MIT is just moving to IPv6.
Actually... MIT forcing an entire generation of future engineers to deal with IPv6... That will literally push innovation.
MIT is just moving to IPv6.
Actually... MIT forcing an entire generation of future engineers to deal with IPv6... That will literally push innovation.
The "just" is incorrect. There are four bullets on the slide: DHCP, IPV6, private IPV4/NAT, and firewall. From the diagram it looks to me like even if you move to IPV6 (which, as others have noted, MIT has not yet rolled out, so at this point you can't), you will still be behind the firewall, so setting up a service visible to the Internet will still be more difficult than it used to be.
MIT was always going to be the last place on earth to go total IPv6
I totally understand the need for a campus-wide firewall. The MIT network is a juicy target for botnets, and individual students are not good enough at running security on their own computers. The old approach to IP assignment was that you needed to get your IP approved and made routable by IS&T anyway, and if they detected botnet activity on your computer, they'd manually intervene and make it unroutable again. That sounds like a lot of work.
If computers end up with firewalled but publicly routable IPv6 addresses, that sounds perfect.
If they detect bad activity, they blacklist your MAC address so you can't connect. This is no different under the new scheme, and has nothing to do with NAT.
But I have my doubts. http://pilot2021.com/index.html
Forcing people to use anything is never a good way to promote innovation.
I went to MIT for my undergrad and doctoral studies. One of the main reasons I chose MIT over other schools was the ease of availability of static IP addresses, unlimited symmetric gigabit bandwidth, no port restrictions, and other things. I even mentioned this in my undergrad application essay. I built a lot of things with it and learned a lot in my time there. I probably learned more outside of classes than in classes, and I think that's one of the distinguishing aspects of MIT culture.
It probably is firewalling all incoming IPv6 connections (?). The Google Wifi app has no settings about this. Googling and stackoverflowing for 10 minutes didn't find a solution. That's when I give up.
Sorry Google and the IPv6 community but I have more important things I need to be working on than dealing with this BS that never works the first time. Back to IPv4 and port forwards, which is working fine for me right now, and will let me get back to my work. :-/
Of course it is. That's how innovation happens. They are focused on overcoming a constraint of the system they operate within. In this case, it will be to get around the limitations of the private IPv4 network, or to make the upcoming IPv6 network easier and more appealing to use.
Most innovations are to overcome some sort of limitation, whether that is with a man-made system or just the laws of nature as we currently understand them. Unbounded innovation hardly ever occurs and usually results in some shitty mobile game.
Now that's not to say MIT IS&T isn't behaving extraordinarily shitty here. But this won't stifle innovation, just refocus it. Whether that's towards a more worthy goal is certainly up for debate.
What if I'm a biology expert and want to run a server to demo something cool? I should be spending my time doing innovation in biology.
What if I'm a deep learning enthusiast and came up with something cool to demo? I should be spending my time hacking at that.
What if I'm a physics student and want to start a blog?
The majority of MIT students are awesome innovators, but most are not innovators in TCP/IP. Forcing a bunch of people who are not networking specialists and sysadmins to deal with the lack of IPv6 support in the rest of the world is not going to promote innovation where it needs to be.
NAT is technological friction. Telling people that "they should not do something" is also friction.
What about even just learning to write apps in your own time? I built dozens of demo websites while I was a student there. A few were slashdotted. Having IPv4 addresses and access to bandwidth from my bedroom was a massive blessing.
The problem isn't configuring IPv6. The problem is without IPv4 you cannot easily make a server that is guaranteed accessible from anywhere in the world, by anybody. That's not a problem that most MIT students are in a position to solve or innovate in a short time. At least not without spending money for an AWS instance that frankly most undergrads don't have the money for.
Innovating in making an HTML5 app to demo your cool bioinformatics project on the other hand is a weekend hackathon deal.
And servers are basically free at MIT. You can just pick up and assemble them up off of reuse when labs throw away various parts. Plug them into your gigabit ethernet socket in your bedroom, get an IPv4 address, and you're up and running in less than an hour.
You're the one who said people should be spending their time doing innovation in biology, hacking on deep learning, and starting a blog, rather than learning how to configure and deal with networking.
If anyone wants to do those things, they can do them now and not have to worry about installing and configuring servers and dealing with IP networking. Or they can work on innovating in networking.
The fact is, however, that no one is going to say "if my server wasn't IPv6 only, then people would read my blog". They'll most likely be saying that because there's a lot of other content to consume on the Internet, and attention is limited. And if that is the case, they can get a $5 a month digital ocean instance, or one from any number of other providers, accessible over IPv4 and IPv6, and serve both protocols to entire Internet.
Also, chances are, the audience for a physics student's blog is most likely at some university, which has a good chance of having a working IPv6 stack; especially now that MIT is going wholehog on IPv6.
If I come up with a super-awesome computer vision algorithm and want to run a server in my dorm room to demo it, being forced to use IPv6-only when the school has enough IPv4 addresses is a stupid annoyance and will only reduce the number of people that can reach the website. Running on AWS or other IaaS service isn't an option for many students without much cash.
(I'm busy and don't have time to deal with this BS. I just need internet access that works.)
Also, what is this whole "Comcast did not play nice with them" trope? I've dealt with Comcast many times, and used Asus, TP-Link, Cisco (the DPC3010 modems are my favorite) and others with them without issue. They aren't even a factor in your internal network and whether or not IPv4 or IPv6 works in it...
At my startup's house:
- Using the Comcast default combined modem+router works.
- Using the Google Wifi AP with a DPC3010 resulted in the DPC3010 being bricked upon connecting to the cable line. This is after the DPC3010 was working fine at my home. That DPC3010 no longer works, even at home, and only gets a power light upon startup.
- Using the Google Wifi AP with a TP-Link modem works flawlessly. No IPv6 though.
- 3 other routers that work at home do not work at my startup's house with the TP-Link modem. Asus RT router gets a fake 10. address from Comcast, Xiaomi router stops responding after several hours, Cisco router gets no DHCP lease whatsoever. All three work at home, all flawlessly.
Comcast is unwilling to debug, saying that unless I use their official combined modem+router they will not provide support.
Two words: seat belts. The auto industry fought this tooth and nail, as did parts of the general public. But once this painful transition was accomplished, it resulted in a big improvement in automotive safety.
Other examples include EPA regulations that forced out the use of hazardous chemicals and processes. This, in turn, also produced a notable series of entirely improved processes: better for the environment, and often cheaper costs and/or better end results (although not universally, to be sure). The potential for innovation had been present, but these mature industries had to be forced into innovation. The very concept that R&D might improve their bottom line as well as their externalized costs was practically foreign.
You're arguing against a straw man. This is about the promotion of innovation. Yes, seat belts were innovative, and left to their own course were going nowhere. Some innovations face adoption challenges that go beyond the mere "meh" of "non-consumption". They are major social battles, requiring large and multi-faceted campaigns to succeed and overcome social inertia. E.g. for seat belts: regulations on manufacturing, laws and law enforcement campaigns, public education and marketing, etc.
They actually rolled IPv6 support out with their latest firmware.
I'm at sea at the moment, so I can only find the play store note: https://play.google.com/store/apps/details?id=com.google.and...
"WHAT'S NEW
IPv6: Enable IPv6 on your Google Wifi."
Google is one of the worst offenders when it comes to dragging their butt on IPv6. Their cloud offerings have zero support, and some of their default Linux cloud images ship with IPv6 disabled in the kernel so that even if you run network virtualization software you don't get it. Much of their front-facing stuff supports it, but users can't actually use it for anything.
Microsoft comes next. Azure has no IPv6 to speak of.
Amazon is finally rolling it out. "Second tier" VPSes like Digital Ocean, Linode, and Vultr have had it for aeons.
Security via network segmentation. IMO, NAT gateway is good place to lock down and put in network security appliance to track/block all the unwanted connections.
NAT is terrible from a network engineering perspective, it was mostly a patchwork to deal with the rapid expansion of the internet and the shortage of IPv4 space. IPv6 brings a lot of cool technology to the table in, like MTU path discovery[2], header extensions[3] and proper anycast[4]. It also makes dealing with subnets and network segments a lot more sane and scalable.
[1] https://en.wikipedia.org/wiki/Hole_punching_(networking) [2] https://tools.ietf.org/html/rfc1981 [3] https://www.cisco.com/en/US/technologies/tk648/tk872/technol... [4] https://en.wikipedia.org/wiki/Anycast
My guess is that IPv6 is the ISDN of the 21st century... an intermediate step between two networking paradigms, one being IPv4 and the other being something we haven't seen yet. IPv6 will appeal to specialists but will never, by itself, see wide adoption. The fact is that NAT works for 99.99% of users, and works very well.
NAT is very useful to the network engineer. NAT lets you turn one network into a different one on a simple one-to-one translations basis.
However NAP got mixed up with masquerading to the point where when someone says NAT they assume you also mean masquerading when in fact the two are different concepts. NAT when you are doing a many-to-one translations is a disaster in many ways, but it works just well enough (and face it, the alternatives don't exist)
One to One NAT translation is fine although it still breaks a lot of things, especially on the IPV6 side of things. (like MTU path discovery).
I would be really happy to have only ipv6 addresses in my VPC, as that would make connecting up multiple VPCs much easier since I know their ip space won't overlap.
https://aws.amazon.com/blogs/aws/new-ipv6-support-for-ec2-in...
Again, the thing I would like to see is being able to either peer only ipv6 for VPCs, or have a VPC that is ipv6 only. That to me will greatly increase flexibility and simplicity if I'm ok with an ipv6-only deployment
Free ADSL, which has been providing IPv6 access via 6rd for like 10 years, even started deployment of IPv6 only DSLAMs in April.
This makes the absence of IPv6 on major platforms and sites very visible. There is no excuse not to have IPv6 today, especially for market leaders, and its lack thereof is definitely a showstopper WRT services we choose to use.
As an anecdote, we have seen some constantly increasing traffic over IPv6 in our logs, and our customers are definitely not on the technical side, very far from it.
http://m.universfreebox.com/article/38742/Free-deploie-ses-p...
https://en.wikipedia.org/wiki/IPv4_address_exhaustion#/media...
*Consumer, and Enterprises in the US
You're free to see these as orthogonal problems, but if enough people think as you do (moving IPv4 to NAT without first deploying IPv6), then the Internet as we know it is dead.
Then why are they doing NAT?
Edit: Although moving to NAT might push innovation too, or at least some clever hacks. Speaking of that, if you want use a relay to do NAT traversal then is TCP over ARQ (on UDP) as bad as TCP over TCP?
Because they sold their IPv4 addresses.