But since VLANs are a layer 2 concept it means you can in theory use them with IPv6 as well (albeit I’ve never personally tested that theory)
Prepending bits wasn't a solution for the problem he discussed.
but then everyone would complain that its harder to write the numbers and try and come up with excuses for implementing it
IPv6 isn’t just a few extra bytes in an IP address.
They removed NAT, which made laymen deployment difficult. I can’t just plug an IPv6 router behind another router (or 3-4 levels of routers) and expect it to just work. In IPv4, DHCP+NAT handles that just fine. In IPv6 I need to worry about address assignment. I don’t care about P2P connectivity issues- the NAT trade-off of using STUN/TURN techniques works for me.
They replaced ARP, and replaced DHCP with SLAAC then realised that people like DHCP so added a version of DHCP back. Except it’s still not the same so has it’s own quirks.
Then there’s the difficulty of supporting multiple IPv6 WANs in one router in a useful fashion. SLAAC takes too long for a PC to detect a dead WAN and use the other WAN range. And there’s no ability to do policy based routing (eg prefer YouTube via dsl, prefer VoIP via fibre) without using NAT+ULA.
Don’t get me wrong, there’s a lot of great things about not using NAT, but there’s a lot of real world scenarios where using NAT is the preferred trade-off.
IPv6 originally decided they didn’t want NAT, and tried to force people into their one way of doing things. They just needed to support both, and then IPv6 deployments wouldn’t be so complicated. They added NAT and DHCPv6 far too late in the game. Even Android doesn’t support DHCPv6 yet and it’s 2019!
Is this common, plugging consumer routers with NAT several layers deep? I haven’t seen that in the wild. The only time I myself tried it didn’t work for some unknown reason.
My only real gripe with IPv6 is the fact that Duplicate Address Detection seems broken on many Wi-Fi networks (clients for some reason see their own traffic as traffic from another node and trigger DAD, which shuts down IPv6 access). I’ve seen this on routers from multiple vendors and I believe it’s some bug in their broadcast/multicast implementations.
But IPv6 in home networks replaces the unreachability-because-of-NAT by unreachability-because-of-filtering. The usual home router protects your clients, and if it's not your box, you're out of luck.
In the commercial/business space it’s more common to see 3 deep. I see it every day. Petroleum in particular often has ISP Router -> Site Firewall/Router -> ServiceProvider Router, because the fuel tank monitoring equipment is behind its own router so the vendor can get remote access/send data back over VPNs they manage.
In retail environments, especially malls and concession stands within department stores, it’s common to be plugged into their network, which you’ll want your own firewall protecting your PCs etc. I’ve also seen businesses at the same office building pool resources and share the one internet connection, with each having their own firewall/router behind the primary site firewall/router.
There’s also hotspots, where the business both puts that infrastructure on a separate network from their back office, and the hotspots themselves are doing NAT too.
Also some payment processors these days are pushing for organisations to install their own router behind the customers network and route all payments via that (Rather than customer managed IPsec VPNs or straight TLS over the Internet).
Yeah it’s definitely common.
Linux/Iptables support wasn’t until Linux 3.7 & iptables 1.4.18 [1]. So that’s only from 2013, when IPv4 NAT has been possible for well over a decade before that.
Also to do NAT66 you really need a ULA address space, that wasn’t defined until 2005 [2]. RFC1918 addresses for IPv4 were set in 1996.
The tooling, support code, supporting RFCs, and UIs for doing IPv6 NAT has been neglected. It’s a halfway house.
1. http://tldp.org/HOWTO/Linux+IPv6-HOWTO/ch18s04.html 2. https://tools.ietf.org/html/rfc4193
It's been a decade and IPv6 has barely entered the zeitgeist of the common internet user.
besides, https://www.google.com/intl/en/ipv6/statistics.html
It has not been a decade! I remember printing out the draft spec in the late 1990s thinking that I have to get ahead of this curve. Twenty years in the making.
I recall at the time thinking initially that the obscure nomenclature for addressing would be annoying, but that it clearly would be fine. What do I know.
In 2010 hackernews luminaries predicted the ipv6 momentum singlularity here: https://news.ycombinator.com/item?id=1236048
The fact of the matter is very very large private corporate networks do not need more addressing space. ISPs use CGnats. Most home broadband routers|modems are junk. It is just a mess
When I said invent, I was supposing we do invent one little extra bit to IPv4, wherein we default to this IPv4 Internet, but we could somehow specify another "universe" and simply have another entire IPv4 network, ad nauseum. Some proprietary routing topography would presumably exist as an inner layer, providing decades of new complexities, masking the implementation for naive ipv4 stacks that couldn't be updated. Those, could continue to exist unawares and perhaps very disjoint between "universes".
Anyways, I am not an Internet architect, and this idea is entirely foolhardy since we have a perfectly good IPv6 universe to move into, one that barely has unpacked the moving boxes from the previous. I suppose all I meant, is that we might invest some more energy in IPv4 before we're really done with it.
They should be actively blocked or redirected to a site that offers quality hardware (Cisco need not apply)
Hell the equipment probably has hardcoded creds that are part of critical infrastructure too.
My argument is to trash crappy equipment.
You didn’t seem to take into consideration all the places where 30-year old equipment is still good, the reasons for why stuff is not uogradeable, nor people who cannot afford spending $100 for the new stuff.
The thing here is cross universe communication and legacy hardware/software stacks.
This sounds like a great mental exercise.