Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Dagger2
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
33 ms
·
451.
▲
by
Dagger2
4y ago
Mobile carriers want v6 because it saves them money. CGNAT capacity is expensive. Having native v6 means that >50% of your traffic won't need to touch the CGNAT, which reduces your costs significantly. NAT is a necessary evil to dea
452.
▲
by
Dagger2
4y ago
Use the GUA prefix from the main ISP. During failover, retract it and switch to the GUA prefix from the second ISP. Prefix translate any stragglers that don't switch to the new prefix for whatever reason. For active/active you can
453.
▲
by
Dagger2
4y ago
Who would opt in to using it? Only people who don't need the extra encouragement. It would be easy but entirely ineffective.
454.
▲
by
Dagger2
4y ago
It's not an RFC, but RIPE690 is pretty clear on the matter: https://www.ripe.net/publications/docs/ripe-690#4-2-3--prefi...
455.
▲
by
Dagger2
4y ago
It causes no end of problems, not just for ISPs and mobile networks but also for people running server networks and for end users like us. I suppose it can be hard to see that when you grew up with the problems and have never used a network
456.
▲
by
Dagger2
4y ago
Too much of the web is mobile these days to be dismissing it. Yes, mobiles on v6-only with NAT64 to reach legacy v4 hosts is a massive success story. How can you say with a straight face that it's not? Most big landline ISPs in the US
457.
▲
by
Dagger2
4y ago
> I have always understood NAT's protection to be limited to prohibiting incoming connections It doesn't actually do this. NAT rewrites the source address of outbound connections. Inbound connections aren't outbound connec
458.
▲
by
Dagger2
4y ago
It's workable if all of the machines you're going to talk to have v6, which is doable. Or you can run your own NAT64. It would also be very easy to suggest that maybe Hetzner want to encourage people to keep paying for v4.
459.
▲
by
Dagger2
4y ago
That could actually work for the host ID part of the address (not so much the network part). You could do it today with v6 just by extending getaddrinfo() (e.g. with an NSS plugin on Linux). But L3 addresses aren't the place for naming
460.
▲
by
Dagger2
4y ago
Which is weird, because there is a business incentive: money. But instead, companies seem to be willing to pay out huge amounts of money to not deploy v6.
461.
▲
by
Dagger2
4y ago
Layer 3 exists as a layer of routing and aggregation on top of layer 2. Aggregation necessarily consumes address space, so L3 needs to be bigger than L2 to accommodate the full L2 address space. The L2 address space is 64 bits and the next
462.
▲
by
Dagger2
4y ago
There is in fact an options section in v4, and I think it's pretty obvious how it could be used: you could put extra address bits there. The problem is... how do you get those extra address bits to work? If you think through that quest
463.
▲
by
Dagger2
4y ago
Both of those statements are wrong. It provides benefits to the user and it's no more of a security vulnerability than having any other networking protocol is. If anything, v4 is more of a vulnerability because it's so easy to sca
464.
▲
by
Dagger2
4y ago
You should learn a bit about v6 before criticizing it for not doing things that it is doing. You're basically reinventing 6to4. > Also, oh yes please give me more fucking ports. IPv6 keeping the same number of ports is stupid. IP do
465.
▲
by
Dagger2
4y ago
That sounds like pMTUd failure. The easiest check for that would be to set your client machine's MTU to 1280 and see if it fixes it. Most people work around that problem with TCP MSS clamping in v4. Sometimes they don't apply the
466.
▲
by
Dagger2
4y ago
Red Alert 2! They never added IP-based LAN play to it.
467.
▲
by
Dagger2
4y ago
Starlink are working on it; they've turned on v6 in lots of places over the past month or so. Although you shouldn't need to do any special handling for v4-only sites on v4-only networks. Your DNS results should be sorted to put v
468.
▲
by
Dagger2
4y ago
If you're on Fios, there's an issue between checksum offloading on Intel NICs and the ONTs that Fios uses. The workaround is to disable checksum offloading. If not, perhaps you forgot to apply TCP MSS clamping on v6. (An easy test
469.
▲
by
Dagger2
4y ago
The majority of the problems seem to come from the fact that v6 addresses are longer than v4 ones. That's why we need socket(AF_INET6)s and AAAA records and a DNS API that supports multiple address families and dual stack and new firew
470.
▲
by
Dagger2
4y ago
Even better, instead of using a reserved unrouted address, use the "IP version" header field, which literally exists for this exact purpose. I'm struggling to see how this would improve anything over what v6 did though.
471.
▲
by
Dagger2
4y ago
Yeah, just pick <prefix>::200 instead of <WAN IP>+<RFC 1918>.200. Forget "no hope", that actually looks easier than the v4 case to me... especially if you have any RFC1918 clashes going on, which many companies d
472.
▲
by
Dagger2
4y ago
v6 already is backwards compatible. Pretty much every form of backwards compatibility that is possible with v4 is available in v6. The problem is that v4 isn't forwards compatible with larger address spaces, and that's a problem
473.
▲
by
Dagger2
4y ago
You're thinking of DNS, which... we already have. v6 actually changed very little from v4. It more or less works in exactly the same way v4 does.
474.
▲
by
Dagger2
4y ago
You can do that with NAT64, which you can run as a service in your datacenter rather than needing to deal with v4 throughout it. (In fact it doesn't have to be run in your datacenter -- it could be outsourced to somebody else, which wi
475.
▲
by
Dagger2
4y ago
It definitely doesn't do any of that. Your problem was having a non-Pi-hole DNS server configured. If you want to run all of your DNS queries through Pi-hole, don't configure a DNS server that's not the Pi-hole server (or whi
476.
▲
by
Dagger2
4y ago
Just like IPX. It's still necessary and in use for some things -- so it hasn't reached its end of life -- but when was the last time you ever thought about it? By this metric, we still haven't finished migrating to v4.
477.
▲
by
Dagger2
4y ago
It's not "twisted into uselessness"... the reduction in routing table size comes from the large address space. No twisting was needed. Also, the routing tables we're talking about here need to be stored in TCAM. Content-
478.
▲
by
Dagger2
4y ago
This is straight up untrue. The only thing NAT does is change the apparent source address of outbound connections. Inbound connections aren't outbound connections, so it does nothing to them. NAT is not a substitute for a firewall.
479.
▲
by
Dagger2
4y ago
You're more or less describing 6to4. It's already a thing in v6.
480.
▲
by
Dagger2
4y ago
That's NAT64. It's something that Hetzner could and should be providing for their customers, but as far as I can see they aren't.
More ›