Live data from Hacker News

Is there hope for IPv6?

internetgovernance.org

361–370 of 399 posts

Re: Is there hope for IPv6?

#361
post #297

Earlier quoted context omitted.

> an attempted deployment of IPv6 caused packet storms in the MIT Computer Science and AI Lab's network They were relying on Spanning Tree in a who knows how big broadcast domain. Firstly, that's just begging for things to hit the fan. A single device having a meltdown will cause exactly this, a broadcast storm that is able to take down the entire campus, because it was a single broadcast domain. Secondly, it is a se…

I mean, sure, CSAIL might have been wrong. (Worth mentioning this is just a single building, not all of MIT.) But if even the MIT computer science network isn't set up "right," there's doubtless a huge amount of technical debt for everyone else who's not an MIT nerd to clean up before they can make IPv6 work. And IPv6 would have been more successful if the designers had taken that into account.

Large L2-networks never work well, they all have some issues. Their existence is purely based on lazyness or believing that Ethernet works like the water main... I admit that I might be more obsessive compulsive than most but I find reconfiguring networks to be a whole lot of fun :)

And no matter how smart the peole on campus are, there will always be someone who cannot accept that someone else is more right. I have first hand experience of this since I have tunneled IPv6 at home and know pretty quickly if someone does not listen to ICMPv6 Packet Too Big -messages. Not the first time I contact people about it but so far the only one I have not been able to convince is exactly someone really smart on some campus somewhere. I wrote many emails and tried to explain that IPv6 allows MTU's as low as 1280 bytes and that ICMPv6 is a must allow protocol but nope.

Re: Is there hope for IPv6?

#362
post #297

Earlier quoted context omitted.

I mean, sure, CSAIL might have been wrong. (Worth mentioning this is just a single building, not all of MIT.) But if even the MIT computer science network isn't set up "right," there's doubtless a huge amount of technical debt for everyone else who's not an MIT nerd to clean up before they can make IPv6 work. And IPv6 would have been more successful if the designers had taken that into account.

The switches being good at ARP and bad at an alternative isn't down to technical merits, it's down to which one existed first. And it sounds like turning the intelligent feature off and treating the packets as pure broadcast, just like ARP packets, would have fixed the problem. If the switch can't do that in the right way, it's not the protocol's fault.

Yup, turning off snooping would have fixed the issue at hand but not the poor choice of relying on STP for redundancy.

I've seen this happen a few times in my life in production systems, designed by someone else. Overload a switch somehow and it goes straight in ludacris mode because of the topology. Properly configured networks suffer minor outages only in case of single device meltdowns.

Re: Is there hope for IPv6?

#363
post #354
post #345

Earlier quoted context omitted.

> Anything that is 'IPv4-like with larger addresses' is very much incompatible with any IPv4 equipment or setup at the edge. I disagree somewhat. You could imagine a hierarchical routing structure where IPv4 NAT servers double as IPv4ext routers and gateways. All current servers maintain an IPv4 address which, if the server is unaware of IPv4ext, will not be able to decode things like full client IP address for login…

There problem here is two fold: 1) As far as I know, nobody ever wrote down a protocol description, and preferably made an implementation. The devil is in the details. It is very hard to estimate if such a design would actually work. 2) At the moment, the core of the internet and just about all host operating system support IPv6. The hard part is getting the edge networks to upgrade. My guess is that your proposal wo…

There are a number of proposals that build on these ideas, for example EnhancedIP. Typically, they would encode the extended addressing info in an options field. They were to late the party and missed the circa 2000-2005 window where it became clear Ipv6 will be an uphill struggle. Back in the day, only naive proposals like ipv7 existed, "ipv4 with larger address" but that solves little.

The fundamental difference compared to dual stack is that there is no technical cost to deploy it outside software updates and very little risk - aside from the dubious security benefits of NAT. Not only the core, but virtually all hardware and software on the Internet today support ipv6, but there is an enormous cost to configure it to work.

This flexibility and drop in upgradability of things like EnhancedIP comes with the significant cost of breaking the internet into 2^32 independent routing domains that prevent you for getting the full benefits of the larger address format. This is an acceptable trade off only in retrospect, after the v6 "failure".

Re: Is there hope for IPv6?

#364
post #304

Earlier quoted context omitted.

Sorry I'm not sure i understand: > Another wrong in the name of IPv6: 64 bit IPv6 prefixes from an ISP means you can only have one subnet. No way to put your dodgy IoT stuff on its own VLAN. Can't your router handle carving up a subnet just fine?

A lot of self-assigned IPv6 networks just tack on the device's 64-bit MAC address on to the end of some 64-bit network prefix. So if you're going with self-assignment of IPv6 addresses then you will have difficulty if your assigned prefix is already 64-bits, since you can't really use any of the 64-bit suffix bits for your own network.

What are you using at layer 2 that has 64-bit MAC addresses?

Re: Is there hope for IPv6?

#365
post #220
post #153

IPv6 is already a success in mobile and IoT, and in countries that matter in economical sense. The rest will follow automatically because they have no choice. More worrying issues are BGP and SS7 reliance in global networks, and there are no viable alternatives on the horizon.

Could you expand on these problems? Why is SS7 an issue? (Aren't telcos moving to IP based platforms? Device registration on towers can work on whatever protocol the device supports the base station encapsualtes/proxy-es/processes that further, and the telco can use whatever routing it wants internally - eg iBGP. Or even some fancy OpenFlow based control plane.) And of course the issues with BGP seem even more intere…

I presume they're referring to the ease of hijacking SS7 where SMS is so widely used for authentication / authorization.

Re: Is there hope for IPv6?

#366

Earlier quoted context omitted.

The switches being good at ARP and bad at an alternative isn't down to technical merits, it's down to which one existed first. And it sounds like turning the intelligent feature off and treating the packets as pure broadcast, just like ARP packets, would have fixed the problem. If the switch can't do that in the right way, it's not the protocol's fault.

Yup, turning off snooping would have fixed the issue at hand but not the poor choice of relying on STP for redundancy. I've seen this happen a few times in my life in production systems, designed by someone else. Overload a switch somehow and it goes straight in ludacris mode because of the topology. Properly configured networks suffer minor outages only in case of single device meltdowns.

It seems like it took multiple switches melting down from bad software design to cause the problems. I originally had a line about the risk of large broadcast domains but the comments on the post claim they were actually pretty small.

Re: Is there hope for IPv6?

#367

Earlier quoted context omitted.

>> ... the utter failure of v6. > Even if IPv6 was completely perfect... More specifically: "completely technologically perfect". Which is the point being made in this thread: the technical aspect is of only partial relevance. If IPv6 fails because of political problems, or "contextual ones" (like “we could make it technologically inferior but more readily backwards compatible; it would make it less awesome but easie…

If IPv6 fails because of political problems Every major OS, network device maker, service and program supports it. I can't imagine it "will fail" in any way where everyone goes "ok, forget IPv6, let's move on to IPv7 it's the new thing" and the world says "phew, at last!". > According to market researcher Gartner, over 1.5 billion smartphones were sold last year That's an IPv4 internet of address-needing devices ever…

Sure there is, it's called IPv4. For profit companies will continue to beat that dead horse with things like CGNAT for as long as IPv6 continues to fail. The failure is a process not an end state, IPv6 is falling for two decades now and the eventual complete deployment in the year 2040-2050 will be it's complete and giant failure, unless something else comes along to make it irrelevant.

Re: Is there hope for IPv6?

#368

I hope (but am skeptical) that folks look at the overall failure of ipv6 from a deployment perspective to understand the root causes of why it failed (some may think "failure" is too strong a word, but I remember v6 being "just around the corner" in 2000, yet in 2019 I'm still connecting to a GCP database with v4). Coming up with a solution that looks like a huge technological advancement, with no real respect for th…

IPv6 adoption has been on an exponential growth curve for a long time, with an inflection point where it really started taking off around 2013. Google has some very solid stats to back this up https://www.google.com/intl/en/ipv6/statistics.html There are absolutely motivations and incentives for the advancement of IPv6, the most obvious of which is the exhaustion of IPv4 address space. The Notice the inflection point…

An exponential works in an unlimited population or for as long as it's effects are negligible compared to total population size. Once you have converted a significant part of the population, the number of possible targets starts to drop exponentially. You will reach for the highest hanging fruits, sysadmins who don't give a crap, nutcases that hate IPv6 for killing their dog, legacy devices that only Bob knew how to manage but we fired Bob back in '98, and so on.

There's every reason to believe reaching a point where IPv6 is widely enough supported to allow you to turn off your IPv4 address, say over 99%, will take the same number of decades as has taken to get to 50%.

You can already see this reverse inflexion in countries that are further along like US and Germany.

Re: Is there hope for IPv6?

#369
post #353

Earlier quoted context omitted.

What do you mean "incompatible"? You can run both of them at the same time, they work on the same links, in the same OS stacks, with the same programs, and you can talk between them or tunnel over them with a variety of transition mechanisms (dual stack, Teredo, 6to4, 6rd, 6over4, ISATAP, 6in4/4in6, NAT64/DNS64, 464xlat, DS-lite, MAP-T/E, 4rd, LW4over6, ...). They're about as compatible as they can possibly be, given…

I mean that IPv6, to my (admittedly poor) understanding, does not contain a specification as to how to route "legacy" IPv4 packets. To have IPv4 packets work in an IPv6 network, you need a whole IPv4 infrastucture. And when you are there, you may as well just use IPv4. But maybe I am mistaken. Does the IPv6 specification proposes way to map an IPv4 network inside an IPv6 one? Or are all these later hacks?

I'm not fully sure what you're asking for here exactly... you're going to need a v4 infrastructure to route v4 packets, because that's what having a v4 infrastructure means.

You can map the entire v4 space into a v6 /96 with NAT64. That works fine, giving the same sort of outbound-only connectivity that NAT gives in v4. Does that do the job?

Re: Is there hope for IPv6?

#370
post #363
post #354

Earlier quoted context omitted.

There problem here is two fold: 1) As far as I know, nobody ever wrote down a protocol description, and preferably made an implementation. The devil is in the details. It is very hard to estimate if such a design would actually work. 2) At the moment, the core of the internet and just about all host operating system support IPv6. The hard part is getting the edge networks to upgrade. My guess is that your proposal wo…

There are a number of proposals that build on these ideas, for example EnhancedIP. Typically, they would encode the extended addressing info in an options field. They were to late the party and missed the circa 2000-2005 window where it became clear Ipv6 will be an uphill struggle. Back in the day, only naive proposals like ipv7 existed, "ipv4 with larger address" but that solves little. The fundamental difference co…

There is a large cost to configure IPv6 because most operators have ignored IPv6, waiting for the IETF to magically get it right.

There is very little consensus within the operator community on how to deploy IPv6. The net effect is that there is an endless series of configuration options.

Which leads to having to select equipment very carefully to make sure you get an overlapping feature set.

The problem with something like encoding extra address bits in IPv4 options is that you would have to get a large group of operators on board for it to get any traction.

For example, the ISP that I use for my home internet connection give customers a static (officially 'stable') IPv4 address. It may not be beneficial for them if a next generation internet protocol would force the deployment of NAT boxes.

The downside of dual stack is that you have to manage 2 networks. The benefit it that you manage two completely separate networks. IPv4 routing has very little effect on IPv6 routing.

Merging the two, as is done for example with NAT64/DNS64, leads to network issues that many people don't understand. I think you would get the same if you mix legacy IPv4 stacks with stacks that encode extra bits in an IPv4 header option.

This is of course completely ignoring the fact that many firewalls just drop anything that has IPv4 options. So deployment may be just as an uphill battle as IPv6.

Post reply on HN