Moving to IPv6 (2002)
web.archive.org
web.archive.org
Not to say CGNAT is unheard of, particularly if the network was large, old, and needed to expand.
If you are v4 only, and the server is v6 only, you really don't have much hope of connecting.
Really the only thing that is largely stuck on v4 is large (and poorly maintained) corporate networks and cloud providers.
This is the majority of networks on the Internet. Otherwise we’d see adoption greater than 20% or whatever it is.
- NAT44 (what everyone is used to)
- NAT64 (what I just described)
- NAT46 (the opposite of what I just described)
- NAT66 (bad)
In this case NAT46.
Nat64 requires a static route added to your gateway or each node, requires a custom DNS resolver and a daemon which manages iptables on a secondary gateway host for rewriting packets to/from IPv4 destination. It's pretty clever since it uses a /96 (32-bits) on the secondary gateway to return AAAA record for all IPv4 addresses.
Dual Stack is more straight forward requiring only an additional IPv6 address to be allocated to each machine requiring access.
How do v4 clients (dual stacked) connected to the Internet with v4 talk to a v6 server?
NAT64 has your ISP be an IPv6-only network--you get an IPv6, no IPv4 address--and your gateway to the Internet is an IPv4 server that translates public IPv4 addresses to IPv6 addresses for you to talk to. The server at that IPv6 address translates the IPv6 address you requested into the original IPv4 address, and acts as an IPv4 client to the IPv4 server.
If you don't have v4 and v6 interoperability - that is v4-only cannot connect to v6-only and vice-versa, how does the Internet (mostly v4-only hosts) go to v6?
amazon.com. 2S IN AAAA 2607:7700::19:0:1:cdfb:f267 amazon.com. 2S IN AAAA 2607:7700::19:0:1:b020:67cd amazon.com. 2S IN AAAA 2607:7700::19:0:1:b020:62a6
These are NAT64 addresses within TMoUS’ prefix, if I try to ping an IPv4 address it is rewritten automatically as well (though this is a feature of iOS).
If you get people to v6 they can continue to access v4 with numerous transition tools like this, even if dual-stack isn’t an option. You can’t go the other way though.
If you want to reach the v6 Internet, the best way is to have a transition mechanism for v4-only hosts to talk to v6.
v4-only and v6-only cannot in general talk to each other. There needs to be some intermediary to convert between IPv4 and IPv6 somehow. The transition from IPv4 to IPv6 is mostly progressing by having servers dual-stack (give them both IPv4 and IPv6 addresses) and dual-stacking the residential networks, or giving up on IPv4 for your internal network and using NAT64. You could in principle do the same thing for servers, but doing that 4-to-6 translation for the initial recipient of a connection request (i.e., the server) is more difficult than the initial sender (i.e., the client).
Enterprises continue to drag their feet with misguided knowledge of NAT as a security feature (it’s a glorified stateful firewall, enable the IPv6 one your network equipment is practically bound to have). SAAS solutions frequently fail to deploy IPv6 support still, even as major US mobile networks are IPv6-only. Email seems to be stuck in IPv4 land because we’ve put far too much into IP reputation, even though DKIM/SPF/DMARC and proper content-analyzing spam filters are a better and less brute force solution.
Don’t get me started on residential ISPs. CableOne STILL doesn’t support IPv6, and CenturyLink supposedly supports native IPv6 in my area (I ordered a static v4 w/ native v6 online) but nobody can tell me how to configure it.
Let’s get moving already! I’m tired of the hacks.
My residential internet service has provided IPv6 for years. (I think it's 6rd, but I don't care — the company-provided router does the IPv6 router advertisement thing, and all the devices on my home network acquire IPv6 addresses. It's pretty transparent.)
And cell networks are now, as I understand it, mostly IPv6-native. IPv4 traffic goes through NAT.
Only in this case you can't easily identify the traffic in your monitoring and logs because of ambiguous addressing.
Boy how I was wrong :-)