Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Dagger2
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
14 ms
·
271.
▲
by
Dagger2
1y ago
You're talking about v4, right? Because that's the one that works weirdly and has weird failure modes and edge cases. You've gotten so used to dealing with the weirdness that you struggle to even see it, but that doesn't
272.
▲
by
Dagger2
1y ago
They do carry into it though. My v6 packets to 64:ff9b::192.0.2.0/104 go to 192.0.2.0/24, and so do the ones to 2002:c000:200::/40. (And importantly the replies come back too, or would do if I wasn't using one of the v4
273.
▲
by
Dagger2
1y ago
At this point, about 25% of traffic on dual-stack ISPs is v4. So no, v4 isn't where all the stuff the phone wants is. CGNAT is generally only done for v4. v6 isn't needed to provide CGNATed v4, and if v6 is provided as well then i
274.
▲
by
Dagger2
1y ago
It wasn't a whole redesign though? It has an identical network model to v4, routing and address assignment work the same way, it works over the same L2 links as v4, and L4 protocols like TCP and UDP all work the same. DNS is the same.
275.
▲
by
Dagger2
1y ago
You don't need to use ULA addresses to use NAT. You can use any GUA prefix too (preferably one you own or are assigned in some way, rather than squatting on one, to avoid the risk of clashing with someone else).
276.
▲
by
Dagger2
1y ago
It's exactly as private as doing the same service with a GUA prefix. Just get a PI block and pick a /64 from it to use instead of whatever ULA prefix they picked at the moment.
277.
▲
by
Dagger2
1y ago
NAT might be a thing in Mullvad's case, but there's no link between that and needing ULA.
278.
▲
by
Dagger2
1y ago
Even Mullvad give out ULA addresses. You can hardly call that a proper implementation :(
279.
▲
by
Dagger2
1y ago
You probably want to add the "optimistic" or "nodad" flags when adding the address, or you'll need to wait for DAD to finish.
280.
▲
by
Dagger2
1y ago
There has to be one somewhere. In my case it's running on my router, but your ISP can do it at their end, and since you can use any /96 including public ones, it's also possible for anyone to run one: $ dig A +short githu
281.
▲
by
Dagger2
1y ago
My router maps the v4 address space into a v6 /96, and my DNS server returns AAAAs pointing to those addresses. I run my own, but try setting your DNS to 2a01:4f8:c2c:123f::1 (and disabling v4 altogether) to give that a go.
282.
▲
by
Dagger2
1y ago
It's still just one firewall. You can listen on a single socket too (sockets listening on :: will accept v4 connections by default on Linux). You can likely drop many of the v4 ACLs when things are going over v6. It's not no wor
283.
▲
by
Dagger2
1y ago
You're never going to get that. There isn't enough v4 in the world for that. That's kind of why we're doing v6. You don't have to install NAT64 to connect to v4-only hosts -- you can run dual-stack, and use your exi
284.
▲
by
Dagger2
1y ago
There's been endless effort into all of those things. What else are we supposed to do when people just aren't following them anyway? It's not even double the config. For e.g. my firewall, which is a 300-line config that I
285.
▲
by
Dagger2
1y ago
It's an imaginary firewall. NAT won't stop unsolicited connections in to your network -- if anything, its entire purpose is to do the exact opposite of that. If you actually want to block inbound connections when you're doing
286.
▲
by
Dagger2
1y ago
The second line is the only one you need for NAT to work. The first is irrelevant to forwarded traffic. If you have no other rules then a) NAT will be applied to your outbound connections, and b) you'll have no firewall for the netwo
287.
▲
by
Dagger2
1y ago
It's a good strategy if deploying a bigger address space is easy and cheap. When it's incredibly difficult and time consuming, you should pause and consider a bit more carefully. New L3 protocols on the Internet are firmly on the
288.
▲
by
Dagger2
1y ago
Does running `ip link set mtu 1280 dev eth0` on the client machine fix it? A lot of servers have somehow managed to screw up their path MTU discovery. People have been using client-side workarounds for this for many years, but I suspect the
289.
▲
by
Dagger2
1y ago
Overkill is good! It's impossible to get the size exactly correct; your only options are "too small" or "too big". Given how difficult it is to deploy a new L3 protocol, why wouldn't we pick the size that ensur
290.
▲
by
Dagger2
1y ago
You would want that. The upstream network can't do it for you, because RAs can't be routed. Same deal for DHCPv6 (although personally I'd say you can probably skip that and just use SLAAC).
291.
▲
by
Dagger2
1y ago
It's pretty simple with systemd-networkd: # On the upstream network. [Network] DHCP=yes [DHCPv6] PrefixDelegationHint=::/56 # On each downstream network. [Network] IPv6SendRA=yes DHCPPrefixDelegation=yes If
292.
▲
by
Dagger2
1y ago
ssh is fine: ssh fe80::2%eth0 where fe80::2 is the peer's address, and eth0 is the local name of the interface they're on. Unfortunately browsers have decided that link-local is pointless and refuse to support it, so HTTP is
293.
▲
by
Dagger2
1y ago
Sure you can. You can do it today even, let alone in some unspecified number of years.
294.
▲
by
Dagger2
1y ago
::ffff:0:0/96 is for representing v4 addresses in v6 APIs. You shouldn't even see it on the wire at all, but if you do it's just a regular v6 bogon range and not anything to do with v4, so it doesn't get or need any spec
295.
▲
by
Dagger2
1y ago
6in4 is just a basic "put the v6 packet directly into the payload of a v4 packet" tunnelling approach. It's a sensible way of tunnelling one protocol over another (and it's the same thing as 4in6, just the other way arou
296.
▲
by
Dagger2
2y ago
That's... not how things work in general. It would be possible for an ISP to do that, and I'm sure somebody somewhere does, but they could do the exact same thing on v4 so you don't get to blame v6 for it. If your ISP runs th
297.
▲
by
Dagger2
2y ago
You can do it from anywhere on the Internet, you don't need to control the ISP's network or anything. If your NATing router receives a packet with the dest IP set to a LAN machine, it forwards it to said LAN machine regardless of
298.
▲
by
Dagger2
2y ago
No, you don't need to be in direct contact with the NATing router. That's kind of the entire point we're trying to making here. All you need to be able to do is send a packet that ends up at your router with the dest IP set
299.
▲
by
Dagger2
2y ago
IP packets have a "destination IP" header field that specifies where the packet goes. The router reads that to figure out where to send the packet. The only thing NAT does is rewrite the dst or src headers of packets. If there
300.
▲
by
Dagger2
2y ago
I can do it with a moral equivalent of a port forward. This situation was inevitable, but it's not like they just gave up and said "welp, guess they're separate then". We've developed basically every single method o
More ›