More than 1/3 of all access to Google is now over IPv6
google.com
google.com
In the requested scenario (internal Enterprise network), the proper comparison should involved IPv4's 16 million private addresses; I can't see any practical advantage to IPv6 there.
Most enterprise networks need to be routed to other networks -- either other networks inside the enterprise, networks inside other enterprises or the internet. To make that work sanely all of the networks involved need to use address ranges that don't overlap. RFC1918 is pretty much the definition of overlap, and using it makes things way more complicated than they would otherwise be.
The IPv6 enterprise argument is 'You might one day have to renumber some devices because some other enterprise might have set up overlapping addresses, therefore you definitely have to renumber everything now, and oh, every time the ISP decides they don't like you, because private addresses are icky'. Obviously that's a hard sell.
> The IPv6 enterprise argument is 'You might one day have to renumber some devices because some other enterprise might have set up overlapping addresses, therefore you definitely have to renumber everything now, and oh, every time the ISP decides they don't like you, because private addresses are icky'. Obviously that's a hard sell.
If you’re an enterprise you would just get your own IPv6 block assignment. It’s not like they’re expensive or hard to get hold of.
Companies already buy and manage domains, this is no different. Using a domain you don’t own is just plain stupid, same applies to IPv6 ranges.
For context, apparently a block of 79,228,162,514,264,337,593,543,950,336 addresses (/48) is about 100$ a year.
Also, the major players probably have more than 16 million devices, especially if you could VMs.
Comcast (an US cable ISP) starting deploying IPv6 because they have so many CPE devices that they are out of IPv4 addresses to do management on them. Story from 2010:
* https://arstechnica.com/tech-policy/2010/01/comcast-running-...
It's also why Apple mandated at some points that iOS apps had to work on IPv6-only networks: it was a requirement from mobile phone companies, as IPv4 addresses are getting scarce, and mobile telcos don't want to shell out cash, so they use IPv6 on phones and do NAT64.
- Both corporations probably started allocating from the top
- Both corporations probably allocated huge subnets.
I know IPv6 network engineers despise RFC 4193 - but, it offers extraordinary flexibility around addressing - particularly if you have large networks that you want full control over. At my last gig, we deployed over 25 million nodes in RFC 4193 space, and it worked like a charm.
The default /64 prefix length can fit the 2^32 public Internet addresses 2^32 times, i.e., 4B Internets can fit in one IPv6 subnet.
Nearly all security intrusions today are "pulled" in anyway via the web, e-mail, update channels, etc., or are injected by human beings via large scale or targeted phishing.
I did netsec for a while and during my tenure all the incidents we had were caused by phishing of one form or another.
Once you are inside the network, any tiny bit of defense in depth supplied by NAT becomes irrelevant.
Security is so full of mindless cargo cultism...
I don’t have it on 4G, either.
edit: am I missing something? The graph shows total IPv6 is 29.86% (which is clearly less than 33.33…%)
The highest weekly peak so far is 33.42%, and the troughs are just below 30% at the moment. The last time the weekly peak was ~30% was in December last year.
Corporate networks tend to have a lot of local policy, and so that's a maintenance burden that probably nobody is paying for so it's just a growing debt for the organisation. Even if every policy was excellent when it was deployed many of them probably hurt by now. At home that stuff tends to get flushed periodically but medium-large businesses have processes to preserve the status quo. The same underlying mechanism that prefers to terminate the 25 year secretary who "made fuss" about a VP putting his hand up her skirt rather than do anything about that senior executive will also prefer to buy $5000 Cisco switches and then disable everything that makes them better than a $50 Costco switch over just buying the Costco switch (let alone using the features of the expensive switch). Change is seen as bad and must be prevented.
This hurts for security a lot too. There's a very good chance that accessing work email from a work laptop in the office is meaningfully less safe than accessing GMail on your phone in a random coffee shop because of such policies.
The cloud providers have pushed back ipv6 adoption so hard imo. At least native ipv6 access.
I know they’ve thrown in some token support and you /can/ make something work; but compared to VPS providers which consistently deliver machines with IPv6 addresses by default- it’s a huge barrier to adoption. You have to really /want/ it, and most people don’t see the value. Unless it’s a backend for an iOS App.
It really frustrates me.
Take a look at kubernetes, which is based on google's Borg. It's only now, slowly getting IPv6 support
I just think that there’s little demand on cloud (and tons of other high prior work)
There would be a lot of demand if IPv6 wasn't an "also ran", a "tack on", some checkbox to tick.
Think about how much network complexity would simply vanish if everything used only public routable IPv6 ranges.
No more split DNS. No more NAT gateways. No need for a separate "public IP" and "private IP". No need to carefully "carve up" the 10.x.x.x range to carefully avoid overlaps... even with future business partners. No need to worry about the "size" of subnets or accidentally running out of addresses in the cramped /24 subnets most people allocate.
It goes on and on.
And on.
But none of that is possible in the public cloud, because it is IPv4 first, and 99% IPv4 by default, and if there's IPv6 support, it's broken, or incomplete, or half-arsed.
(They still could do IPv6 proper - no argument there)
If the default security group for IPv6 only allows SSH and ICMPv6 to an instance/host, what difference does it make?
* https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-secu...
It's not the NATing that gives (internal) networks security, it's the stateful packet inspection at the gateway and--more and more--at the host level.
IPv4 NAT provides security as a side effect.
You don't need NAT for security.
PS: This is the #1 most common argument trotted out against IPv6, and it is blatantly false.
https://www.f5.com/services/resources/white-papers/the-myth-....
Obviously that doesn't make those machines secure, but an insecure machine that hasn't been exploited is better than an insecure machine that has.
Laughable, right?
IPv6 was available in Windows 2000. Just saying.
If any vendor had tried to sell a network product in 2001 that didn't do IPv4, they would have been laughed out of the room.
Nobody is laughing in the faces of vendors in 2020 for selling products that can't do IPv6 properly... or at all.
Nobody will be laughing in 2021. Or 2022... or...
I suspect we'll be having this conversation in 2030 as well, and the same people complaining about the side-effects of carrier grade NAT four levels deep will trot out things like "IPv6 doesn't have security because it's not behind a NAT!"
I mainly remember as Vista dropped IPX support, rendering those games unplayable on LAN's for years until someone developed a UDP patch instead
Over the next few releases, they worked hard on v6 support, and in fact some issues people had with Vista were caused by NT6 being IPv6-first OS, across all of the MS solutions. MŚ had to go backwards a bit in 6.1, introducing things like v6-over-HTTP tunnels because they found that assuming native v6+ipsec working was too much, even with Teredo.
For one, they NAT all IPv6 traffic.
Let that sink in. Let it percolate. Mull over the fact that the entire purpose of IPv6 is to eliminate NAT, and that it's practically impossible to get an IPv6 NAT-ing network device.
Microsoft must have had to write their own, custom network load balancers to NAT IPv6. It's madness.
Oh, if that's not bad enough, they also hand out ludicrously small /124 ranges of just 16 addresses. Sixteen! Not sixteen trillion or some crazy huge number like that, which is what I've got on my home internet. Sixteen. Six and ten.
But no worries, right? Just allocate more blocks! Bzzt... that would run up against the subscription IP limits with just 100 addresses.
Okay, fine, just because my lab environment needed more than a couple of addresses doesn't mean that everybody is so wasteful with the precious IPv6 address pool. Some people can constrain themselves to just a handful of addresses, and don't have a problem with any of the above.
Except that when Azure finally adds proper, native IPv6 support, whatever work their early adopter customers have done will have to be thrown out and redone. Subnets. DNS addresses. Load balancer rules. NAT rules. Security Groups. Everything will have to be revisited.
So why would you bother?
https://docs.microsoft.com/en-us/azure/virtual-network/ipv6-...
This is rather bad considering the importance of ICMPv6 in IPv6 (for Path MTU Discovery, for example).
Their support is being rather useless, despite us having to pay for the privilege of reporting a bug in their own infrastructure to them!
Azure sucks anyway. Their prices are not good and their management console is horrible.
That’s why adoption is slow.
NAT isn’t such a huge problem that the industry thinks it’s urgent enough to push hard to solve.
RFC1918 was forced upon the cloud providers only because there weren't enough IPv4 addresses to go around.
If Amazon had started in 1980, they would have simply allocated a /8 for each region and be done with it. No NAT, no gateways, no address translation of any sort. Everything routing to everything else natively.
AWS has 24 regions. If each one had a single /8 block -- which would be the bare-minimum at their scale these days -- they would eat up 10% of all available IPv4 addresses!
Keep in mind that they would still have to "carve up" that /8 for each customer, which is still an overly tight fit. Either everyone gets a bunch of small random pools of addresses (eww), or they have to restrict each region to a small number of customers (bad for business), or provide each customer with tiny subnets (too restrictive for the big fish customers).
With IPv6 this just vanishes. They could have multiple address ranges for each Region, AZ, CDN POP, or whatever. They could have ranges for each service, making firewall rules trivial. They could give each customer a huge prefix that they could still carve up into many subnets.
I seriously don't get the arguments against IPv6.
Why are people so happy with their constraints?
For example, Azure Network Security Groups (NSGs) have some glaring omissions that were ignored for years, but have just recently been oh-so-conveniently resolved by Azure Firewall. The old NSGs were free, the firewall costs money, and they also charge per gigabyte of data transferred through it!
Of course, they're recommending that all customers should immediately "uplift" their network architectures to plumb everything through a central firewall.
For security.
You know, income security. For Microsoft.
I should go buy some AMZN and MSFT...
Bucking this trend and building an "Internet-style architecture" is a competitive advantage. You can save multiple orders of magnitude on your hosting and bandwidth costs.
So then you ask the engineers, "when are you going to adopt IPv6?" And they're like: "What do you mean? We've never NOT used IPv6 for everything important."
On the one had my GCP server's "native" IP address that the OS sees is always an IPv4 address. On the other hand, it's always in the 10.x.x.x/8 range. Everything else is NAT and LB.
Why? What problem does this solve?
Even just working out what IPv6 devices are on my network and who they're communicating with seems very difficult given the giant address space. I'm slightly ashamed to admit this (feels very anti progress!), but I've blocked all the IPv6 traffic on my home LAN. Devices can still talk to each other, but no IPv6 packets are allowed out to the internet. Everything still works fine. My firewall blocks a few hundred MB per day of IPv6 traffic, and I have no idea what any of it is.
Very happy to be told why I shouldn't do this though.
The choice isn't between every device being globally routable (which is easily solved by a firewall WITHOUT NAT) and a single routable address, the choice is between zero public routable addresses, and as many as you need.
E.g. my ISP doesn't hand out public IPv4 and you can't order it, unless you change to a business contract. However, my ISP is doing some weird 1:1-NAT, so while I don't get assigned a public IPv4 to my router, I do get assigned a single IPv4 on the CGNAT router that also translates back to my home network.
It's probably a 1:Many NAT, where the external IP you see yourself as coming from, is used by many customers, not just you.
Otherwise there's no upside to deploying the additional overhead and cost of CGN devices for the carrier.
Because your IPv4 traffic goes (or will, in the future, as IPv4 depletes further) through a slow, overprovisioned CGNAT - making IPv4 much slower then IPv6.
On a more personal note, if ipv6 were so great, their fans wouldn't have to make up things to badmouth ipv4.
The larger the network behind the NAT, the more problems you get. This is also before considerations like the fact NAT breaks 2 way connectivity that is the cornerstone of the design of the internet.
>if ipv6 were so great, their fans wouldn't have to make up things to badmouth ipv4.
The explicit goal and reason IPv6 was created was to make up for the short-comings of IPv4.
The Internet of the 1990s was very different to the Internet of 2020. The widespread surveillance of activity as it exists today was not a consideration back then, nor were there the same security concerns, making it a desirable property to have every device uniquely and globally addressable.
Privacy extensions were then ratified (RFC 4941) after 2007 as a workaround, and firewalls get applied on hosts and gateways to protect against bad actors on the Internet (which are significantly more prevalent today than 20+ years ago).
IPv6 is not a magic bullet. The increase in addressable space is definitely a positive. Pretty much everything else is up for debate, depending on perspective and use case.
I've been dual-stacking networks for over a decade. The easy part[0] is making the network work with both IPv4 and IPv6. The hard part is making everything else work.
[0] Easy is relative. I agree with everything listed in https://news.ycombinator.com/item?id=24059729 as additional sources of complexity and confusion. That's still just the mole hill at the start of the mountain.
And I've been on several residential ISPs where IPv4 was unusable during peak netflix hours, likely because people were blindly disabling IPv6 on their devices.
With AAAA enabled for *.netflix.com address resolution, I can't watch Netflix. If I actually paid for it, versus getting it included as a perk of T-Mobile, I'd have quit over that. I shouldn't have to fiddle with DNS to watch a service I pay for.
Why the hell would you block IPv6. You ARE stuck in your ways. OS vendors consider it necessary on LAN for various functionality.
Devices configuring without DHCP as a network administrator is really hard. There is no longer a single method to be given an IP6 address, and with the auto methods, there is no log either. Only some clients will do dhcpv6 which means you often have two different auto configuring services on a network.
Similarly, to see devices on a network I now have to use neighborhood discovery whice gives me a bunch of IPs, but very hard to figure out which IP is for that raspberrypi next to me. Port scans are much harder.
Public IP address are great, but now a filtering firewall is always required at the edge, since I don't want my printer being reachable on the internet. There isn't a upnp for IP6 to punch wholes automatically either. Ironically P2P over ipv6 is harder because the firewalls are so unforgiving.
Port scanning _should_ be difficult in IPv6. Instead, you should be using DNS and/or multicasting.
Having multiple ways to configure IP addresses _isn’t_ a problem. Modern devices have lots of RAM. They can handle having lots of IP addresses.
Because of how difficult it is to port scan IPv6, as long as you don’t manually allocate a low-entropy address to the printer, it won’t be easy to get to it. Even better, these days you can allocate a unique local address to the printer (RFC 4193, fd00::/8) and eliminate Internet access entirely. https://tools.ietf.org/html/rfc4193
I.e. essentially what we already had with IPv4.
> Because of how difficult it is to port scan IPv6, as long as you don’t manually allocate a low-entropy address to the printer, it won’t be easy to get to it.
Security provided by 'the attackers get bored'....
You could sort of consider the 64 bit host ID to be a cookie, stored in DNS, that has to be provided by the client to connect to the server. Viewed like this, the IP itself would be considered a layer of security, since it forces the client to know the correct DNS name (or spend a lot of time guessing) to connect.
Right so as I said elsewhere I'll be dropping all packets for incoming connections at the firewall. I was heavily downvoted for that comment... I guess a lot of folk will leave insecure devices open to the world.
IPv4 is from the old days of 1 device, 1 IP address.
RFC 4193 addresses are in addition to the globally routable IP addresses. Your laptop could have both classes of addresses. Your printer could have only one class of address.
Between the ULA and the global addresses, with DHCPv6 and NDP and IPv6 privacy extensions, my laptop currently has 13 IP addresses on its main network adapter. That’s leaving my router and my laptop on default settings, nothing special, no appreciable memory impact.
1. What the hell is DHCP-PD and is it better on or off?
2. What are 6to4, 6in4, 6rd, etc. and should the user care?
3. When should autoconf be stateless vs. stateful? I thought the point of IPv6 was to allow things to be stateless?
4. When should DHCPv6 be enabled vs. disabled? Why the hell is this even a question on some routers if devices are supposed to be "autoconfigurable without DHCP"?
5. What are the more subtle implications of all of the above that are not necessarily mentioned?
6. Give one good reason why in the world every single one of every user's devices should be reachable from anywhere on the internet for even a single moment in time? Why exactly do you feel you should even have a reachable path to my computer, and everyone else's too? Common sense precautions would suggest this shouldn't be possible by default.
Note: I personally don't need responses to all of these. I'm just listing some examples of questions that come up for people configuring it to illustrate why the choice to use IPv6 is hardly as simple as you depict it to be.
I get all the concerns about CGNAT and so on, but that's something for the ISP to figure out. If I get a message one day saying that my connection speed is about to drop 30% because of my insistence on IPv4, I will of course react!
The question for me is not, "why would I block it?" but instead, "why would I enable it?". There needs to be a reason, and right now I'm not seeing it.
But if you're running your own router then you're taking over part of the responsibility, so you need to handle your part of it.
In both cases for residential use: you're most likely ok with the defaults. And if you want to change something, you have to learn about the tech.
But even if I was, "it only doubles the complexity" is not exactly a compelling response to "why should I switch to IPv6?"
And for basic usage people can ignore that the same way they ignore it now.
If your argument is users can ignore IPv6 complexities as they already do with IPv4, then you've just established the IPv4 complexities can be disregarded by the user... which means you just destroyed your own argument...
I'm not interested in endless debates here though; I feel like I've made my point sufficiently well. If this is an attempt to change my view on the matter I think you're misunderstanding the purpose of the discussion.
6to4, 6in4, 6rd are legacy transition technologies, not needed when you have IPv6, so don't worry.
NAT vs Direct addressing is an interesting topic, because we've gotten so used to working around the issues inherent in NAT that we take them as a sort of given. I'll lay them out here:
1) The actual NAT state table in your router is much slower than a simple bit-map firewall lookup. This will show up as a bit of latency on every new connection.
2) The state table can get full. When that happens some connection needs to be evicted. For web technologies this wont look too bad.. Maybe a websocket connection gets closed and re-connects in the background. But if you're streaming something over raw TCP then that's annoying. Basically it makes your internet connection just that little less stable.
3) uPnP exists to try to mitigate the p2p issues with NAT; but does a poor job. -- Take for instance, a video game with VOIP, consoles are notorious for this; centralising and muxing everyones audio is expensive, so it's more useful to help people build peer meshes. So "NAT PUNCHING" is the normal way to go, but of course that doesn't always work, so you have weird tutorials on "how to port forward" when in reality this shouldn't be needed, a stateful firewall would be enough if not for NAT. Some guides even suggest putting your devices in the DMZ with direct port forwards on every port from the internet[!!]
https://www.denofgeek.com/games/how-to-change-nat-type-on-ps...
This would be so much more convincing with some numbers to show it actually does happen in reality, especially at a rate that's comparable to other random connection drop-outs.
This is hard for individuals to see, but put a fair bit of load on a home consumer 'router' and, presuming you can get enough access to it to watch resources, you'll see it run out.
This is one of the things that better home network devices do: have sufficient RAM to handle a big state table, and manage it well.
IPv6 completely sidesteps this by not even needing a state table because no NAT.
You may have forgotten that a stateful firewall that tracks inbound and outbound connections still needs memory to store a state table still applies in IPv6.
Now it also needs 8x more memory per entry, as the addresses have gone from 2x 32bit to 2x 128bit.
This actually seems bizarre to me now that I think more about it. The routers I've seen allow something like a few hundred thousand established connections over like a ~week. Say 300,000 over 3 days. To exhaust this you'd need to establish on average one new connection every single second (300000/3/24/60/60 ≈ 1), continuously for a week, while also timing out on every single one of them silently. Surely a normal person wouldn't exhaust such a table?
Professionally I run one (two, actually) of those annoying 'always online video games' and state drops in low quality routers is the most common cause of VOIP drop.
It seems like most router firmware has some kind of intelligent sensing software to see if there's a lot of traffic going over a state and then attempting to avoid evicting it. But for VOIP which can sometimes be silent.. or for a person not moving around in a game (and thus sending/recieving very few and very tiny updates) it can be seen.
Now; you want concrete evidence, and unfortunately the kinds of routers most people have (Say, a Virgin Hub 3.0 which is based on the Touchstone TG2492[0]) does not lend itself to being monitored well.
We're in some luck though, as I happen to run something immeasurably more powerful: a PfSense branded NetGate APU2[1]
PfSense absolutely /loves/ letting you know how it feels; and if we assume that I'm a "normal" user, (I have 1 laptop, 1 phone and an apple watch as the only devices on my network right now and I'm just browsing like normal) then we have some measure of how much memory a state table really consumes.
My state table currently contains a mere 170 states (according to iftop), but it's not really hurting my memory:
> 6% of 4030 MiB
Yet, I can see that some states have been forcefully closed, despite having lots of ram available to store too (these statistics were reset yesterday):
state-mismatch 748 0.0/s
In general the state table is very busy: State Table Total Rate
current entries 152
searches 90040931 338.1/s
inserts 437333 1.6/s
removals 437181 1.6/s
it's worth noting that this device is forcefully configuring itself to hit a max of 403000 states total: states hard limit 403000
So it's not "memory" like you suggest, but since doing nat translation on every single packet is CPU intensive, states can be dropped if the table can't keep up.[0]: 256MB of ram reserved for the state table it seems: https://deviwiki.com/wiki/Virgin_Media_Super_Hub_3
[1]: 4G of general purpose ram: https://www.firewallhardware.it/en/apu2-3nic/
the Hard limit is just one imposed by the OS, it doesn't seem to matter that I have absurd amounts of free memory, or that the kernel is quite content with loading up hundreds of thousands of states: they still get dropped.
And like I said, my hardware and software platform is many dozens of times more advanced than what most people are using at home.
As for the usage; easily explained by: every single website I open, all of the things that website asks my browser to pull in, every DNS request, every NTP update and every 'ping' to see if the device is online-- counts as a new state.
But network address translation _can_ be a processing-heavy task.
Every single packet that leaves the private network needs to be translated, and every single packet that comes in from the public network needs to be translated. Each individual translation may be simple enough, but with heavy internet use, it all adds up.
Here’s my network activity while browsing the web: https://i.imgur.com/oP8PrX4.png, with one 720p YouTube video open in a tab and a dozen other tabs for various websites, all in the Edge browser.
The top nine processes are using an average of 1,182,149 bytes per second. Every network interface has a maximum transmission unit (MTU), which is the largest size that a data packet can be. Ethernet and Wi-Fi have an MTU of 1,500 bytes.
My computer, doing nothing more than watching a YouTube video, is putting a minimum load on my router of 788 packets per second. That’s assuming the bytes are all divided into 1,500-byte packets, which isn’t the case in real world usage. Somewhere between 1,000 to 3,000 packets per second is more realistic.
The load is worse during bandwidth-intensive activities, such as multiplayer gaming and torrenting. In fact, torrenting is so intensive that it’s the primary cause of NAT issues for home users today. (Open connections to dozens/hundreds of peers, with each connection involving high-speed downloads and uploads.)
And it’s not just one computer on a private network. It is commont to have a smartphone or two, maybe a tablet, smart TV, plus a handful of other devices for the rest of the people sharing the living space. They all need network address translations too!
At the end of the day, we’re talking thousands and thousands of data packets per second, all translated by a weak CPU that can’t keep up. It’s one reason why cheap routers are prone to slowing down.
Notably: while doing that (and opening youtube) my state table grew to just under 400 states. So, youtube needs a lot of connections it seems.
I routinely see a single ad impression make over 20-50 connections outbound, and repeatedly close and reopen or randomly open new ones for various reasons, the most common being some form of "anti ad fraud" tracking that repeatedly polls to get an average or median latency, new connections and requests firing on every mouse move, etc.
Would also be entirely unsurprised if phones that had free mobile games and equivalent were polling and sending stuff like location data every minute.
* https://www.zdnet.com/article/apple-tells-app-devs-to-use-ip...
According to Apple, IPv6 is 1.4 times faster than IPv4 (latency wise AFAICT):
* https://www.zdnet.com/article/apple-tells-app-devs-to-use-ip...
This is supposedly "due to reduced NAT usage and improved routing."
It is great marketing to list 40%. But we need to know 40% of what. If it was 1ms, than 0.4ms faster isn't much of a performance.
I got a warning about an unauthorized attempted login to my gmail account. They gave me the IP of the offending login. I was able to track that IP not only back to my house, but to a specific device in my house.
It was my NAS, and it was trying to log into gmail to send me an email about a failing drive. Gmail no longer allows username/password logins from third party apps, so I got a warning instead.
Without IPv6, I would have just chalked it up to a misbehaving device and ignored it since it came from my own IP, but because of IPv6, I was able to see it was from the NAS and investigate further.
Azure officially has IPv6 support, but like every other cloud vendor, they are 100% native IPv4 with IPv6 bolted on as an afterthought.
For example, it's impossible to create an IPv6-only Azure vNet.
The metadata API endpoint is IPv4-only (169.254.169.254).
So on, and so forth...
Please provide citations if you’re going to speak so factually.
That's fair. I don't really have handy citations. I just know this stuff from working in email deliverability for a long time. I guess you can choose to believe me or not.
A mailserver was blocked by Gmail until I disabled IPv6 on it.
I just wish gmail had tech support so I could resolve this directly instead of flailing about trying random obscure solutions.
I decided I'd need to configure Exim4 to issue a different EHLO name depending on whether it's connecting over IPv4 or IPv6, and then triple check (with tests) that reverse DNS unambiguously matched in each case.
But as deliverability was the priority, disabling IPv6 seemed lower risk than fiddling with config, seeing it work, then finding out a few weeks later that it introduced another "Google mystery factor". Reviewing that is on the todo list somewhere, very low priority.
If more developers and SA's would have access to IPv6 at home, the practical knowledge of how to work with IPv6 would build up more quickly. I would experiment with it more, and build up more knowledge.
Unfortunately, my ISP does not support IPv6. This severely limits experimentation with it, since all experimentation is locked behind my home network.
You probably know about this already, but there are free IPv6 tunnel brokers you can use to experiment. I previously used Hurricane Electric's tunnel, back before Comcast had native IPv6 support: https://www.tunnelbroker.net/
A more practical challenge, Hurricane Electric is a 6in4 tunnel, not layered over TCP nor UDP. Some ISP-provided residential gateway devices (AT&T) don’t support 6in4, not even if you configure your device as a “DMZ” with a public IP address. Also, I frequently find myself in situations with IPv4 NAT and no public IPv4 addresses at all.
The only free IPv6 tunnel service that supported UDP was SixXS, which shut down in 2017.
Nowadays, AT&T supports IPv6 natively, and I went through an annoying amount of effort to bypass their gateway device and control the entire /60 instead of being limited to a /64 and being limited by their NAT. https://github.com/jaysoffian/eap_proxy
It's surprising that China doesn't show as dark green on the world map. China was into IPv6 early; the address space was needed.
This one better describes the situation: https://blog.apnic.net/2019/01/03/ipv6-in-china/
Some are IPv6-only, because it's much easier to manage from my side. I whish I could add an A record for these that pointed to a reserved IP address that would inform clients the service is IPv6-only.
For now, I just don't put any, and browsers just display a generic error. Since some DNS don't answer with IPv6 addresses, the browser couldn't even provide a meaningful error message if it tried to.
Would that be worth an RFC? What IP address should be used?
* I don't know any browser or app that display a special, informative message in that specific case.
* You need a DNS server that answers AAAA record to detect this. Some ISPs do not provide IPv6 connectivity, nor do their DNS servers provide AAAA records. In most places I know, especially when talking about individuals, people use their ISP-provided DNS servers.
Even better if web browsers could display a message of their own, recognizing this IP address.
How long have they been saying that now? Five years? Ten years? Probably about ten years.
IPv6 affects everyday internet users exactly 0%. It's rational for them not to care about it.
Obviously it's not worth it for any website that matters to actually do this, but it's fun to think about.
Things like using only numbers and not issuing address with letters. We would still get larger than 64bit of address space, but we dont have to work with the gibberish address.
I mean, Google DNS is 2001:4860:4860::8888, and in the IPv4 style it would have been: 32.1.72.96.72.96.0.0.0.0.0.0.0.0.136.136 I’m sure if IPv6 were formatted like IPv4, Google would have formatted the address differently, like, 32.1.72.96.72.96.0.0.0.0.0.0.8.8.8.8
The point is there is no way around the address being uncomfortably long, and doing it in a new style with hexadecimal allows both easier manual calculation of the address and an opportunity to truncate all those 0s in manually allocated addresses.
That is exactly what I meant. Instead of 20FA:FF00 etc.... the sets should use Numbers only. It is still within IPv6 spec, we just dont user letters ( Yet )
Is the great firewall ipv4 only perhaps?
I wonder if anyone is exempt from the Great Firewall? What about senior officials including Xi himself? I’m sure if he asked for unfiltered Internet he’d get it.
...which is certainly possible, but just "Google is blocked" alone doesn't cover it.
Still not sure why they do that.
I'm not a networking expert, but AFAIK there's nothing stopping them from making their 6-to-4 bridging available to customers with a custom router. However, getting that stuff up and running correctly can be tricky, so it would involve a lot of support burden on the ISP's side. Hence why they don't offer that, they just drop those customers down to a configuration where the customer gets to use well-known protocols only (IPv4 and DHCPv4 over Ethernet).
https://www.juniper.net/documentation/en_US/junos/topics/top... (this isn't a purely Juniper thing, but they have nice diagrams on their documentation)
It's a kind of carrier grade NAT with 4over6 baked in.
Depending on the version of this they are relying on your modem to perform encap/decap of 4to6, hence when you switch to modem mode or your own router you fall back to what the network truly is... v4.
This is what the knuckle draggers at Virgin Media are contemplating apparently.
In the UK the best option for IPv6 is https://www.aa.net.uk/ but unfortunately for me the DSL speed in my area is pretty bad due to being a few KMs from the exchange.
The alternatives to all of this is to run your own Wireguard instance elsewhere on a v6 network, and tunnel the entire home network to it.
For VDSL the distance to an exchange shouldn't matter. The copper runs to a green box in the street, then another newer-looking green box nearby (or in some cases attached) with fibre in it takes the VDSL signal - and only old-school voice line conversations go to the exchange.
So definitely if previous ADSL speeds were poor it's time to check again. If you just meant that as shorthand then no worries, but I've run into way too many people who have the idea that all DSL is the same.
Hyperoptic will give you a globally unique IPv4 address for an extra £5/month, and otherwise will stick you behind their CGN.
My guess is that turning on bridge mode also migrates you from the ISP's newer DS-lite service to their older v4-only one. This is unfortunately common in DS-lite deployments; ideally the old service would also have v6 so that you aren't forced to choose between v6 and non-CGNATed v4.
I was on them for a year great service.
I'm now on Hyperoptic which also does IPv6.
IPv4 not having enough addresses is a good thing.
With IPv6 identification (and therefore control) can be down to the person globally, but IPv4 forces NAT's. The inability to label all the things is a feature. NAT's are borders; they prevent fine grained censorship without larger consequences.
$ zcat /proc/config.gz | grep -i ipv6
# CONFIG_IPV6 is not setDo you have better insight than Apple?
It's also always there to pretend the major corps care about (insert 15s ad here) it.
If you really measure response time, frame by frame, Windows 3.1 is faster than Windows Billion.
Process improvements in hardware obviate any trivial 40% benchmark. 400%, maybe, lets talk about it.
It's utterly irrelevant compared to what being to tag every item every person ever comes into contact with and the interactions of those items with other items; iterated as many times as desired.
Google building their infrastructure around IPv6 does not have anything with tracking IPv6 users
And surely you can do NAT with IPv6, Google for NAT66, but your average Linux box can do it. It's just almost never needed.
This is widely believed, but it's false. There is nothing whatsoever stopping you doing NAT with IPv6, even though you probably don't need to.
In the early to mid 90's, nobody did NAT with IPv4 either.
Your client machines don't know what is going on at the border, so they can't "choose" a route out unless you turn the lot into routers and use OSPF or something internally.
So NPT. Your router sends flows out over links and rewrites the prefix accordingly for that link. Its a bit horrible and I've decided not to bother yet.
https://www.transtutors.com/questions/how-many-bits-are-need...
People know why. Even if a few really get 32's, it's PR. The endgame is the same.
This is a critical path item for removing the ability to have 2 party value transfers. The power at stake is incalculably valuable.
The vast majority of IPv4 connections get an IPv4 IP (= a /32), CGNAT is pretty much only used by providers that don't have another choice and has various downsides for users too.
IPv4 not having enough addresses is why it's valuable. It's impossible to arm band every human with 32b.
EDIT: I'm comment limited for the night. @efzx: Seeing "google" in the same sentience with "does not have anything with tracking" is pretty good stuff.
In the typical IPv6 setup, your network gets an IPv6 prefix from which client devices use randomized and rotating IPs. Everything in your network is trivial to group.
How long the network-identifying address/prefix is stable is purely an ISP design choice - some keep them as long as possible, others force a change regularly.
Both of my ISPs hand out new ISPs hand out new /64 prefixes every so often. One does it every half-hour, the other is comparable but I don't remember. I think they do it to encourage business customers to get more expensive connections, but the effect on my connections is that each device's IP address changes every few minutes, within the ISP's /32, and doesn't repeat in a year... and I do wonder how many IPSs do this.
Changing your prefix every half an hour would be... unusual, at least, although again I wouldn't put it past some ISPs to do that (possibly unintentionally)... but sounds like your prefix might be changing every time you do a DHCPv6-PD request, which makes me wonder if your DHCPv6 client might be generating a new DUID for every request rather than remembering it.
How do you know that the ISP replacing it often is "unusual, to say the least"? Or is that something you know?
Even my incoming rdiff-backup jobs don't raise a noticeable number of errors.
If 30-minutely prefix changes were common, people would definitely be complaining about it.
...but okay, I won't claim that I catch everything. Can I ask which ISP this is, or at least which country? Perhaps it's common in places that don't have much presence in the English-speaking parts of the internet.
It's nice to hear that it mostly works for you. It should do, but a lot of software is terrible at handling dynamic changes -- it seems to be something that programmers struggle with. The biggest problem should be that long-running connections aren't possible.
Why can't Android devices connect to ipv4-only networks?
The V6 privacy addresses are typically only rotated daily but the space is so large that it could be done almost per connection of the stack and router could handle that. Realistic rotation limits are probably every few minutes.