VMWare Fusion IPv6 NAT Black Holes
rachelbythebay.com
rachelbythebay.com
It seems plausible that their network stack wasn't up to the task of handling this so they sort of jury-rigged up this sort of odd connection forwarding.
That's the only thing that I can think of here as otherwise there's just no planet where this makes any sense. That said, NAT for IPv6 is a generally problematic concept and they probably were flying a bit blind on how to implement it since there's no real standard way to do this. IPv6 was really designed around the idea that every endpoint would have a unique, globally routable address.
http://blogs.vmware.com/teamfusion/2016/01/workaround-of-nat...
https://twitter.com/jdotk/status/691771635771244545
They haven't release any patches since... :(
http://arstechnica.com/information-technology/2016/01/vmware...
Personally I suspect that they're offshoring these products rather than killing them completely.
Also, it's worth noting that Workstation and Fusion will be EOL by March, 2017.
On a related note. It annoys me, in articles about VMware, when they mention that EMC owns 80% of VMware. Yes, that's true, BUT... EMC owns 97% of the voting stock. Once Dell finishes the acquisition, you might as well just call VMware a private company.
I'd like an alternative to VMWare Fusion but don't want VirtualBox.
Other challenge is Fusion allows me to transfer VMs to my home ESXi box pretty easily, so I'd lose that too by switching
Veertu is way less featureful than Fusion but the latency means it's INSANELY fast. Windows 10 installs in sub 5 mins, but more to the point it just doesn't suck due to lag like Fusion did. I actually test on Edge now.
And yet they are still sending me Fusion special offer emails. It feels dishonest is they really intend to EOL it in a year.
For more info see update3 on this post. http://planetvm.net/blog/?p=2952
Source: I was on the Workstation team when the layoff happened.
Not so great when all the systems you want to talk to are v6 only, and the v4 NAT address is just for legacy use.
It appears that they were trying to build an ad-hoc connection-forwarding faux-NAT for the guest's IPv6 connection to the host's, to approximately mirror the NAT they can do for IPv4.
IPv6 really doesn't want to be NATed, though, and they've done a poor approximation of it.
Multihoming, site renumbering, and a few other issues are areas where work still needs to be done. Prefix translation is a current workable answer to some of those problems.
And yeah, as mentioned elsewhere, bridging onto a wireless situation is even worse.
I get "logged in from a new IP address!" alerts with a service I use almost every time I log in, even though my IPv6 prefix hasn't changed. Deciding it's a completely new IP just because something changed in the last 64 bits is probably a bad idea in a v6 world.
Devices being multi-homed is intended to be standard practice.
My iPhone regularly has multiple IPv6 addresses, with different reachability characteristics for different addresses. There's an address used by my carrier for voice, there are addresses I locally administer, there are addresses from a stable prefix I use, addresses from dynamic prefixes provided by my upstreams, ...
The v6 world is a world where many devices have many addresses and addresses do not all have the same scope.
Application developers are going to need to get used to this new normal.
An application I manage has ~40% of users accessing it over IPv6, most of which would have a degraded experience if we didn't offer v6 connectivity.
IPv6 is here, it's here to stay, and applications are going to need to understand the new world they live in.
I've been trying a few different approaches to routing. Putting link-local addresses in routing tables has worked well in some deployments.
Debian & OS X use MAC based addresses in addition to their privacy addresses. https://www.danieldent.com/blog/remote-ipv6-device-fingerpri...
They are not marked as 'preferred' and won't be used by default. But they are still available for use if someone goes out of their way to do so.
(No idea if it works with VMware, which I regard as devilspawn)
But in any case, I was wondering if this had anything to do with happy eyeballs but did not hear any further input.
EDIT: Upon rereading, this is the followup post.
VMWare are no longer, in my view, a particularly innovative company.