Which is kind of ironic, because you don't get that with most wireline connections, as they're all done through IPv4 NAT.
Which is kind of ironic, because you don't get that with most wireline connections, as they're all done through IPv4 NAT.
[0] Comcast is surprisingly good here -- they'll give you a /60 (16 /64 networks) if you ask for it with the right DHCP option!
Can you go into more detail or point me to instructions? I'm on Comcast and would be interested in getting v6 at home.
I run a little OpenBSD router and my dhcpcd.conf is here [1], but I've done this before on a Linux router box too -- here are some instructions from Arch's wiki [2]. IIRC, the stock firmware on my old consumer router was also able to request a prefix and advertise it on the network.
[1] https://gist.github.com/cfallin/e5865a6a93c75ace8d26d6a85287... [2] https://wiki.archlinux.org/index.php/IPv6#Prefix_delegation_...
I actually played with NAT64 for a bit (IPv6-only internally, all IPv4 space is mapped to a special /96 in IPv6-space and NAT'd at the router, and local DNS server on the router returns translated AAAA records for IPv4-only hosts), but dropped that when I simplified my router config. It works, it just takes a bit of config :-)
Any user that wants more than a single subnet at home is supposed to receive a /48 by the same recommendation base. A lot of ISPs settled on /56s. Comcast is a bit more stingy than some.
That introduces a whole other set of problems.
And finally, the space is huge -- an ISP would typically get a /32 at least (Whois says that Comcast is using a /26 just for the Bay area), so if every customer gets a /60, that's 2^28, or 256M, delegations. (With the /26, Comcast could hand out 16 billion /60 delegations to their SFBA subscribers.)
[0] https://www.ripe.net/publications/docs/ripe-690#4--size-of-e...
DDNS is something that I once thought would be an artifact of a less civilized time, but ISPs gotta upsell, I guess.
At the very least, IPv4 fallback takes a few seconds for each DNS query, and I've experienced it failing completely in some cases (can't recall if I ever figured out why). So regardless it's a PITA when it happens.
I tried disabling the option for it to advertise itself as a DNS and instead insert the local IPv4 address in the DHCP options but to no avail, clients still ended up with public IPv6 as main DNS.
After a few hours of trying to fix it I just turned off IPv6 again.
If you set a machine to try just one IP address per second in IPv4 you'll explore a significant fraction of the whole public address space per year. In IPv6 doing that is extremely unlikely to find even a single valid address to connect to in a human lifetime.
Practically, my laptop is in some Wifi network and has an IPv6 address, but that isn't accessible from the outside because the Wifi/router box blocks incoming connection. That is a wise decision overall, but unforunately replaces the "can't connect because NAT" by "glorious IPv6, bit still can't connect".
And I'm not the owner of those boxes.
I've had a static IPv4 subnet allocation from AT&T on AT&T U-verse, and tried using it on a couple of consumer routers for the local network. Well, guess what — all these devices from major brands that are called "routers" don't actually route between the interfaces, after all — all they did was NAT between my public IPv4 allocation and the main IPv4 address assigned by DHCP. And disabling the NAT simply disconnected the networks — instead of rounting one interface to the other. I actually opened up a support ticket with ZyXEL, which got escalated to their engineering managers, and they did confirm my finding that their routers had a bug in sysctl settings that stops them from routing the interfaces (e.g., sysctl net.ipv4.ip_forward not set to 1).
Anyhow, back to T-Mobile US IPv6 on a hotspot — when I originally tried ssh'ing back to my own box via the public IPv6, things didn't work, either; but I then found out that it was some sort of a local policy on the local machine, because another laptop without a firewall was able to receive connections on IPv6 from the internet without any issues.
SSH is normally not enabled, either.
sudo ufw default deny incoming
and your laptop is now secure.
You can configure firewall rules on that.
In fact, the default is almost always to disallow all inbound and allow all outbound.