Live data from Hacker News

The IPv6 Transition

potaroo.net

391–400 of 433 posts

Re: The IPv6 Transition

#391

Earlier quoted context omitted.

> so for anyone that "just browses the web" (which is overwhelming majority) there is virtually no difference/benefit? Our current patterns of internet behaviour are limited by IPv4, so almost by construction nobody does things that need IPv6. Few people made international journeys before deep water navigation; watched live streams before Twitch; or had pizza delivered at 4am before dominos.

Could you give examples? One, the most obvious, is actually having distributed net and serving content from your own machine and in the ancient times like 15 years ago Opera tried that by bundling sort of local http-server (?!, can't even remember the name of the project…) but it floped... I'm not sure that ipv4 was the issue or rather the fact that people don't usually have or want their machine work 24/7... for cal…

I don't see significant difference for most private people. I guess the median has three phones, a tablet and a tv box, there's not much scope to improve the network for that use case.

But IPv6 makes a difference for some other situations. If you operate a network with routers and such, it makes sense to have all connections to internal services use IPv6. Backup, file storage, databases, management interfaces, blah: Give everything its own IPv6 address, don't accept connections on IPv4, and allow IPv4 packets from 192.168/16 only to the outside world.

Re: The IPv6 Transition

#392
post #142

Earlier quoted context omitted.

NAT is mostly okay, but carrier grade NAT where you can't forward a port causes real problems. IPv4 exhaustion is a real problem, it's just not enough to motivate people much.

The main problem I had when I was on CGNAT was not so much port forwarding (annoying, but solvable), but with being banned from all sorts of stuff. The address is shared with so many people and one person did something stupid or malicious or whatnot. Sometimes you don't even know if you're banned or not. For better or worse, IP blocks are still very common. It's easy to complain about this, but there aren't really an…

Ah… that makes it sound as if we've reached a phase where IPv6 has no significant problems and saves a little bother compared to IPv4. Switch to v6 ⇒ escape false alarms from tools like fail2ban.

Re: The IPv6 Transition

#393

I have fully implemented IPv6 in my home network. I have even implemented an IPv6-Only network. It fully works, including accessing IPv4 only websites like github.com via DNS64 and NAT64 at my router. The only practically useful thing about my IPv6 enabled network is that I can run globally routable services on my lan, without NAT port mapping. Of course, only if the client is also IPv6. Other than this one use case,…

> internet really doesn't care about being completely peer-to-peer.

I think this is mostly the way it is because of all the NAT headaches that come with IPv4.

We regularly see the limitations of Dropbox/Google drive when we just want to share that large birthday video with our friends/family. Imagine them having a secure link to your device that you can revoke any time.

Same with all the home automation / iot devices / cctv cameras that have no excuse not to be local first/need you to install an ad infested app.

Re: The IPv6 Transition

#394
post #389
post #98

Earlier quoted context omitted.

These people are neither competent nor serious. In the real world, people who design and operate large networks are the very same people who staffed the working groups who designed IPv6. It's their design.

"IPv6 is great and easy to use, if you're one of the leading experts who designed it" This is not the kind of glowing endorsement you think it is, if you're expecting your technology to see widespread adoption

Half the US has already deployed it and 100% of the mobile carriers. I would say the detractors who continue to stomp their feet about not deploying IPv6 are holding a fake title of "Network Engineer". People need to grow up and do their job or get out.

Re: The IPv6 Transition

#395

All big German internet providers (DTAG, Telefonica, 1&1, Vodafone) are IPv6 Dual Stack or CGNAT'ed for many many years now. Same for all mobile providers. So everybody is using IPv6 in their home networks without problems.

Vodafone refused to enable dual stack on my DSL connection. I got to pick from either keeping dual stack with CGNAT or completely disabling IPv6 but get a reachable IPv4.

My mobile provider doesn't allow IPv6 connections.

So ironically, to be reachable from everywhere, I had to turn off IPv6.

Re: The IPv6 Transition

#396

For my entire life, the networking nerds have been shaming us for not using IPv6. Back when I had a NeoPet in middle school, IPv6 was was "just around the corner." I'm now raising my own children and still listening to the same IPv6 talking points. Every company I've ever worked for has completely disabled IPv6 on the corporate network. My own ISP still doesn't offer it. Disabling it is often the quickest fix for a v…

> Disabling it is often the quickest fix for a variety of networking issues. In a way, you disabling it now is the reason why others are disabling it later. A lot of IPv6 deployment issues are precisely caused by middleboxes/clients disabling or misconfiguring it.

Yes, and? Don't make excuses for shitty technology. The mental model of what the "future Internet" (aka the one we're using now) would look like is completely insane in IPv6.

Re: The IPv6 Transition

#397

Earlier quoted context omitted.

It could work like 4 socks requests wrapped in each other like onion. But LAN services wouldn't need to care about long addressing as they don't need to cross network boundary, while letting everything else use new approach, so you could use old stuff without changing anything and there would be no need for new ip6 drivers with new vulnerabilities that are yet to be fixed.

But no v4 devices support this "four socks requests wrapped like an onion" thing you're proposing, so how would they work with it?

Socks goes on application layer, hardware sees it as normal tcp/ip4.

Re: The IPv6 Transition

#398
post #51

Earlier quoted context omitted.

You said "government-mandated" - do you think your words matter? That doesn't sound like agreement. Agreement is how we have arrived at the imperfect solution we have now... Agreement between various technical and non-technical parties.

Conversely, blindly categorizing all government mandation as authoritarianism sounds like a highway to all kinds of logical fallacies! Is mandating a fair market (by e.g. punishing monopolies) authoritarian? A sensible person would answer no. Similarly, mandating an Internet Protocol that doesn't require centralization (you know, NAT) and renting an address from the Big Boys (AWS etc) sounds like a perfectly sensible…

A sentence written by a pedant that doesn't help communicate.

Followed by another sentence.

Ending with a quote that implies a worldview that the government should use violence without any balance "it's a status quo broken by an external force".

Re: The IPv6 Transition

#399

Earlier quoted context omitted.

It could work like 4 socks requests wrapped in each other like onion. But LAN services wouldn't need to care about long addressing as they don't need to cross network boundary, while letting everything else use new approach, so you could use old stuff without changing anything and there would be no need for new ip6 drivers with new vulnerabilities that are yet to be fixed.

There have been tunneling protocols and systems for IPv6 since nearly the beginning of IPv6. The ability to tunnel it hasn't solved all the "backwards compatibility" complaints for IPv6. Same for network address translation, both NAT46 and NAT64 standards have existed for a while now and that also hasn't solved the "backwards compatibility" complaints for IPv6.

Presumably NAT46 still requires most things like middle boxes to upgrade to ipv6, and also somehow needs to squeeze ipv6 addresses into ipv4 addresses, which is only a temporary solution at best.

If addressing is two layer, e.g. NAT is 1.1.1.1 and everything behind it is in 10.0.0.0/8 network (cloudflare could use this scheme while having only one top level address), then you can use existing socks support without any new hardware or software.

Re: The IPv6 Transition

#400

Earlier quoted context omitted.

There have been tunneling protocols and systems for IPv6 since nearly the beginning of IPv6. The ability to tunnel it hasn't solved all the "backwards compatibility" complaints for IPv6. Same for network address translation, both NAT46 and NAT64 standards have existed for a while now and that also hasn't solved the "backwards compatibility" complaints for IPv6.

Presumably NAT46 still requires most things like middle boxes to upgrade to ipv6, and also somehow needs to squeeze ipv6 addresses into ipv4 addresses, which is only a temporary solution at best. If addressing is two layer, e.g. NAT is 1.1.1.1 and everything behind it is in 10.0.0.0/8 network (cloudflare could use this scheme while having only one top level address), then you can use existing socks support without an…

My understanding is NAT46 is very nearly the same as NAT44 ("traditional NAT" between IPv4 and IPv4), using tricks like (but sometimes different from) SOCKS and UPnP and fake port numbers to accept incoming connections for one (or more) IPv4 addresses to pretend to be/delegate to some number of IPv6 consumers behind it. It doesn't solve general routing of any IPv6 address, just specific addresses routing via an IPv4 proxy.

To my understanding, the difference between NAT44 and NAT46 is really hard to spot in practice and somewhat "just" a distinction of whether or not the NAT in question thinks of its IPv6 subnet or IPv4 subnet as "primary". I've heard some major consumer-side routers quietly upgraded to NAT46 as "primary" because it does lend itself to better consumer experiences. Also I've heard some CGNAT (Carrier Grade NAT) is easier to build when considered as NAT46 than NAT44 (as awful as CGNAT is as a general thing).

NAT46 is absolutely a standard designed to be a temporary solution. It's just about the exact same ugly temporary solution as NAT44. (Or at least as NAT44 was supposed to be. The continued confusion of NAT44 as a security measure will probably keep NAT44 still in use long after its problem disappears and its temporary transition window has expired.)

(NAT64 is the interesting one that may not be as temporary as networks move to IPv6-only single stacks. Some cell carriers have already moved in that direction.)

Post reply on HN