPv6" push with lots of media coverage which is forgotten about shortly afterwards. As far as I know there's only one ISP (Internode) here in Australia which offers IPv6.
- rdtsc 13y agoThere is some network effect in there and I've experienced it myself. In a product we make, we can go the extra mile and start supporting IPv6 but the libraries we use, the rest of the echo system we play in, don't support it. So we feel like it would be wasted effort at best and it would break things at worst. A good way we found to force others to configure and bother about IPv6 support is if we deliberately add extra and better features only tied to IPv6.
- kazagistar 13y agoIts not really so bad. Its not like end users need IP addresses. All you need is addresses for all the major servers, and then like a couple dozen for each ISP, right?
- cbhl 13y agoCarrier NAT has lots of bad consequences. It means that NAT-punching may stop working (because there may be two or three levels of it). It makes fraud detection harder. Plus, it's error prone -- once in a while, you'll get data that happens to look like your IP address, and you'll find that you can't send that precise sequence of bits in a packet ever because it'll get mangled by the NAT.
- otterley 13y agoIt also breaks IP-to-geography mapping.
- tjgq 13y ago> once in a while, you'll get data that happens to look like your IP address, and you'll find that you can't send that precise sequence of bits in a packet ever because it'll get mangled by the NAT How so? Those bits should only matter to the NAT logic if they are found in their expected position in the IP header, not in the payload portion of the datagram.
- 0x0 13y agoSome cheap NAT devices rewrites stuff that "looks like" the internal IP addresses inside the TCP payload, in a hackish attempt to "fix" things like FTP and other protocols that send addresses in the payload. A really stupid and dangerous way to do things, but it's been known to happen.
- tjgq 13y agoCrazy. Has that been observed in carrier-grade NAT boxes, though? Or only in el-cheapo residential devices? It seems an incredible risk to the carriers to do things that way.
- PhantomGremlin 13y agoBah. All this IPV4 "exhaustion" stuff can be simply solved. Almost overnight. Right now, most of the space is underused and simply being hoarded. Want to free up 90% of the IPs? Easily? Then charge for them!!! If MIT had to pay $1/mo for each IP address ($16 million per month), it would immediately give most of them back. If MIT had to pay $1/year for each IP address ($16 million per year), it would immediately give most of them back. And yet for people like me, paying (in round numbers) $50 / month for Internet, $1/year or even $1/month would be "in the noise". So how many hundreds of billions of dollars will instead be spent on the designed-by-nerds very-difficult-to-implement not-very-backward-compatible solution of IPV6?
- icebraining 13y agoThat would still only fix the problem for a relatively short time, and then you'd still need IPv6. It's a stopgap, not a long term solution.
- belorn 13y agoSuch policy would lead to an explosion of fragmented patterns in routing, expanding the global routing table. That mean latency and costs would go up while throughput would go down. If I remember right, there doesn't exist hardware for backbone networks that can handle a fully fragmented global routing table at the required speed of today. They are thus unlikely to also handle the increased speed of tomorrow without quantum computers.
- devcpp 13y agoAwesome, that will push IPv6 adoption. And big companies that need this sort of routing for millions of addresses can surely afford paying for these addresses anyway.
- valisystem 13y agoMaking ipv4 a second class citizen working like an low performance compatibility layer for legacy seems like a great migration plan to me. Especially if performance would go down progressively.
- teddyh 13y agoMeanwhile, in Europe, RIPE ran out of IPv4 a year ago[1], and people have been happily implementing IPv6 ever since. In Sweden, there is a government directive[2] that all state infrastructure should implement IPv6 and DNSSEC by this year (2013) at the latest. 1) https://www.ripe.net/internet-coordination/ipv4-exhaustion https://www.ripe.net/internet-coordination/ipv4-exhaustion 2) http://www.regeringen.se/sb/d/15234/a/177127 http://www.regeringen.se/sb/d/15234/a/177127
- MattJ100 13y ago> people have been happily implementing IPv6 ever since. Spoke to my (UK) ISP last week. They said: > "We will support IPv6 when it is in widespread use worldwide. At the moment IPv4 still has a number of fresh IP's." Sigh.
- teddyh 13y agoFound an english version of the directive (PDF): http://www.government.se/content/1/c6/18/19/14/70f489cb.pdf http://www.government.se/content/1/c6/18/19/14/70f489cb.pdf Page 40, Actions, first paragraph: “In addition, all authorities should make use of DNSSEC and be reachable with IPv6 by 2013.”
- bloopletech 13y agoWhat's the time lag until we run out of IPv4 addresses at the VPS/hosting provider and broadband ISP level? I see the situation getting progressively more dire, and presumably these notifications are there to try and get people moving to avoid the wall; but assuming everyone keeps operating as close to the status quo as they are able, how long before we truly hit the wall?
- teddyh 13y agohttp://www.potaroo.net/ispcol/2013-08/when.html http://www.potaroo.net/ispcol/2013-08/when.html Currently the estimate indicates September 2014.