Live data from Hacker News

The IPv6 Transition

potaroo.net

241–250 of 433 posts

Re: The IPv6 Transition

#241

I'm pretty naive about this stuff, but IMO IPv6 is a lot more empowering than v4. You aren't dependent on some owner of v4 addresses for access, you don't need to manage--and aren't forced into--NAT, and you (probably) get to use all of your ports. My conspiracy theories about why v6 hasn't taken off are: people make money off v4 leases, and email spam blacklists become pretty useless in v6. But again, very naive her…

The more likely reality is that we have a lot of v4-only hw in place with lifespan of 20+ years. Those devices won't go away.

Heck, I work on embedded, and having a dual-stack system is just a PITA to deal with. If v6 would have been fully retro-compatible this wouldn't have been something to think about, but you can't drop v4 and there's no future in sight where v6 will be the only choice (we'll have dual-stack for a looooong time), so we just push the problem up the chain.

There are plenty of systems being developed _now_ which are still v4 only as a result.

Re: The IPv6 Transition

#242

Earlier quoted context omitted.

Why do dynamic address allocations matter? Most IPv4 consumer WAN addresses are also dynamic. I’m asking, because I’m an advocate of having your gateway advertise a separate, stable ULA /64 in conjunction with the globally-routable dynamic /64. This gives you a stable set of addressable LAN IPs, and you can usually ignore the dynamic globally routable IPs. Granted this won’t work for everyone, but if dynamic global a…

It matters, because when the prefix changes, it changes IP addresses of every single device in your network. As you wrote, internally, you can use ULA. But you cannot open access from outside, because your firewall rules will become invalid with prefix change. With classic IPv4 NAT, your internal addresses don't change, so your port forwarding works, even if the WAN address changes. Together, with a single /64 -- whi…

I don’t know what router you use, but openwrt lets you set firewall rules that only match the last 64 bits. This should solve your problem, provided you configure your router to hand out static IPv6 leases to devices.

Re: The IPv6 Transition

#243

Earlier quoted context omitted.

I hadn’t put that quite together. I wonder how many people would value IPv6 if they knew it meant less CAPTCHAs.

I'd imagine that to be short lived. IPv6 having such a huge address spaces means the IP reputations are even more worthless than IPv4 so eventually the bots would use it too, and if the ratio of bots to real users become too high sites may refuse IPv6 traffic altogether.

You can block ipv6 /64 subnets just like you can block IPv4 /32 IPs.

Re: The IPv6 Transition

#244

I have fully implemented IPv6 in my home network. I have even implemented an IPv6-Only network. It fully works, including accessing IPv4 only websites like github.com via DNS64 and NAT64 at my router. The only practically useful thing about my IPv6 enabled network is that I can run globally routable services on my lan, without NAT port mapping. Of course, only if the client is also IPv6. Other than this one use case,…

> I have fully implemented IPv6 in my home network.

I could have written this message in 1999. That's 25 years ago (as you alluded to). That's a long time to hold your breath.

Re: The IPv6 Transition

#245

I have fully implemented IPv6 in my home network. I have even implemented an IPv6-Only network. It fully works, including accessing IPv4 only websites like github.com via DNS64 and NAT64 at my router. The only practically useful thing about my IPv6 enabled network is that I can run globally routable services on my lan, without NAT port mapping. Of course, only if the client is also IPv6. Other than this one use case,…

Can it be that IPv4 price now leveled off because big players are getting ready to switch to IPv6 any time and not buying up anything that is available?

If GooG/FB/Amazon force IPv6 how long will it take for ISPs to switch? I think in one week where some people cannot reach GooG/FB and any ISP that was dragging his feet has implemented IPv6 by the end of the week.

I expect IPv6 adoption will blow up any time now as past performance is not indication of future changes ;) because there is much more required on the server side than it was ever before. ISP and home use could live with NAT but servers not really even if you can handle bunch of services on a single IP address, there is just limited traffic you can squeeze onto a single server.

Re: The IPv6 Transition

#246
post #7

I think the article's diagnosis is spot on. The urgency of IPv6 adoption was predicated on the assumption that every connected device, both server and client, needs a unique and stable IP address. Back when IPv6 was first discussed, you couldn't even host two HTTPS sites on the same IP/port combination! That was such a colossal waste of IP addresses. Another thing that changed on the server side was that, thanks to A…

> Another thing that changed on the server side was that, thanks to AWS and the like, it became trivial to set up a massive private network. Nowadays you can have a cluster of thousands of virtual machines that communicate with one another entirely within a VPC. Only machines that need to communicate with external entities get a public IPv4 address. This kind of setup not only frees up a /20, but also has the benefit…

IPv6 had this cool idea that each subscriber would get a /64, and devices within the subscriber's network would be assigned /128s with the last 64 bits matching their MAC addresses.

Except it turns out that most organizations see no need to give internal devices globally routable IP addresses, much less expose their MAC addresses. If anything, it's a vulnerability, not a feature.

On the other hand, going too far along with your idea would look like a dystopian future where everyone is corralled into one corporate walled garden or another. So it's understandable that there's a strong gut reaction against it. Fortunately, there are enough IPv4 addresses to support both corporate walled gardens and a reasonable number of independent operators.

Re: The IPv6 Transition

#247
> The rather bizarre economics of financing 3G infrastructure meant that dual stack infrastructure in a 3G platform was impractical, so IPv4 was used to support the first wave of mobile services.

What's he referring to here?

Re: The IPv6 Transition

#248

I have fully implemented IPv6 in my home network. I have even implemented an IPv6-Only network. It fully works, including accessing IPv4 only websites like github.com via DNS64 and NAT64 at my router. The only practically useful thing about my IPv6 enabled network is that I can run globally routable services on my lan, without NAT port mapping. Of course, only if the client is also IPv6. Other than this one use case,…

NAT is mostly okay, but carrier grade NAT where you can't forward a port causes real problems. IPv4 exhaustion is a real problem, it's just not enough to motivate people much.

It is enough for Amazon/Google/FB/Netflix - they start to choke on IPv4 and they also don't want to pay up insane amounts for holding IPv4 ranges. When they switch to IPv6 they have more cheaper addressing. Once they force it down by making faster services via IPv6 all the ISPs will follow right away because everyone will want to have their Netflix/YT streams load faster.

Re: The IPv6 Transition

#249
post #148
post #20

China's IPv6 transition is 74% complete.[1] Conversion to IPv6 was specifically called out in China's 14th Five Year Plan, which gives the goal high visibility within the government and the Party. Conversion is quite far along. The current goal is everything IPv6 enabled by 2025, IPv4 turns off in 2030. 99% of the top 100 mobile applications in China are on IPv6. China Mobile's backbone is now IPv6 only. [1] https://…

The IPv6 transition is a side effect of China building their own internal "internet" from the ground up that will not be connected to what we think of as the internet. "Turning off IPv4" is code for shutting off the DFZ and users only being able to reach other networks within the country. We should absolutely not be pointing to this as a success or a model for other countries.

What? You can still connect to worldwide IPv6 endpoints in China -- some endpoints are censored, just the same as how the IPv4 firewall is accomplished.

You are describing as if the IPv6 network within China is completely blocked off from the wider network. It's not.

Re: The IPv6 Transition

#250
post #15

Earlier quoted context omitted.

NAT is mostly okay, but carrier grade NAT where you can't forward a port causes real problems. IPv4 exhaustion is a real problem, it's just not enough to motivate people much.

Have you tried using PCP to forward the port? I was under the (maybe-incorrect, and if so I would really like to learn) impression that most major CG-NAT setups supported it.

PCP is not widely deployed in South East Asia at the very least. Relying on it is not feasible.
Post reply on HN