Live data from Hacker News

So Long Last /8 and Thanks For All the Allocations

labs.ripe.net

121–130 of 201 posts

Re: So Long Last /8 and Thanks For All the Allocations

#121

Earlier quoted context omitted.

It does but I can't say how frequently. My IPv4 address has only changed 7 times since 2012. My IPv6 record has changed once this year when I shut down my modem for an extended period of time. I use http://freedns.afraid.org/ to manage my DNS. They support IPv4 and IPv6 with domain linking so you can update all your DNS records with 2 calls (one for IPv4 and one for IPv6). This can be done with wget via a cronjob on…

Thanks. I am very much interested in making a similar setup of my own on a Raspberry Pi. Do you recall what were the IPv6 issues with Rasbian? Also, do you have any concerns about potentially going against Comcast policies which appear to prohibit running servers?

I guess I should rescind my comment about Raspbian because I haven't had any major issues since the Jesse release and I doubt anyone is even going to use that with the Stretch release out.

I had a lot of issues with Raspbian prior to Jesse just failing completely to get an IPv6 address from the Gateway and not being able to resolve anything.

I've been running Pi.Hole and OctoPi on Jesse for at least 6 months with only minor issues that aren't the distro's fault but the applications. OctoPi doesn't even configure the HTTP Server so IPv6. Pi.Hole listens for HTTP requests and responds with errors.

I installed Stretch on a Pi and setup a Ubiquiti Controller a few weeks ago and IPv6 works flawlessly with it.

\* Regarding Comcast's policies, I have never run into an issue with them and I've been running servers for over a decade. That being said, mine are personal use, low traffic, and not business related.

Re: So Long Last /8 and Thanks For All the Allocations

#123

Can anyone offer an explanation why IPv6 still has not blanketed the world yet? I mean if client pings an IPv4 address, it should be automatically converted to an IPv6 version. So why isn't IPv4 instantly outdated?

What? Converted by who? How does this work?

For IPv6 only like that https://tools.ietf.org/html/rfc6877 Sprint mobile uses that method

Re: So Long Last /8 and Thanks For All the Allocations

#124

Earlier quoted context omitted.

Man I've worked with my fair share of quasi-governmental agencies who have a /8 or /16 to themselves and use it for their internal address space. I wonder how many addresses we'd have if we could take back unused address space.

Why do they do that? They already have an /8 to themselves -- 10.0.0.0/8. Did they need an additional 16M IP addresses?

Well, see, compared to what most of us are used to nowadays, IP networking looked a little bit different back then.

In 1981, RFC791 [0] came about, describing a way of doing IP addressing on the ARPANET (based upon "classful networks" [1]). In accordance with this scheme, you would get either a /8 ("Class A"), a /16 ("Class B"), or a /24 ("Class C") -- depending on how many hosts you had (or thought you might reasonably have). This is the main reason why you see some organizations with a /8 today that you wouldn't expect.

Classless routing ("CIDR") [2] -- or, more specifically, variable length subnet masking (VLSM), what we're all familiar with today -- didn't officially exist until RFC1518 [3] and RFC1519 [4] (fall 1993). CIDR was introduced as a solution to a problem people were already starting to experience then: a shortage of IPv4 addresses!

(Yes, 25 years ago, they realized they were running out of IPv4 addresses and started working on solutions. IPv6 [5] first emerged as a "draft standard" in late 1998 -- but only officially became an "Internet standard" last summer!)

[0]: https://tools.ietf.org/html/rfc791

[1]: https://en.wikipedia.org/wiki/Classful_network

[2]: https://en.wikipedia.org/wiki/Classless_Inter-Domain_Routing

[3]: https://tools.ietf.org/html/rfc1518

[4]: https://tools.ietf.org/html/rfc1519

[5]: https://tools.ietf.org/html/rfc8200

Re: So Long Last /8 and Thanks For All the Allocations

#125

Earlier quoted context omitted.

Why do they do that? They already have an /8 to themselves -- 10.0.0.0/8. Did they need an additional 16M IP addresses?

There was a time before NAT, where every machine had a publicly routable IP, and things were good. Any machine could talk directly to any port on any other machine (firewall willing). Until one day, IP exhaustion attacked. Thankfully NAT doesn't exist in IPv6, because 2^128 addresses should be enough for everybody.

Everything having a publicly routable IP isn't an automatic good thing.

Re: So Long Last /8 and Thanks For All the Allocations

#126
post #65
post #36

Earlier quoted context omitted.

> Windows just works seems to fuck with nonWindows clients so Enterprises disable it via Group Policy. well I've seen most enterprise networks with no IPv6 support. (mostly admins thing that this beast is hard to work with) Also Kubernetes has limited IPv6 support (mostly on the documentation site) (of course it's easier to support a IPv6 only cluster, because heck you wouldn't really need BGP or some wierd overlay n…

privacy is not the issue. Selling business plans is the real reason.

You won't believe the number of crazy people in Germany who believe that static IP addresses are the root of all evil because of all the magucal tracking and surveillance possibilities they famtasize about.

Re: So Long Last /8 and Thanks For All the Allocations

#127
post #36

Earlier quoted context omitted.

Support for IPv6 is weird. Comcast's IPv6 implementation is rock solid and faster than IPv4 most of the time. I've been running publicly accessible IPv6 HTTP hosts over it for several years now. The last two Motorola Modems I've had came with IPv6 support and were provisioned by Comcast out of the box. Access Points from D-Link will autoconfigure via SLAAC but DNS has to be hardcoded. It's 2018 and yet Ubiquiti's Uni…

> Windows just works seems to fuck with nonWindows clients so Enterprises disable it via Group Policy. well I've seen most enterprise networks with no IPv6 support. (mostly admins thing that this beast is hard to work with) Also Kubernetes has limited IPv6 support (mostly on the documentation site) (of course it's easier to support a IPv6 only cluster, because heck you wouldn't really need BGP or some wierd overlay n…

Other big German providers just fail at this. O2 for example only hands out IPv6 addresses very selectively based on whose lines they are renting in the area. I have no chance in hell of getting an IPv6 prefix from them.

Re: So Long Last /8 and Thanks For All the Allocations

#128
post #38

IPv4 address utilization is incredibly low. For example, consider 44.0.0.0/8 - it's sitting around almost entirely unallocated. UCSD Caida uses it for their network telescope (pretending to use it for amateur radio) and won't give it back. Just look at how dark it is: https://benjojo.co.uk/internet-2018.png (from https://blog.benjojo.co.uk/post/scan-ping-the-internet-hilbe... ) Discussion on r/amateurradio - https://…

They don't have to give it back, of course. If anything, the first organization to have netblocks yanked out from under them should be the US DoD. As I mentioned a few days ago [0]: > There are also large portions of the 13 /8s (218 million IPs!) assigned to the US Department of Defense [5] that you wouldn't need to scan since there are no routes to them at all: the 11.0.0.0/8, 22.0.0.0/8, 26.0.0.0/8, 28.0.0.0/8, 29.…

Technically that depends on the agreements with IANA. If IANA could say "HEY YOU if you're not using 80% of your space actively, by January after next then we'll charge you a an exponentially increasing fee" I suspect they'd get a lot more movement. I suspect that the price of IP space on the market will also change that attitude as people go "Well crap that's worth a lot of money"

Re: So Long Last /8 and Thanks For All the Allocations

#129

Another interesting complication is Android's longstanding lack of full support for DHCPv6: https://android.stackexchange.com/questions/3718/does-androi... https://issuetracker.google.com/issues/36949085

Many people, myself included, feel DHCPv6 is a silly idea and should go away. IPv6 was designed to not need it, and continuing to use DHCP is just inertia and a desire to keep doing things in the same old way.

As I recall originally everyone was supposed to use well-known addresses like ::1, 2, 3 on the current network or multicast DNS.

But nooo. Was that too hard? DHCP or nothing! And then DNS was added to SLAAC.

The rest of DHCP was always useless. Once you have DNS, it can be used for all other service discovery.

Re: So Long Last /8 and Thanks For All the Allocations

#130

Earlier quoted context omitted.

There was a time before NAT, where every machine had a publicly routable IP, and things were good. Any machine could talk directly to any port on any other machine (firewall willing). Until one day, IP exhaustion attacked. Thankfully NAT doesn't exist in IPv6, because 2^128 addresses should be enough for everybody.

Everything having a publicly routable IP isn't an automatic good thing.

NAT does nothing meaningful securitywise that a firewall cannot achive, and causes a lot of stupid problems.
Post reply on HN