Earlier quoted context omitted.
Please don't put words in my mouth. I did not say "Because pfSense, does really bad things." How pfSense works is fairly reasonable if every IPv6 deployment had been as the original designers intended, ie you have a static prefix. It's just that the way IPv6 ended up getting deployed in practice was often not aligned with that original vision. And that has been a large source of IPv6 frustration.
There's a few things here that are a bit iffy tbh! I can't see why an ISP is dynamically changing the IPv6 addressing for a client, but if that's what is going on, then v6 NPT is your friend (RFC6296 - https://datatracker.ietf.org/doc/html/rfc6296 ). But pfsense's behaviour is a bit iffy too, unless when you say 'public IP', you mean the IPv6 address being used on the pfsense facing the clients? (I'm assuming it's us…
IPv6 is the only way forward
191–200 of 350 posts
Re: IPv6 is the only way forward
#192Earlier quoted context omitted.
I dismiss IPv6 because my ISP doesn't support it.
I dismiss ISPs that don't support IPv6.
Re: IPv6 is the only way forward
#193Reading the comments, it looks like some people dismiss IPv6 just because they need to sit down and learn a couple of new things.
Yeah, it's always the same with IPv6 discussions. The main points being: 1. IPv6 addresses are too long to remember 2. IPv6 doesn't need NAT and people are uncomfortable with their devices having a public address as they see NAT as an additional layer of security
Re: IPv6 is the only way forward
#194Earlier quoted context omitted.
This is without even getting into learning the new (old?) paradigm of "exposing" all addresses to the whole internet. I realize "NAT" is not equivalent to "firewall", but placing them at the same boundary made things simple to understand conceptually. I for one never had trouble opening/forwarding ports (and liked the control it provided over what goes in and out, especially in the days before it all just became HTTP…
NAT also solves the dynamic address issue. With GUA I need to deal with both dynamic prefix and randomised suffix that can be changed by seemingly unrelated things when opening ports to the internet.
Regarding firewall policies:
just because most network OS are plain dumb, does not implies that's the fault of IPv6.
A zone based firewall solves that already. And for instance OpenWrt fw4 can make rules for suffixes in a zone too.
Re: IPv6 is the only way forward
#195Earlier quoted context omitted.
Because IPv4 is logical and makes sense. First thing which IPv6 came up with? No NATs everything will have a public address. It turned out that this was hare brained idea so let's just cover it up with firewall. However misconfigured firewall means that everything is open... IPv6 has been designed by people who were unable to think further than what is going to be tomorrow for a lunch.
Are you really complaining about the fact that we need to deploy firewalls?
Re: IPv6 is the only way forward
#196Earlier quoted context omitted.
Because IPv4 is logical and makes sense. First thing which IPv6 came up with? No NATs everything will have a public address. It turned out that this was hare brained idea so let's just cover it up with firewall. However misconfigured firewall means that everything is open... IPv6 has been designed by people who were unable to think further than what is going to be tomorrow for a lunch.
IPv4 came out in 1982 and was designed for every device to have a unique public address. Protocols like FTP were designed to literally pass an IP address to connect directly to. As addresses started running out, the NAT RFC was published in 1994 and described NAT as a "short-term solution". NAT was never meant to be an integral part of IPv4. https://www.rfc-editor.org/rfc/rfc1631 NAT broke a ton of things which requi…
Re: IPv6 is the only way forward
#197Earlier quoted context omitted.
Because IPv4 is logical and makes sense. First thing which IPv6 came up with? No NATs everything will have a public address. It turned out that this was hare brained idea so let's just cover it up with firewall. However misconfigured firewall means that everything is open... IPv6 has been designed by people who were unable to think further than what is going to be tomorrow for a lunch.
Isn't that the first thing that IPv4 came up with as well? One publicly routable address per device that wants to access the Internet (or the network of universities or military installations or whichever network you were on pre-Internet).
Re: IPv6 is the only way forward
#198Earlier quoted context omitted.
I dismiss ISPs that don't support IPv6.
I'm not signing up for a new contract with a different company to get the same speeds at higher price and IPv6 that is pretty much useless as many major websites don't even work with it. It will take at least another 15 years before I will consider using IPv6 at home.
I can't take seriously the claim that someone would literally refuse to move into an apartment purely on the basis of not having IPv6 support. Bad internet in general? Sure, that's plausible; I work from home, and like I said, the outages were annoying, and if there were no decent speed options my (now) wife and I might have ruled it out? But literally just the lack of IPv6? That's an absurd reason to pick another place to live entirely.
Re: IPv6 is the only way forward
#199Earlier quoted context omitted.
I'm not signing up for a new contract with a different company to get the same speeds at higher price and IPv6 that is pretty much useless as many major websites don't even work with it. It will take at least another 15 years before I will consider using IPv6 at home.
Not only that, but not everyone will even have any other choices. The last apartment I was in literally only had one ISP option; I literally would check every six months or so with other ISPs that were in the area because of the fairly frequent outages, and every time they all said that they couldn't offer me service at my address. (This didn't stop them from filling my mailbox with spam all the time though of course…
Re: IPv6 is the only way forward
#200Earlier quoted context omitted.
Not only that, but not everyone will even have any other choices. The last apartment I was in literally only had one ISP option; I literally would check every six months or so with other ISPs that were in the area because of the fairly frequent outages, and every time they all said that they couldn't offer me service at my address. (This didn't stop them from filling my mailbox with spam all the time though of course…
any idea why no one else could service the building? Ive usually had option of verizon or optimum when ive rented, though my experience has been queens and long island