IPv6 Wall of Shame
ipv6wallofshame.com
ipv6wallofshame.com
This addon does nothing much for me except informing me that I use IPv6.
http://blog.apnic.net/2016/09/15/quiet-ipv4-internet/
I found the "Sage" certification from he.net/tunnelbroker entertaining. You basically setup a IPv6 capable mini-ISP. Also have a look at these nifty Browser add-ons that tell you which part of website is served via IPv4/v6:
Chrome: https://chrome.google.com/webstore/detail/ipvfoo/ecanpcehffn...
Firefox: https://addons.mozilla.org/de/firefox/addon/ipvfox/
Once you started to live without NATs and have endless[1] amount of addresses, you start banging your head against the table when you encounter so called 'future' technologies [2] that on their very core only support IPv4 and rely on NATs and ugly port-bridges etc.
[1] for all practical purposes
[2] e.g. docker
I wanted to know what actions I could take to get IPv6. I knew that a competitor offered IPv6 (a friend just switched) and having IPv6 access would make it much easier to administer my servers w/o using a tunnel.
- The first tier support told me my leased modem did support IPv6, but I'd need to buy a "business class" plan. This was a flat out lie, and in fact I "have" a business class plan at work. (Hint: it's the exact same modem, and we don't get an IPv6 allocation at the office.)
- The second tier told me IPv6 wasn't available in my area, full stop.
- The third tier [correctly] told me my modem doesn't support IPv6, and that a new one from an "approved list" would. (Though when I inquired about a specific model _from that list_ she told me it wasn't supported.)
---
In the end I bought a modem from that list (the exact one she told me wouldn't work, hilariously enough) and IPv6 just started working out of the box.
I really don't understand what the point of leasing a modem from a cableco is. I was operating under the assumption that they'd replace it when it was obsolete or in disrepair, but apparently "has IPv4 access" doesn't count as obsolete just yet.
So if you want IPv6 access: a good place to start would be pestering your ISP and probably ditching your ISP provided gateway. As an added bonus I now save $10/mo on my bill.
In the future, people might not be able to use IPv4 at all, or all the time, and then you need your website to be available via both IPv4 and IPv6.
We have a /23 of nice IP addresses. There's no ugly NAT or private addressing at our end, so that's not an argument for us to add IPv6 support. They're part of a university's /15 assignment, so it's not realistic to give them up or sell them.
We'll get IPv6 support eventually, I'd guess in 2018-19 or so, but I'm curious if the lack of support causes problems for users in Africa in the mean time.
If a user types in a domain, eventually a root dns responds with an ipv4 A record and resolves to a server the site has configured. Am I missing something?
By supplying v6 you ensure anyone in the world can access it regardless of which IP protocol is deployed by your carrier and how they are or aren't translating from one to the other.
Sounds like this is mostly the case, but it has some issues and any new ISP on v6 would have a hard time because a lot of the big sites would be unreachable.
Of course, this becomes political soon enough. As new countries see mass adoption of the interwebs and find out that they have massively smaller allocations of IP addresses than the existing countries they might feel annoyed and do something about it. Tempers flare, shoes are thrown, everyone gets sulky and unhappy.
All this could be avoided if we just flipped a few switches, wrote some code, and all moved to IPv6. It's such an easy, small thing to do. Why not just do that and not irritate the living buggery out of everyone?
It's about being a good netizen.
So - and this is a genuine question - what is the issue right now with, for example, the BBC not yet having an IPv6 address, as long as they have plans in the pipeline for when v6-only clients need to access them?
Because of the catch-22 problem. The BBC sees that no consumers use IPv6 exclusively, and don't bother supporting IPv6 "yet". ISPs see that "no" content providers support IPv6 at all, and then claim that it doesn't provide any real benefit over CGNAT bullshit.
And so we'll be stuck in this mess for another century at least...
If you make your server available on IPv6, too, then I can use my non-shared IPv6 address to communicate with you which means that the packets don't need to undergo NAT which means a less horrible, faster connection without messy port forwarding requirements.
Let's take an example I got from a Cisco presentation, when NAT is used. A map web application may have to download a lot of tiles quickly. It's best done using several parallel TCP connections. Each of those connections must be tracked by the NAT box. At scale and for peak time load, this can become a nightmare and some connections may be dropped --- leading to retries and delays in completing the web page display. With IPv6 this issue doesn't exist.
Supporting IPv6 can help providing a better mobile user experience in this case, and is why a lot of the big companies do support IPv6 already. Bypassing CGNAT helps with latency in a situation as in the above example.
Running iptables firewall on a server. Checked what's my ip address at a customer site. Saw an IPv6 address. Ok, no problem add it to the iptables rules. Oh yeah that doesn't work. Duh.
So I guess I have to learn to use ip6tables now...
https://nickcraver.com/blog/2016/02/17/stack-overflow-the-ar...
Also apple.com does support IPv6.
(ditto s/apple/microsoft/ - I just picked the example quickest to type)
The first shouldn't be required since you would have a public IPv6 address and the second is just a fact of life that we'll have to pay extra if you want a IPv4 address in future.
Quite true. Most hosting companies charge around $1/mo. for a dedicated IPv4. (Naturally, not for shared plans but for VPS/dedicated boxes etc.)
All that needs to be done is add the appropriate firewall rules (probably on the router and computer) to allow traffic for that port and it'll be accessible from the outside over IPv6.
(This problem currently affects the “ntp.org” domain – an IPv6-only host can not resolve the name “pool.ntp.org” – since at least two years ago. I did report it at the time.)
What I’m saying is that these kinds of problems are not reflected in the site, which only reports if a site has an IPv6 DNS record.
Verizon is the big one.
That they use IPv6 for their wireless division just makes it more ridiculous that they don't for their wired division - they clearly have the institutional knowledge to make it work.
So it is better to see it as a completely different project. The core routing IPv6 is the same, but that tends to be the easy part.
I don't see how this has anything to do with wired vs wireless.
On wired, just about every business account is assumed to have a public address and often a static one. In addition, a lot of gaming doesn't work behind carrier grade NAT.
In the mobile world, this expectation of public (or even static) IPv4 addresses is almost completely absent.
But that episode is (almost to the day) four years old, and most of the sites mentioned back then still are not reachable via IPv6... It is a little sad.
Heck, if all the sites on that page where green, mobile Internet would suddenly be a lot better since the carrier NAT boxes would have to deal with ~90% less traffic.
The big issue here are AWS/azure dragging their heels (and I assume some CDNs, too)
This is like saying DEFLATE doesn't work because someone committed a bug to zlib.
Shame on you.
> "Everyone who's seeing this error on their system is running a package of the Linux kernel on their distribution that's far too old and lacks the fixes for this particular problem."