Dealing with IPv6 fragmentation in the DNS
blog.apnic.net
Dealing with IPv6 fragmentation in the DNS
1–10 of 45 posts
Re: Dealing with IPv6 fragmentation in the DNS
#2Sad to see even a NIC letting itself be MITMed by Cloudflare :(
Re: Dealing with IPv6 fragmentation in the DNS
#3Re: Dealing with IPv6 fragmentation in the DNS
#4Maybe we should bow to the inevitable and recognise that IPv6 is an unfixable problem.
Re: Dealing with IPv6 fragmentation in the DNS
#5Maybe we should bow to the inevitable and recognise that IPv6 is an unfixable problem.
if it's unfixable, why is 40% of our in-office internet traffic running over IPv6? Why is 100% of our LAN traffic over IPv6? Why is 30% of the traffic to our sites running over IPv6?
http://icmpcheckv6.popcount.org
http://icmpcheck.popcount.org (IPv4 version)
via: https://blog.cloudflare.com/ip-fragmentation-is-broken/
Re: Dealing with IPv6 fragmentation in the DNS
#6Earlier quoted context omitted.
if it's unfixable, why is 40% of our in-office internet traffic running over IPv6? Why is 100% of our LAN traffic over IPv6? Why is 30% of the traffic to our sites running over IPv6?
The article suggests "Fragmentation in IPv6 is unfixable", not ipv6 itself. Try running this to see if fragments get delivered to you: http://icmpcheckv6.popcount.org http://icmpcheck.popcount.org (IPv4 version) via: https://blog.cloudflare.com/ip-fragmentation-is-broken/
Re: Dealing with IPv6 fragmentation in the DNS
#7Earlier quoted context omitted.
if it's unfixable, why is 40% of our in-office internet traffic running over IPv6? Why is 100% of our LAN traffic over IPv6? Why is 30% of the traffic to our sites running over IPv6?
The article suggests "Fragmentation in IPv6 is unfixable", not ipv6 itself. Try running this to see if fragments get delivered to you: http://icmpcheckv6.popcount.org http://icmpcheck.popcount.org (IPv4 version) via: https://blog.cloudflare.com/ip-fragmentation-is-broken/
Re: Dealing with IPv6 fragmentation in the DNS
#8If it is so much anathema to their nature then maybe they shouldn't insist on violating network layers?
Re: Dealing with IPv6 fragmentation in the DNS
#9This sounds like it would force a return to Store-And-Forward[1], where the switch waits for the entire frame to load into memory, before forwarding to its next hop. Waiting these few milliseconds doesn't sound bad, until you consider that's added to each packet, reducing (e.g.) application performance.
Re: Dealing with IPv6 fragmentation in the DNS
#10How about we just let the people who configure these filters solve their own problems?