Live data from Hacker News

I spent a week without IPv4 to understand IPv6 transition mechanisms

apalrd.net

221–230 of 511 posts

Re: I spent a week without IPv4 to understand IPv6 transition mechanisms

#221
post #40

Earlier quoted context omitted.

NAT and a Firewall are two different concepts. What's wrong with a firewall that blocks everything by default, yet all your devices have a public IP?

> NAT and a Firewall are two different concepts. They are, but in practice they are muddled together and I suspect people are going to create subnets with IPv6 in the name of security. In IPv4 NAT is used to make sure your laptop isn't exposed to random script kiddies trying to scan for vulnerable services behind your router. A fun exercise is to plug a RaspberryPi up directly to a public facing IP address and log ev…

>In IPv4 NAT is used to make sure your laptop isn't exposed to random script kiddies trying to scan for vulnerable services behind your router.

NAT does nothing for that. Those incoming connections are dropped on the WAN interface before NAT would even be involved. Which is why it works exactly the same way regardless of whether the destination IP for that traffic was IPv4 or IPv6.

Re: I spent a week without IPv4 to understand IPv6 transition mechanisms

#222
post #97

My experience with IPv6. I have option to enable full dual stack with my ISP. After doing this I noticed that YT/FB/Google were significantly faster, however my kids started to complaing that some games began to have connectivity issues. Minecraft have problems to start. On a number of sites load time was noticebly longer. Switching off IPv6 as a experiment on one of kids PC solved all issues. My conslusion is that i…

I have never fixed network problems by turning IPv6 on, but I have fixed them numerous times by turning it off.

Re: I spent a week without IPv4 to understand IPv6 transition mechanisms

#223
post #126

Earlier quoted context omitted.

Also I'm not going to expect my ISP to actually give me more than one address, so if I have multiple devices at home, I will need to do NAT. Heck, back in the day they used to set TTL to 1 so the packets weren't routable at all without mangling them via iptables. Maybe that will be harder now than 20 years ago since everything connects online...

ISPs are expected to delegate a /56 or /64 prefix to customers. Some are even delegating /48s. Mine delegates a /56. That should be enough for all your devices to randomly rotate IPs for a lifetime or a few without any NAT.

https://news.ycombinator.com/item?id=24999906

Shitty ISPs do exist, or at least they existed two years ago.

Re: I spent a week without IPv4 to understand IPv6 transition mechanisms

#224
post #185

>There seems to be a lack of drive (judging by forum posts) to enable IPv6 on internet services by admins, either because they don’t care to, or it’s more work to manage a public IPv4 and public IPv6 presence If you run a mailserver adding ipv6 support is far more risk to your domain's mailserver reputation than it is worth. And if you're just a human person and not a megacorp that new ipv6 address, even if it it doe…

Yeah I have zero motivation to deal with IPv6. I also have all my IPv4 addresses memorized, and IPv6 addresses are too long to remember with all the hex-double-colon nonsense. If they could have turned 1.2.3.4 into 1.2.3.4.5.6 I'd probably use it, but instead they opted for some scary stuff that looks like d0ff::eefa::0010::faff:::://::92::0 which I'd rather not look at. Product management fail. Anyhow, IPv4 still wo…

: separates groups of 4 while optionally :: abbreviates a bunch of 0's and leading 0's in groups are optional. The address can be longer, sure, but it's really near identical to dotted decimal beyond the lengths.

I wouldn't mind a simpler DNS server IP though seeing as it's one of the few locations you need to treat as an address regularly. Sprint/T-Mobile has 2600::, which is not only short but seemingly a phreaking reference, active so why can't something similar be active for DNS. I get not wanting 8888 or whatnot, those blocks aren't assigned and advertising random bits for vanity can be annoying, but there are plenty of short IPv6 addresses that could be in use for the most common DNS servers on the planet. Even I have my personal DNS server running on an XXXX:XXXX:: public IPv6 address!

Re: I spent a week without IPv4 to understand IPv6 transition mechanisms

#225

I have built a couple of dual stack Kubernetes clusters already and they work much better to be honest. Most of the problems are solved and especially for node-based-ranges it works really well. Even in ipv6 only mode calico will manage amazingly and so do my OpenWRT routers. HOWEVER, My ISP regularly messes up with its ipv6 routing (deutsche Telekom (so as big as it can get for me) and if that's not the problem, the…

I got so fed up with IPv6 being either straight up unavailable or being deployed in a botched fashion by residential ISPs in my area in the last 10+ years that I picked up an ASN and a /44 last year. I advertise it from a VM on Vultr in a datacenter close to home and the experience is just amazing.

I also got fed up with people discriminating against Hurricane Electric's tunnel broker (streaming services, etc) so now I just have my own tunnel broker. It's really great to have my own addresses, use them in my kubernetes clusters (via calico and cilium) and have my homelab directly advertised to the internet, knowing I will never need to re-number.

Networking is a helluva drug

Re: I spent a week without IPv4 to understand IPv6 transition mechanisms

#227
post #191

Earlier quoted context omitted.

And that's the problem! Who can memorize all that? I mean look, a few days ago Comcast had an outage and I plugged my phone into my USB port to tether it for internet access. It hijacked my DNS entirely, and I couldn't turn on my damn lights or change my thermostat which were on my LAN. Thankfully I know their LAN IPv4 addresses from memory, 10.10.10.x and 10.10.10.y, and I was able to issue CURL commands directly to…

Seems like a complicated solution to a problem that does not exist. You cannot turn on lights at all without a working network? If your router crashes your whole house is stuck? Seems like there is a bigger issue than the IPv6 protocol

[deleted]

Re: I spent a week without IPv4 to understand IPv6 transition mechanisms

#228
"although software support is virtually a requirement these days"

Who's fault is this again?

-------------

"- IPv6 is absolutely ready for prime-time and has been for awhile

BUT

"- About half of the internet sites I rely on support IPv6 natively, so there needs to be more pressure on site admins and CDNs to support IPv6 natively"

That is a contradiction.

-----------

"There seems to be a lack of drive (judging by forum posts) to enable IPv6 on internet services by admins, either because they don’t care to, or it’s more work to manage a public IPv4 and public IPv6 presence"

Again, who's fault is it that its so hard? What is the payoff for the extra work?

-----------

- Networks should be designed IPv6-first instead of IPv4-first, and this design approach largely solves most of the major issues

K thanx, but that's not the way virtually every company works. Mayyyyybe a startup? This is unrealistic.

-----------

"Other operating systems are bit of hit or miss"

so... IPV6 is NOT NOT NOT ready for prime time, is that what you are saying?

-----------

What dream world are the ipv6 people living in?

I love this. Who should be implementing ipv6 stacks in OS's? Probably ipv6 people, but ... where are they again? The amount of blame is crazy.

A protocol switchover of this magnitude is about outreach and assistance. The ipv6 crowd has NEVER displayed that, just arrogance, dismissal, and waited for things to get "so bad" in ipv4 that it transferred.

Which is why ipv6 people HATE HATE HATE NAT. It has delayed their grand moment by decades.

...

In an ideal world, the ip++ protocol would have been easier, not harder. BLog posts wouldn't be victim blaming, throwing around NAT64, 464XLAT, DNS64

DNS64 kills me. WHy is there a totally different service for ipv6? Isn't DNS just a key-value store? People put all types of crap into DNS, including, I believe, ipv6 addresses.

Why isn't there a DNS record type that basically lists both an ipv4 and ipv6 for a name, along with negotiation information? Might that make transition a lot easier? Maybe it does, but it isn't in this article.

Just ... all the same problematic attitudes, no progress on issues, my way or highway, and denial.

Re: I spent a week without IPv4 to understand IPv6 transition mechanisms

#229
post #64

I've given a try to IPv6 in a company with few tens on servers in a 2 DCs, an office + additional location, 3 ISPs in total. For me the real challenge is not just different way to write an IP address or doing NAT. The challenge is that IPv6 changes a lot of unexpected things: - Our ISPs support IPv6 but routing quality is way worse than IPv4 including occasional inability to connect to some networks or greater latenc…

> SLAAC is cool but doesn't provide DNS configuration. (there is RFC8106 but is it supported by all OSes?)

For the most part, yes it's supported by major OSes. (ND RDNSS) https://en.wikipedia.org/wiki/Comparison_of_IPv6_support_in_...

Re: I spent a week without IPv4 to understand IPv6 transition mechanisms

#230
post #97

My experience with IPv6. I have option to enable full dual stack with my ISP. After doing this I noticed that YT/FB/Google were significantly faster, however my kids started to complaing that some games began to have connectivity issues. Minecraft have problems to start. On a number of sites load time was noticebly longer. Switching off IPv6 as a experiment on one of kids PC solved all issues. My conslusion is that i…

I don't think this anecdote proves anything.

It doesn't say a lot. What says more is how often you seek home networking advice and one of the first troubleshooting steps is to disable ipv6 (though restarting the router is probably first).
Post reply on HN