Live data from Hacker News

Is there hope for IPv6?

internetgovernance.org

71–80 of 399 posts

Re: Is there hope for IPv6?

#71
post #57
post #53

Earlier quoted context omitted.

The thing about NAT that for network operators it is a negative externality. For them it often simplifies their job. They do not feel the searing pain it inflicts on network application developers. It's hard to come up with a carrot to convince operators that NAT is wrong because from their perspective it isn't, even if it harms the internet as a whole.

As a network application developer I haven't felt much pain from NAT - I need to run a central server to relay connections, but that's about it. And oftentimes I need to run a central server anyway for discovery or authentication. (A few years ago I worked at a startup that enabled secure remote access to corporate networks, as in you could connect from a roaming laptop or mobile app into the network, browse the web,…

You're right some some applications are more effected than others. It sounds like you were dealing with business customers, "asked people to...forward a port on their NAT" is not a viable strategy when dealing with consumers.

I work on P2P applications, so NAT is the bane of my existence.

Re: Is there hope for IPv6?

#72
post #29

What we really need is a killer app that requires end-to-end connectivity. Users have little reason to care about IPv6 right now because the existing ecosystem of services has evolved around the constraints of NAT. As IPv6 deployment expands hopefully we will reach a point where some great new application becomes economically viable. My biggest fear is such an application not emerging quickly enough. Without an imper…

There are great apps "requiring" end-to-end connectivity. Cryptocurrency clients, various videochat solutions, many multiplayer games, bittorrent clients, etc. They either force you to set up port forwarding (unless they can do it themselves using UPnP), or they use STUN/ICE or any of the other NAT traversal techniques. As a last resort it's often sufficient if enough of your users are reachable from the outside and…

Exactly. We already have "the killer app". Or several killers apps. But we also have a NAT punching.

And that works. Does it take blood and tears to make it work? Certainly. But not so many to make it infeasible.

Re: Is there hope for IPv6?

#73
post #31

Earlier quoted context omitted.

What does a system that does take those incentives into account look like?

Loose coupling and no second system effect. IPv6 should have been extended address space and extended address space only, in a manner backwards-compatible with IPv4. You think ARP is broken? Great, implement a fixed version of ARP for both IPv4 and IPv6, meanwhile we'll spec IPv6 to use ARP. Don't design IPv6 to use your new thing called NDP that layers completely differently. You think everyone using NAT is wrong? G…

You hit on the problem with IPv6 designers- they took a solution (bigger address space) to a problem (not enough addresses) and they added a bunch of other changes (No NAT, No DHCP, ARP vs NDP, weird address scheme, etc) that arguably made things worse.

Then they wonder why people aren’t adopting it.

(Its the same complaint I have against Let’s Encrypt. They shoved down a policy which is antithetical to helping their mission.)

Re: Is there hope for IPv6?

#74
post #38

I have been getting native IPv6 from my ISP for nearly six years now. It is not quite as cool as it could be, because I get assigned a new prefix every 24 hours, but still, IPv6 is there, and it "just works". When I connect to machines on my home network in any way involving avahi/zeroconf, the machines talk to each other via IPv6 by default. At work, it's a different story. I have drifted from a sysadmin/helpdesk ro…

> because I get assigned a new prefix every 24 hours

Which kinda defeats the purpose of having a globally reachable unique address in a lot of respects. How am I supposed to allow connections to this device in my firewall if the address is always changing?

Re: Is there hope for IPv6?

#75
post #53

Earlier quoted context omitted.

The thing about NAT that for network operators it is a negative externality. For them it often simplifies their job. They do not feel the searing pain it inflicts on network application developers. It's hard to come up with a carrot to convince operators that NAT is wrong because from their perspective it isn't, even if it harms the internet as a whole.

If NAT is wrong, then firewalls that block incoming connections by default are also wrong. I think you'll have a hard time making that argument.

You're mixing up NAT and ingress blocking. A stateful firewall doesn't depend on NAT, we're just used to ingress blocking as a side effect of NAT.

Re: Is there hope for IPv6?

#76

I like IPv6 it can actually be easier to set up stuff instead of using IPv4 for example OSPF. But I find IPv6 is not as intuitive as IPv4 just looking at an address in IPv4 vs IPv6. You can create new networks for IPv4 pretty easily just by eyeball but not IPv6. At least I can't.

It can be done (using each :XXXX: block as a network instead of splitting it up), but its definitely not quite as easy to eyeball.

Re: Is there hope for IPv6?

#77
post #38

I have been getting native IPv6 from my ISP for nearly six years now. It is not quite as cool as it could be, because I get assigned a new prefix every 24 hours, but still, IPv6 is there, and it "just works". When I connect to machines on my home network in any way involving avahi/zeroconf, the machines talk to each other via IPv6 by default. At work, it's a different story. I have drifted from a sysadmin/helpdesk ro…

> because I get assigned a new prefix every 24 hours Which kinda defeats the purpose of having a globally reachable unique address in a lot of respects. How am I supposed to allow connections to this device in my firewall if the address is always changing?

Exactly. There is more than enough address space to give a person a static IPv6 network.

Comcast is guilty of this. Verizon doesn’t even offer IPv6 on FIOS.

For both, I just set up an IPv6 tunnel to Hurricane Electric using pfSense.

Re: Is there hope for IPv6?

#78

Earlier quoted context omitted.

> Literary, every modern ISP This is either factually incorrect, or else you're using a definition of "modern" that excludes a substantial portion of real world isps.

It in fact excludes most ISPs in many countries.

To be precise this excludes 75% of all autonomous systems in the world, which is at least 75% of all ISPs plus those that connect to 25% of IPv6 capable autonomous systems, but still don't use IPv6. So we are talking like 80% of all ISPs in the world.

Re: Is there hope for IPv6?

#79
post #62

Earlier quoted context omitted.

It's less a redeeming quality and more the entire reason why we bothered to switch to a new system. So yes, that is the point.

Then, given that CG-NAT solutions have proven to work well and they don't bother most end users, it's no wonder the transition to IPv6 has stopped.

> it's no wonder the transition to IPv6 has stopped

Where are you getting that from? Looking at public IPv6 statistics from big companies shows that it's going up. Google's shows a 4.5% increase in IPv6 of total traffic during the past year[0]. Facebook's shows a 6% increase and at 55% for the US [1]. Meanwhile Mexico went from 5% IPv6 to 25% this year [2].

[0]: https://www.google.com/intl/en/ipv6/statistics.html [1]: https://www.facebook.com/ipv6/?tab=ipv6 [2]: https://www.vyncke.org/ipv6status/project.php?metric=p&timef...

Re: Is there hope for IPv6?

#80

Earlier quoted context omitted.

Backwards compatibility seems to be the largest. Look at the deployment of TLS as a success story. Everyone kept on supporting both old and new, watched the percentages, and then dropped the old when the new had enough penetration. The whole thing is also a bit of a shell game. Nobody wants to invest in it until they feel like they're "behind" if they don't. So you have a big player or two in order to make it feel li…

TLS is a great example of how to do it. IPv6 is a great example of how not to.

TLS is way more concentrated than IPv6/IPv4.

There are a handful of browsers that pushed the adoption. There's nobody doing the same in the IPv6 space.

There are areas that the browsers purposefully ignored (DNSSEC, DNS-SD) and thus their adoption is low.

Post reply on HN