Live data from Hacker News

IPv6 Deployment Status

datatracker.ietf.org

31–40 of 78 posts

Re: IPv6 Deployment Status

#31

Earlier quoted context omitted.

NAT is horrible.

Leaned on heavily to protect cheap IOT devices. Could you imagine the bot armies if every IOT device was NOT behind a NAT?

NAT shouldn't be used as a replacement for a firewall. So the answer was always to set up a firewall.

Re: IPv6 Deployment Status

#32

Earlier quoted context omitted.

NAT is horrible.

Leaned on heavily to protect cheap IOT devices. Could you imagine the bot armies if every IOT device was NOT behind a NAT?

The virtues of NAT lie more in their nature of being blanket blacklist firewalls by default.

This can indeed be replaced with firewalls on each IPv6 client, but you have to concede that just putting a router between your computer and modem adds a ton of security for very little effort or know-how.

But NAT in itself is a workaround for IPv4 limitations with significant problems, which has become permanent because there's nothing as permanent as temporary solutions.

Re: IPv6 Deployment Status

#33
post #27

Earlier quoted context omitted.

Most phone companies now provide IPv6 natively over their 4G/5G service, and IPv4 goes through carrier-grade NAT.

My ISP offers a plan without IPv4 at a lower price. v4 websites only are served through their NAT64/DNS64 infrastructure and it works really well except for some dumb applications that hardcode the IPv4 instead of using domain names (yeah, and also the ones that rewrite the entire stack in C and only support AF_INET...)

If possible, can you share the ISPs name?

Re: IPv6 Deployment Status

#34
post #4

At this point I'm personally convinced that ipv6 is a failed technology. It used to be interesting to see the news about new ipv6 deployments, adoption ratings etc. Now I basically don't care.

Setting up IPv6 on my home network was fun and exciting now it's just boring. The only time I've noticed it was was once when IPv4 broke (dhcp server issue) and another time when IPv6 itself broke (radvd issue).

All that said I do sort of wonder when or if we'll ever move off dual stack. I think there's a strong argument that running two protocols at once is riskier then the combined risks of the two.

Re: IPv6 Deployment Status

#35

Earlier quoted context omitted.

Most phone companies now provide IPv6 natively over their 4G/5G service, and IPv4 goes through carrier-grade NAT.

Pretty sure all xbox services use v6 where possible as well.

I am dual stack at home. While my xbox will happily display its ipv6 address my traffic logs still show it heavily preferring ipv4 when actually doing anything.

Re: IPv6 Deployment Status

#36
post #32

Earlier quoted context omitted.

Leaned on heavily to protect cheap IOT devices. Could you imagine the bot armies if every IOT device was NOT behind a NAT?

The virtues of NAT lie more in their nature of being blanket blacklist firewalls by default. This can indeed be replaced with firewalls on each IPv6 client, but you have to concede that just putting a router between your computer and modem adds a ton of security for very little effort or know-how. But NAT in itself is a workaround for IPv4 limitations with significant problems, which has become permanent because ther…

Every IPv6 router for home or small business use is initially configured with a default-deny firewall. The same for every router supplied by an ISP.

This is so basic that any argument against it needs some strong evidence.

You can search "IPv6 pinhole" and find plenty of documentation from router manufacturers and ISPs on this.

Re: IPv6 Deployment Status

#37

Does anyone know why German universities are so slow to deploy IPv6? Almost none has their website reachable over IPv6 or IPv6 on their internal network.

Depends on the technical expertise of the staff, I guess.

My alma mater (FAU Erlangen, https://fau.de ) did have some internal and external IPv6 already back when addresses were still 6bone 3ffe::, 20 years ago. Don't know since when the main website has been IPv6-reachable, but it has definitely been over 10 years.

Re: IPv6 Deployment Status

#38
post #4

At this point I'm personally convinced that ipv6 is a failed technology. It used to be interesting to see the news about new ipv6 deployments, adoption ratings etc. Now I basically don't care.

It doesn't matter. IPv6 is happening, its way past the point of no return. Nobody is entertaining the idea of dropping ipv6 and doing something else. Any remaining problems that IPv6 has are more realistic to deal with within ipv6 than scrap the whole thing and start again from scratch.

Re: IPv6 Deployment Status

#39

Earlier quoted context omitted.

NAT is horrible.

Leaned on heavily to protect cheap IOT devices. Could you imagine the bot armies if every IOT device was NOT behind a NAT?

NAT is not a firewall. NAT is a 'hack' that some firewalls use. My university only used routable IP addresses, but due to the wonders of firewalls, you could not connect to the HP printers in the library over the internet. Even though it had a routable IP.

Re: IPv6 Deployment Status

#40

All we need is ONE major website to declare 24 Hour brown-out for IPv4 and put a message something like "Contact your ISP to upgrade your connection". Alas, publicly traded companies....

I often thought if Netflix started doing Live sports on IPv6 multicast, that might finally change things with all the home internet connections..
Post reply on HN