Live data from Hacker News

By installing NAT, MIT stifles innovation

blog.achernya.com

121–130 of 188 posts

Re: By installing NAT, MIT stifles innovation

#121
post #99

Earlier quoted context omitted.

I totally understand why Comcast, AT&T, Verizon and other service providers would want /16s. They are continent wide providers with millions of customs (millions of sites). I'm trying to grok why MIT went for a /24 instead of a /32. Because they could?

Because they are replacing their /8. They want to make sure they are never constrained.

With their IPv4 /8 they had 2^24 IPv4 addresses to work with, or, from a network perspective, 2^16 /24 (65K) networks, each network containing no more than 254 hosts.

If they had requested a boring /48 IPv6 allocation (that anybody can have just by asking) - they would have had 2^16 /64 networks, and each network could have had basically an infinite number of hosts.

But, this is the IPv6 world, so I would have expected MIT to claim they were a LIR (Local Internet Registry - equivalent of a small ISP or larger) - and asked for a /32 - which would have given them 2^32 networks - or 4 Billion networks to work with. They probably would have assigned the networks by segmenting them on a per site basis - so each site would have had a /48 assigned, so they could have up to 65K sites, each site having 65K networks, each network having (effectively) infinite number of hosts. That is, a /32 would have been far, far, far larger than their /8 was. Easier to manage as well (no VLSM - nothing ever smaller than a /64) And, keep in mind, with a single, no contest request, they could have gotten the /32 adjacent to theirs (another 4 Billion networks, or 65K /48s) so they could aggregate on a /31.

Instead, they've asked for a /24. And I'm just darn intrigued as to why they think they can make use of such an address space. If they weren't constrained with their /8, then a /32 would have been far more than they ever required. (And odds are a /48 would have been sufficient with even modest address management).

I mean, I work with really large mesh networks, millions of nodes, some of our subnets have 20K nodes each on them - we roll out /48s like they are nothing, and even after deploying a couple hundred customers over 10 years, and 25 million nodes, I think we've used up maybe 1500 /48s.

BTW - this doesn't even take into account that they can use RFC 4193 up the wazoo for all sorts of interesting non-globally routable experimental internal networks.

I"m just hoping someone from MIT is reading HN and will clue us in.

Re: By installing NAT, MIT stifles innovation

#122
From the article:

NAT deployment doesn't benefit the Institute in any way,...

I have often had changes foisted upon me that when I looked at them I could see no benefit. In every instance the 'benefit' I didn't see was one that I typically didn't approve of and so hadn't listed in my set of 'possible benefits'.

From reading the article though it sounds like MIT has had a very open and loosely (if at all) documented set of features around network access. And in today's world network access is many things more than it was 10 years ago. But perhaps the process of going through and documenting all of the things they do was 'too expensive' compared to setting it up the way the institution wanted it to work and then dealing with any fallout as it arose.

Another in a series of signs that the Internet is moving from science project to critical infrastructure.

Re: By installing NAT, MIT stifles innovation

#123
post #73

Earlier quoted context omitted.

Sometime, I felt force all IOTs devices, typical laptops, Phones, behind NAT is actually safer for internet as whole. Security via network segmentation. IMO, NAT gateway is good place to lock down and put in network security appliance to track/block all the unwanted connections.

except NAT does neither network segmentation or lock down the network. Those things are done by a router and firewall. Implementing proper security of IoT devices can be solved by A) writing more secure software for IoT devices and B) having a proper firewall solution with sane defaults. Using NAT as a tool to masquerade your IP addres is not secure. see NAT hole punching for example [1] NAT is terrible from a networ…

Has any security threat ever relied on NAT hole punching from the outside in? The only cases I can think of involve defective gateway firmware, and IPv6 is hardly a panacea for that.

My guess is that IPv6 is the ISDN of the 21st century... an intermediate step between two networking paradigms, one being IPv4 and the other being something we haven't seen yet. IPv6 will appeal to specialists but will never, by itself, see wide adoption. The fact is that NAT works for 99.99% of users, and works very well.

Re: By installing NAT, MIT stifles innovation

#125
post #114
post #101

Earlier quoted context omitted.

If your access point wont pass IPv6 traffic - you should consider another AP vendor. I have plenty of older network gear that cannot do IPv6 - but it passes the traffic along un-molested.

I tried 4 different AP vendors (Asus, TP-Link, Cisco) and Comcast did not play nice with them. Random disconnects all the time. Only Google's worked without a hitch. But alas, no IPv6. (I'm busy and don't have time to deal with this BS. I just need internet access that works.)

That isn't what Aloha was getting at, why is a layer 2 device (in this case a WiFi AP) even interacting with IP addressing? You should be able to run whatever you want, whether that be IPv4, IPv6, or your own custom protocol using raw ethernet frames (of which there are quite a few).

Also, what is this whole "Comcast did not play nice with them" trope? I've dealt with Comcast many times, and used Asus, TP-Link, Cisco (the DPC3010 modems are my favorite) and others with them without issue. They aren't even a factor in your internal network and whether or not IPv4 or IPv6 works in it...

Re: By installing NAT, MIT stifles innovation

#126

Earlier quoted context omitted.

MIT just sold off half of its class A subnet. MIT was always going to be the last place on earth to go total IPv6

They'll get to IPv6 faster than the DOD, I guarantee it.

Even Verizon wireline hasn't deployed IPv6....

Re: By installing NAT, MIT stifles innovation

#127
post #62
post #11

A lot of fuss, but if you look at the presentation slide in the middle of the page ( https://4.bp.blogspot.com/-PyyPpTv1p7g/WU7hMEBnm4I/AAAAAAAAE... for reference) it is clear that MIT is not stifling anything or shutting anyone's mouth. MIT is just moving to IPv6. Actually... MIT forcing an entire generation of future engineers to deal with IPv6... That will literally push innovation.

No. IPv6 is great in concept but the world just isn't ready for it yet. Even our Google Wifi access points don't support IPv6 in their latest firmware, so I have no way of using IPv6 even though Comcast supports it. AWS IPv6 support has been sketchy until only this year. Many parts of the world are happily dancing with their IPv4 NAT and their sysadmins have no incentives to support IPv6 whatsoever. Forcing people to…

Forcing people to use anything is never a good way to promote innovation.

Two words: seat belts. The auto industry fought this tooth and nail, as did parts of the general public. But once this painful transition was accomplished, it resulted in a big improvement in automotive safety.

Other examples include EPA regulations that forced out the use of hazardous chemicals and processes. This, in turn, also produced a notable series of entirely improved processes: better for the environment, and often cheaper costs and/or better end results (although not universally, to be sure). The potential for innovation had been present, but these mature industries had to be forced into innovation. The very concept that R&D might improve their bottom line as well as their externalized costs was practically foreign.

Re: By installing NAT, MIT stifles innovation

#128
post #112
post #95

Earlier quoted context omitted.

> Forcing people to use anything is never a good way to promote innovation. Of course it is. That's how innovation happens. They are focused on overcoming a constraint of the system they operate within. In this case, it will be to get around the limitations of the private IPv4 network, or to make the upcoming IPv6 network easier and more appealing to use. Most innovations are to overcome some sort of limitation, whet…

Innovation will happen, but it is heavily misdirected. What if I'm a biology expert and want to run a server to demo something cool? I should be spending my time doing innovation in biology. What if I'm a deep learning enthusiast and came up with something cool to demo? I should be spending my time hacking at that. What if I'm a physics student and want to start a blog? The majority of MIT students are awesome innova…

Running a server isn't demoing something cool in biology, coming up with something cool to demo in deep learning, or starting a blog. If these people are going to spend their time doing innovation in biology, hacking on deep learning, or writing about physics, they shouldn't be spending their time running a server or configuring IP.

Re: By installing NAT, MIT stifles innovation

#129
post #62

Earlier quoted context omitted.

No. IPv6 is great in concept but the world just isn't ready for it yet. Even our Google Wifi access points don't support IPv6 in their latest firmware, so I have no way of using IPv6 even though Comcast supports it. AWS IPv6 support has been sketchy until only this year. Many parts of the world are happily dancing with their IPv4 NAT and their sysadmins have no incentives to support IPv6 whatsoever. Forcing people to…

I am almost positive I saw IPv6 in the release notes for the latest Google Wifi app update, am I crazy?

You are correct: http://www.androidpolice.com/2017/06/22/google-wifi-onhub-up...

Re: By installing NAT, MIT stifles innovation

#130
post #114
post #101

Earlier quoted context omitted.

If your access point wont pass IPv6 traffic - you should consider another AP vendor. I have plenty of older network gear that cannot do IPv6 - but it passes the traffic along un-molested.

I tried 4 different AP vendors (Asus, TP-Link, Cisco) and Comcast did not play nice with them. Random disconnects all the time. Only Google's worked without a hitch. But alas, no IPv6. (I'm busy and don't have time to deal with this BS. I just need internet access that works.)

Honestly I would ditch the Comcast provided router, and bring your own cable modem and router. I can't count all the number of issues I've had with Verizon and Comcast provided equipment.
Post reply on HN