Live data from Hacker News

Tell HN: IPv6-only still pretty much unusable

news.ycombinator.com

591–600 of 649 posts

Re: Tell HN: IPv6-only still pretty much unusable

#591
post #577

Earlier quoted context omitted.

> And lastly... a lot of IT guys still don't care for IPv6 The issue I have with IPv6 is that it's so complex compared to the IPv4 I know, and still has lacking support in routers and similar. For example, I want to be sure my local devices uses my local NTP server. With IPv4 it's trivial, I just add an option to the DHCP server. With IPv6 I can't do that with RA, I have to use DHCPv6. But Android doesn't support DHC…

> For example, I want to be sure my local devices uses my local NTP server. With IPv4 it's trivial, I just add an option to the DHCP server. With IPv6 I can't do that with RA, I have to use DHCPv6. But Android doesn't support DHCPv6, so I have to run both RA and DHCPv6, and hope it just works out. Out of curiosity, why does this require DHCPv6? Cant you just point your local devices to ntp.homedomain (or whatever the…

> Cant you just point your local devices to ntp.homedomain

So how do I do that without configuring each device manually? I mean, that's way too much hassle.

Re: Tell HN: IPv6-only still pretty much unusable

#592

Earlier quoted context omitted.

Why can't you use it as a firewall? It's weird, and against RFCs for your ISP to only give you a /64, but that should still be routed address space is routed through your router/firewall box, and therefore trivial to firewall with the normal tools. This is also pretty much the necessary topology, because if the box needs to do NAT for IPv4, it needs to terminate the address on the firewall too. You'd need separate in…

I'm dealing with this now as well..=( Do you happen to have a reference from the RFC, about it being against spec to hand out just a /64?

Originally (2002) a /48 per site was recommended in RFC3177.

More recently (2011) RFC6177 took a more pragmatic / softened approach, but it does say:

      - it should be easy for an end site to obtain address space to
        number multiple subnets (i.e., a block larger than a single /64)
        and to support reasonable growth projections over long time
        periods (e.g., a decade or more).
I don't really understand why ISPs choose to be so stingy with allocations. An extra 8 bits of address space to allocate /56 instead of /64 costs them effectively nothing and has considerable operational benefits, simplifies CPE configuration etc. Just minds still living in IPv4 land I guess.

Re: Tell HN: IPv6-only still pretty much unusable

#593

Earlier quoted context omitted.

45% of users are on IPv6. Clearly almost half of ISPs have adopted it, probably more than half of consumer ISPs.

How many of those are Mobile? And how many of those mobile ipv6 addresses are communicating with the "real" internet through a carrier grade NAT to translate/intermediate with IPV4 servers/addresses? And about the most offensive, disgusting thing to ipv6 people is the NAT. It's the thorn in their side that 1) IPV6 "trivially" solves (allegedly) but even worse 2) it's what keeps ipv4 on life support with the ISPs. Can…

Too much of the web is mobile these days to be dismissing it.

Yes, mobiles on v6-only with NAT64 to reach legacy v4 hosts is a massive success story. How can you say with a straight face that it's not?

Most big landline ISPs in the US are doing v6. Comcast, the poster child for awful ISPs, winner of multiple worst company in America awards, has been running v6 over their entire network for years now.

Re: Tell HN: IPv6-only still pretty much unusable

#594

Earlier quoted context omitted.

Both of those statements are wrong. It provides benefits to the user and it's no more of a security vulnerability than having any other networking protocol is. If anything, v4 is more of a vulnerability because it's so easy to scan and because NAT increases the complexity enough that most people don't understand how their networks work.

Three decades of IPv6 mis-adoption shows otherwise. "Running out of IPv4 addresses" is not a problem you face unless you're an internet service provider or a mobile network. 99.99999% of the rest of us don't care because we use 192.168.0.0/16 or 10.0.0.0/8 when we have to do networking. Yes, NAT is complex. That sucks. No, blindly stating "you don't need NAT and you're holding it wrong" is just plain incorrect. Pleas…

It causes no end of problems, not just for ISPs and mobile networks but also for people running server networks and for end users like us. I suppose it can be hard to see that when you grew up with the problems and have never used a network where you didn't need to deal with them though.

The world can mostly function without NAT. It's mainly only used to work around address shortages, which aren't an issue on v6, so there's simply no reason to use it most of the time. It can be a useful tool in your toolbox, but it's one that you only need to use very rarely.

Here's a benefit from v6: 40% faster connection setup†. Measurable benefits show that there are benefits. "No need to use NAT" is of course another obvious benefit of v6.

†: https://www.zdnet.com/article/apple-tells-app-devs-to-use-ip....

Re: Tell HN: IPv6-only still pretty much unusable

#595

Earlier quoted context omitted.

Why can't you use it as a firewall? It's weird, and against RFCs for your ISP to only give you a /64, but that should still be routed address space is routed through your router/firewall box, and therefore trivial to firewall with the normal tools. This is also pretty much the necessary topology, because if the box needs to do NAT for IPv4, it needs to terminate the address on the firewall too. You'd need separate in…

I'm dealing with this now as well..=( Do you happen to have a reference from the RFC, about it being against spec to hand out just a /64?

It's not an RFC, but RIPE690 is pretty clear on the matter:

https://www.ripe.net/publications/docs/ripe-690#4-2-3--prefi...

Re: Tell HN: IPv6-only still pretty much unusable

#596

I've always figured the easy way to improve adoption rates is to build in a statistical failure to ipv4 stacks; add a kernel option to drop 0.1% of ipv4 packets, or add a 250ms delay to ipv4 packets, and adoption of ipv6 will skyrocket without significantly impacting existing workloads because v4 will still work 99.9% of the time.

Who would opt in to using it? Only people who don't need the extra encouragement. It would be easy but entirely ineffective.

Re: Tell HN: IPv6-only still pretty much unusable

#597

Earlier quoted context omitted.

How many of those are Mobile? And how many of those mobile ipv6 addresses are communicating with the "real" internet through a carrier grade NAT to translate/intermediate with IPV4 servers/addresses? And about the most offensive, disgusting thing to ipv6 people is the NAT. It's the thorn in their side that 1) IPV6 "trivially" solves (allegedly) but even worse 2) it's what keeps ipv4 on life support with the ISPs. Can…

Too much of the web is mobile these days to be dismissing it. Yes, mobiles on v6-only with NAT64 to reach legacy v4 hosts is a massive success story. How can you say with a straight face that it's not? Most big landline ISPs in the US are doing v6. Comcast, the poster child for awful ISPs, winner of multiple worst company in America awards, has been running v6 over their entire network for years now.

Because you should talk to an ipv6 person and say the word "NAT". They froth at the mouth.

It IS a success, but it's a success that is singularly enabled by the #1 thing that ipv6 people hate with a passion: a NAT. The evil NAT that has kept IPV4 address space alive, that was the crutch that kept ipv6 from being adopted earlier. The evil NAT isn't a firewall, the evil NAT can be replaced by string-of-acronyms.

And, it's a success which paves the way for practically any protocol to replace ipv6 as the real successor, like the casually thrown out ipv4.4++v2, which is getting dismissed right and left by the ipv6 people here. Or god forbid a better protocol. Please give me ipv8.

Not that I was in the room, but it's apparent that the mobile success is due to the fact the cartel of phone makers and spectrum owners/mobile carriers got in a room and adopted ipv6 head to toe.

I would like to know if the FCC had a role here, or it's just that the mobile carrier industry is used to adopting new standards so this wasn't a big deal, or it was the OEMs that enforced/enabled it.

For the rest of ipv4-land, where is this cooperation/regulation/coordination for migrating?

My comcast modems do not support ipv6 last I tried, but that was three years ago. Maybe the magic wand has been waved finally. But I look at this thread and think: Eh, nope.

Re: Tell HN: IPv6-only still pretty much unusable

#598

Earlier quoted context omitted.

If you want failover-independent IPs you can keep using NAT, ie NPTv6, at the gateway level and not bother with giving public IPs to your LAN machines.

That's possible, but my understanding is that NPTv6 is strongly discouraged. Part of the point of IPv6 is do away with NAT and the problems caused by it. I was hoping there was a better way.

Use the GUA prefix from the main ISP. During failover, retract it and switch to the GUA prefix from the second ISP. Prefix translate any stragglers that don't switch to the new prefix for whatever reason.

For active/active you can distribute both prefixes, but you don't get much control over which network clients pick. You can do the same thing here though: NAT only the outbound connections that you specifically want to steer onto the other ISP.

This way you avoid most of the problems of NAT.

Re: Tell HN: IPv6-only still pretty much unusable

#599

Earlier quoted context omitted.

Too much of the web is mobile these days to be dismissing it. Yes, mobiles on v6-only with NAT64 to reach legacy v4 hosts is a massive success story. How can you say with a straight face that it's not? Most big landline ISPs in the US are doing v6. Comcast, the poster child for awful ISPs, winner of multiple worst company in America awards, has been running v6 over their entire network for years now.

Because you should talk to an ipv6 person and say the word "NAT". They froth at the mouth. It IS a success, but it's a success that is singularly enabled by the #1 thing that ipv6 people hate with a passion: a NAT. The evil NAT that has kept IPV4 address space alive, that was the crutch that kept ipv6 from being adopted earlier. The evil NAT isn't a firewall, the evil NAT can be replaced by string-of-acronyms. And, i…

No need for conspiracies - see for example the presentations from T-Mobile to nanog: https://pc.nanog.org/static/published/meetings/NANOG73/1645/... and https://www.internetsociety.org/resources/deploy360/2014/cas..., just for two examples after thirty seconds of googling.

Comcast has had ipv6 support rolled out for some time now. I don’t know why you don’t see it.

Re: Tell HN: IPv6-only still pretty much unusable

#600
We use it in production. Much of our traffic comes in to us on it.

We dual stack, though, as we know we won’t be able to access all external resources we need over it.

If you are expecting everything else to work over v6 before you deploy it then you’re hoping to be the last network on earth to do so. And there can only be one of them so that game of chicken can’t end.

There will be a very long tail of networks only on v4. Yep.

Post reply on HN