IPv4 pricing
docs.hetzner.com
docs.hetzner.com
Stuff like this really hinders adoption.
$ dig +short a ec2.amazonaws.com
52.46.140.46
$ dig +short aaaa ec2.amazonaws.com
(no response) api.ec2.us-east-2.aws
https://docs.aws.amazon.com/AWSEC2/latest/APIReference/Using...So yes, this is a long story.
But that was a long time ago. From what I hear, things are different now.
In case of icloud, I attribute it to the Proofpoint spam filtering system, which also sell service to ups.com.
And even gmail, but at least gmail accept the email, then just flagged it as spam.
The irony here is that much of the inter-service traffic on the internet could already be sent over IPv6 without anyone noticing. Getting end users onto IPv6 is always going to be a challenge as, well, ISPs, but when my mail server talks to your mail server there's no need for this to be IPv4.
(I don't really know what I'm talking about.)
In other words, it's a Sybil-resistance mechanism, called Proof-of-IPv4. It works specifically because v4 addresses are scarce. v6 addresses are not nearly as such. Everything that makes IPv6 great for the Internet at large makes it terrible for mail providers. For example, because the original v6 design wanted to eat lower link layers, it reserves half the v6 address for an embedded MAC64. This never really panned out, but it's terrible for security, so every v6-capable OS nowadays will rotate addresses every few hours. The average machine will have hundreds of addresses. How do you assign a usable notion of per-IP reputation to that?
You could use v6 subnets for reputation, but there's still 64 subnet bits - enough to stick an entire IPv4 subnetwork inside of each IPv4 address. Some ISPs actually will assign a /64 per customer (because Comcast needs something to sell to Business customers), while others assign /56s or /48s. So there isn't even one granularity of subnetting that you can use for reputation tracking on v6.
Meanwhile, v4 pricing is getting worse and worse, which is great for mail providers. They don't necessarily need to turn a profit on incoming mail, but they do need to make it expensive for people who want to send lots of spam.
The problem of spam is actually solved, the problem is no one setups any of these security parameters correct, large and small companies alike all have bad SPF Records, bad or no DMARC, etc etc etc
If 99% of contacts you want to send mail to are on google/yahoo/microsoft you have to play by their rules. And those rules are effectively "send mail internally or gtfo".
I think maybe once in the last 3 years I ended up in someone’s spam box, total. In fact I just sent to a new gmail address and to a university I have never contacted before this week and both were delivered without issue.
Setting up DKIM/SPF/etc isn’t that hard and it’s fairly easy to verify with existing tools FYI.
Personally, I'm hesitant because I don't know if the end of all my effort will be constant blacklisting. If I could be confident that if I do it right I won't get blacklisted, I probably would.
Now most of them do not actually enforce it unless you become a problem, but most of them do put active measures on the network to stop SMTP Servers
For example here is a Exerpt from Comcast AUP prohibiting email and web hosting [1]
>>>use or run dedicated, stand-alone equipment or servers from the Premises that provide network content or any other services to anyone outside of your Premises local area network (“Premises LAN”), also commonly referred to as public services or servers. Examples of prohibited equipment and servers include, but are not limited to, email, web hosting, file sharing, and proxy services and servers;
[1] https://www.xfinity.com/corporate/customers/policies/highspe...
Why? Google Fiber is Available to less than 1% of US Households. Comcast is the largest Residential ISP last I looked in about 60-70% of US Markets...
ATT has the same policy, and I believe most of the other Cable Providers do as well. My guess would be over 90% of Residential Internet Plans today have a policy inline with Comcast not Google Fiber
Pointing to an outlier to the norm does not mean i need to update my worldview at all.
I looked for market share info on Google Fiber but was unable to find it. Mind sharing your source?
I was happy to move hosts to one that was considered trusted, but there was no way for me to know the IPv4 addresses the company had in the past, never mind if they'd been on a pertinent blacklist at some time.
Based on that I think it could work, but there are no guarantees that outside, historical characteristics won't screw things up for you.
The people that say "I Cant send anything" are likely trying to setup it up on a Residential or "Business" (which is really just a Residential with a slightly better SLA and less overselling) Internet Circuit... Not an Enterprise Internet Circuit
Hint: If they are trying to bundle TV Services with your Internet you are not on an Enterprise Line.
Even if you buy a dedicated IP from these services they still make is hard to impossible to send email on the circuit
Spam is an interesting problem. Assuming one self-hosts and makes their email address publicly available, then one can get a metric for how much spam is flying around. Eventually one will try to stop spam from coming to their inbox, and on doing so one might build a mental model for how the big mail providers combat spam and realize why one's emails are not being delivered. Then one might realize that one is sending mail that one would not willingly receive! And then take action to resolve.
In general though, there is some base effort to establish trust, and as long as you don't ruin it by sending spam, then you shouldn't end up on a blacklist. If you find that your IP was on a blacklist before it became yours, then work with the people that are blacklisting - but at that point it does become a bit of a job. I actually ran into an issue in my professional life where an AWS WAF rule started alerting on one of our own servers hosted in AWS because someone had previously used the IP for malware C&C.
Anyway - I will think on this and see if I can write something up. It's a good idea. My main concern is that there is a gap between the way I did things (sysadmin style) and the "new" way of doing things (containerized).
The issue people have trying to send mail is with the latter, where the email won't even show up in the spam filters, it will either be blocked by the mail system or silently ignored.
On my server, when I block a message due to trust, I reject the connection. When I block due to spam, the message is received but goes in the spam folder.
I get reports from Google/Microsoft/etc when other people try to send using my domains but their messages fail due to DKIM/SPF failures.
I just want to push back against the “it’s impossible to self host email” meme that seems comes around occasionally. Every time I’ve run into an issue there has been a solution.
Is that how Google/Microsoft/etc. do it too? If not, then your practice really doesn't matter. Most of my friends have an @gmail.com address, so if Google would pretend to accept mail from my hypothetical mail server, but instead just drop it on the floor, that's a non-starter for me hosting my own mail.
What I would like to get across is that self hosting is not impossible or unacceptably unreliable. If Google and Microsoft have policies that make it difficult to send messages to gmail or hotmail users, that isn’t a reason in and of itself that we should not self host. It’s a reason that we should work with Google/Microsoft to have better policies - but accepting things as they are and writing off self hosting as impossible is eventually accepting control of email by a limited handful of corporations, which I don’t think is a good thing.
Maybe thats why it works for you. Try making new one?
But...I've also been in the unfortunate position of leasing IPv4 addresses which were already blacklisted by various sources. It's not a terribly easy problem to solve if you need to contact customers NOW without using a 3rd party solution.
Unless you have a Commercial Line that has be specifically designated for hosting content then it is likely any IP you are issued is added to Google/Microsoft/etc Blacklist by the ISP. Most of them clearly spell out in their terms that running a Mail Server on the circuit is forbidden.
I recently made a presentation that has a full explanation of the techniques, why they exist and how they work, on Hetzner Cloud (from the original post):
https://nh2.me/recent/Running-your-own-mailserver.pdf
I find it very easy to configure with simple-nixos-mailserver (much easier than the manual setup on Ubuntu that I ran the years before):
https://gist.github.com/nh2/6814728dc3bea1508323e9bf2213c28d
Generating domains is fairly cheap though.
lsjfdlakj.com
There, I just generated a new one with a clean reputation. Just spend US$ 10 to register it and off we go.
It's the companies whom you rely on for email that are the worst abuser e.g. airlines need to inform you about delays and abuse this trust with holiday adverts incessantly.
Any company that claims to require your email for two factor auth should be given automatically generated fines for every email they ever send that is not auth related.
That would shake up Oracle sales dept. :)
The whole point of using a scarce identifier is to allow for a "neutral" reputation for new identifiers. If identifiers are less scarce, then known-bad actors can get free reputation (from bad to neutral) by just starting over with a new one. Which means that you have to distrust neutral reputation more. Without some level of scarcity of identification, introductions don't really work, because I have no idea if the new host I'm being talked to from today is just the one I banned yesterday wearing a different mask. This ultimately implies e-mail moving to some kind of federated whitelist system rather than the current system of federated blacklists.
e.g. when .com is on the list, and .somesite.com is not on the list, mail@somesite.com is from the same entity as mail@subdomain.somesite.com
From what I gathered from that, publicsuffix is a poorly-funded semi-volunteer org that shouldn't be relied upon for anything critical.
(Btw I’m pretty sure almost everyone is already using domain-based spam scoring.)
This also has a secondary problem for legitimate domain buyers. If the domain name they buy was previously used for spam that reputation will affect thier business for quite a while. There's actually a market where people buy domains with bad reputations, setup small legitimate businesses and get the reputation cleaned up, then sell the site domain and business for a substantial profit because a site with a good reputation history and established line of business will show up higher on internet searches.
would be very useful
(business opportunity here guys!)
What did you have in mind as far as a use case?
(for fraud detection it switches from block to identify)
for IPv4 this is generally the /32 (the single IPv4 address)
for IPv6 it's probably a /64, but may be a /56 or even a /48, and on some crappy providers even a /128
if the subnet is smaller than you think it is you risk banning an entire ISP (or country), whereas if if it's too large the abuse continues
it's quite a complicated problem as by design you can have subletting (subnetting!) within a block, e.g. a VPS provider gets a /48 from its ISP, and then they sublets out /64s to their customers (while not necessarily giving them all their own RIPE/ARIN records)
The other aspect is that a decent chunk of the IPv4 space at least is fairly dynamic. We've seen some blocks change owners every few weeks.
if i spent like a hundred bucks or something, i dont know... just asking. how would that work, does that "bring your own ip" that vps providers talk about mean this?
i
In pactice you cannot have less than a /24 because nobody will announce less than a /24
Edit: Seeing your use-case, this should probably be part of the whois records.
absolutely, assuming people subnetting to their customers delegate the space in the whois accordingly
(they do have an incentive to do that -- prevents all of their customers being banned if one misbehaves!)
Treating individual v6 addresses like individual v4 addresses is silly and nobody serious will take that approach.
You can use cloud providers, sure small ones do get blacklisted (which happens to also benefit Microsoft as they also are a cloud provider) but they can't really blacklist Googles or Amazons Cloud.
This is what is hindering adoption everywhere to be honest.
All of my forums, wikis, and game servers reject ipv6 purely for the same reason.
FWIW, I actually have residential service from Comcast and they'll assign you a /60 if you request it. I then use /64s for my subnets/VLANs.
You don't and that's the point.
Stop bloody tracking me.
What should you as a mail provider do with this new information?
Oh I dunno, innovate?
I've completely given up to try to get my personal mail server delisted, as I can't even get Microsoft to tell me why they blacklisted it in the first place.
Instead I'm nowadays just rejecting all incoming emails originating from Microsoft with a message telling the sender to use another non-Microsoft email account.
It's just stupid. I never had problems with any other mail provider, but trouble with Microsoft as long as I can think of.
Link: https://support.google.com/websearch/workflow/9308722?hl=en
(For example Microsoft has blocked whole IPv4 ranges of cloud providers (i.e. Microsoft Azure competition) for E-Mail, supposedly because of abuse. But all cloud providers are used by people "producing bad mails" and somehow only small to mid-sized ones are blacklisted while e.g. Google or Amazon are not and to be clear that had not been cloud providers in some arbitrary small country but e.g. the EU).
$ host hotmail.com
hotmail.com has address 204.79.197.212
hotmail.com mail is handled by 2 hotmail-com.olc.protection.outlook.com.
$ host hotmail-com.olc.protection.outlook.com.
hotmail-com.olc.protection.outlook.com has address 104.47.57.161
hotmail-com.olc.protection.outlook.com has address 104.47.58.161
On the other side, if a host announces that they have an IPv6 address - do you think they do it mostly for spamers? $ host gmail.com | grep handled | head -n1
gmail.com mail is handled by 5 gmail-smtp-in.l.google.com.
$ host gmail-smtp-in.l.google.com.
gmail-smtp-in.l.google.com has address 173.194.73.27
gmail-smtp-in.l.google.com has IPv6 address 2a00:1450:4010:c1c::1aI've been on FiOS for almost 10 years. Every few months, I check to see if I or any other FiOS customer has IPv6. It's been on in one testing market (or two) for years, but nothing else outside that.
I first discovered this when I started presenting a terraform demo from home, and it broke because at least one of the AWS modules didn’t support IPv6. When developing I only used my Xfinity connection, which gives an IPv4 address. Apparently my laptop had switched to my other wifi Network right before the presentation. Luckily the interviewer was understanding, and we used the experience as a troubleshooting exercise.
I'm also on FiOS, in a major MSA, and nope, IPv4 only.
Any day now...
Claiming that they don't see a return on investment is equally silly. Most ISPs have rolled out fibre, or new equipment in the last 10 years. They could just have rolled out IPv6 when new equipment came online over the last decade.
Maybe the ISP deliberately bought equipment without IPv6 support, like we did, but by accident. Two years ago we bought new Cisco equipment, for a remote office, only to discover that there where no IPv6 support. So back to Cisco it went. Why did Cisco even bother to make network equipment that doesn't support IPv6?
Still, it's better than IBM who claims IPv6 support in their software, but haven't bothered to test it the last 7 years, so it doesn't actually work in the current versions.
I just googled Terraria IPv6 and this is the first result I got:
https://www.reddit.com/r/Terraria/comments/cytn2w/terraria_p...
Yeah, people ask you why you are using IPv6 as if ISP customers get to make that decision...
I just switched to full dual stack (by leasing a static IPv4 address from my provider) to be able to handle incoming connections for my VPN. As long as you don't want to host anything on IPv4, dual stack lite is fine.
The same reason credit-card payment terminal people sold almost-EMV terminals to retailers in the US around 2010-2015: so their customers will come back 5 years later needing another upgrade to something they should have bought originally.
In other words: the demand is for connectivity--or rather the services being connect gives you, like the ability to view YouTube videos and see tweets--not for addresses.
It's not circular logic, it's no loose ends.
Reminds me of a story in The Dragon Book. (compiler design book from the 1970s) FORTRAN IV doesn't (didn't) allow arrays with more than three dimensions. Because programmers didn't write programs using arrays with more than three dimensions. Programmers didn't write programs using arrays with more than three dimensions because the compiler didn't allow arrays with more than three dimensions.
I say miraculously, because most of the rest of the ISPs in my country have "experimental" IPv6 "coming soon". Any decade now. Any decade...
I do VPN from the router, giving me a proper /64 block...
All in all, I had so many troubles with setting up anything behind IPv6 or DS-lite, that I asked my ISP to give me an additional IPv4 address, so that I don't have troubles. While they usually provide bad service, this came for free -- but other ISPs, for example my parents' ISP, want you to pay 50 or more euros per month for an "enterprise contract" to get a dedicated IPv4. I still haven't found a way for my dad to setup his old webcam server at home such that others can reach it from the outside world, and I tried every couple months over the last 6 years or so.
For example when the webcam server is reachable on LAN at 192.168.1.2:1337 you can do
$ ssh -N -T -R 1338:192.168.1.2:1337 user@cloudserver.com
on a raspberry pi on the same LAN or locally in the webcam server and then you can access the webcam server from anywhere using cloudserver.com:1338
At least I ran into this frequently (multiple times a week, I really need to fix my sleep cycle).
Not affiliated, just a happy user.
But for many other thinks there are to often to many problems including bad availability of speeds about 50Mb/10Mb and they still selling you faster speeds which technically can't be delivered.
And for many areas of Germany it boils down to:
- If you live in a city and only go for 50Mb it's often ok (but even in cities there tend to be areas with faulty installations causing problems for the citizens in that area for years, e.g. my sister and a co-worker of mine had/have that problem).
- If you live in the metro area but not in the city it's spotty sometimes going with LTE is better, sometimes it's not, sometimes you should by both to make sure at least one of them works (my former co-worker had that problem).
- If you live outside the metro area it's random either you get reliable reasonable fast internet if you buy from the right provider or you get less then 1Mb no matter what provider you choose (multiple of my friends had/have that problem).
Usually happens if the customer's computers connect to the Comcast gateway directly. If they have their own router, it usually gets an IPv4 address.
Without passing judgement on a) medium.com articles, b) Comcast or c) pfsense here is an article that covers making IPV6 work in that specific instance. https://circuitguy.medium.com/home-network-virtualized-pfsen... - Worst case scenario someone can take this and adapt it to opnsense or their OS of choice.
This is done because many routers were built with bad IPv6 support that requested a /48 even though they only needed a single /64 for a LAN and Comcast was handing out /60's (their largest size) like candy with almost no use.
So my config was to request two prefix delegation, one tagged 0, which would always get a /64, and then one tagged 1 which would get a /60.
Not sure if you still can do it or not, but at one point you could continue to ask for prefix delegations (/60's) and get even more address space.
Here's the dhcp6c.conf:
interface em0 {
send ia-pd 0;
send ia-pd 1;
send ia-na 1;
};
id-assoc pd 0 {
prefix ::/64 infinity;
prefix-interface lagg0 {
sla-id 0;
sla-len 0;
};
};
id-assoc pd 1 {
prefix ::/60 infinity;
prefix-interface vlan10 {
sla-id 1;
sla-len 4;
};
prefix-interface vlan11 {
sla-id 2;
sla-len 4;
};
prefix-interface vlan20 {
sla-id 3;
sla-len 4;
};
prefix-interface vlan21 {
sla-id 4;
sla-len 4;
};
prefix-interface vlan22 {
sla-id 5;
sla-len 4;
};
};
id-assoc na 1 {
};
Note: ia-pd 0 will only ever pull a /64, even if you ask for a /60 all you'll ever get back is a /64. ia-pd 1 on the other hand will allow you to pull anywhere from a /64 to a /60.Yes, this means you get 16 + 1 /64's to use.
On top of that I pull a single /128 for the external interface of my router.
I personally don't think there is an issue with handing out /60's like candy, but I am not Comcast and can't speak for their network engineering team which made the decisions they made for their millions of customers.
And this is well known in the industry. The IPv4 world has had enormous mapping and trust ratings and understanding -- coupled with a scarcity that gives range owners or operators a higher incentive to care about what happens on it -- while a lot of people are still completely in the dark about IPv6 and still treat it like some scary unknown.
Indeed, and residential ranges are wholesale blocked from participating in various services, because of abuse through compromised hosts in residential networks.
Budget cloud providers are wholesale blocked from participating in various services, either at thier local edge, or the remote edge, because of abuse through deliberate malicous customers and/or compromised hosts.
I have Google Fiber, and I can't say I get a ton of captchas (other than sites that have them for everyone, e.g. unauthenticated contact forms). The only downside to v6 was I had to get a new router because my old one couldn't route v6 at gigabit speeds (could easily do gigabit symmetric on v4 only, but topped out at 400/400 Mbps on dual-stack).
Back when I had Spectrum (which was Charter in my area pre-merger), their v6 worked fine as well.
If your ISP uses CGNAT for IPv4, then Walmart could fix the captcha problem by supporting IPv6, where your address is distinct from the bots.
Walmart uses a litany of external services, presumably including real-time threat/bot analytics. For instance AdobeDTM, which does indeed serve via ipv6. It seems possible that IPv6 could be playing a part regardless of the status of the base site. These bot gates aren't at HTTP responses, but are in client interrogations and javascript triggers while interacting with the page.
Many IPv6 addresses could be mapped to a single IPv4 gateway address, causing the trigger.
This is utterly bonkers. While the ethernet cables they give out can likely do 10Gbit (but definitely not 25Gbit) very few people have 10Gbit-capable ethernet or wifi chipsets and there is no way they will actually be able to routinely transmit data at this speed.
Swisscom do 6rd and don't offer static IPv6 either presumably because of how 6rd works. So it is a pain to configure anything except using their own box.
Bit of future proofing, the fibre cables will be in the ground for 10 years and who knows whether consumer devices can routinely do 10G by then. The cost is dominated by the price of digging up the roads, not by sticking a few extra strands in the ducts.
It just feels a bit dishonest to sell a 10G connection and tell the user to speed test on the router's web portal when their PC won't get remotely near that.
I've wanted to switch to init7 for a longtime, but Green's service and price is hard to argue with.
(Through to be fair you get 50/10 for 30€/Month without limit.)
Offering connections in the Mbit range anno 2021 _is_ bleak, compared to some countries.
This paints a pretty good picture: https://tweakers.net/ext/i/2003127256.jpeg, which comes from this article in 2019: https://tweakers.net/nieuws/158414/aanleg-van-glasvezel-naar...
Plenty of places here are stuck on some form of broadband.
You know what's not great? I live in a new building. It was built in ~2015. It's not even on Google Street View.
They decided to go with a commercial solution ("digitalStrom") for Ethernet that caps out at 100Mbit.
I now have to use Wifi to get anywhere close to the 1Gbit I pay for. The lack of forethought (or the grift for the company that bought that tech) is astounding.
Thank god I only rent.
But I wouldn't be surprised if my 50mbps connection is as expensive as your connection, presumably while offering worse service.
- You often only get it in city areas, I say city areas because metro areas include small settlements around the city still connected with the metro. And in many experience it's quite likely the best you can get in that settlements is either way less or unreliable high latency LTE.
- There are faster contracts like 250Mb/40Mb for 45€/Month but availability is spotty, and companies will sell it to you even if not technical available. E.g. most 100Mb contracts say serving 60Mb would still be "valid" for your 100Mb contract.
- It's not uncommon that many DSL of different people will go through choke points in areas with high population density but not that much money, so speeds dropping sometime randomly noticeable are not uncommon.
- It's common that if there are technical problems (which are not uncommon when switching providers) it can take days to fix them, my previous (small) company went a month without proper internet connection due to this, they fell back to using a LTE router temporary but they had to buy it themself it wasn't provided by the internet provider.
A good point is that all the internet contracts tend include a land line phone number and tend to have "unlimited" data volume (which isn't always truly unlimited, but close enough to unlimited).
Frequent stories include internet being so bad that it frequently is short term temporary(<15min) unavailable, randomly temporary super slow internet, or a supposedly 100Mb internet connection frequently slowing down to close to 1Mb causing video conferences to fail. And that is in the city.
Outside of cities it's common to have insanely slow internet all the time to a point that people fall back to use LTE->WLAN routers, but then it's common to hear that the LTE is frequently overloaded around "rush hours" making people at the "outer ranges" of the closest LTE tower lose connection.
The state of the German internet infrastructure is kinda a sad joke.
Through I should note that things differ depending on the area of Germany you are in.
Anyway the best thing I can buy (and get) in my area (in a relatively wealthy area of Berlin) is ~60Mb/10Mb connection which is somewhat reliable (fails 0-4 times every day for ~1-5min each, but it only happens between 2am and 6am, so ok, not a problem and at least one failure is probably the router).
EDIT: Just to be clear the biggest joke are not the ISP's but the politicians which let themself be bribed not only to tolerate but actively support this situation. Through it's also incompetence not to long ago some politician responsible for making regulations in this area stated (and believed) that ???Kb (forgot the actual value but it was less then 1Mb) is high speed internet. It's sad if politician are stuck years in the past and are so arrogant and incompetent that educating them about their mistake is destined to fail.
https://www.tagesspiegel.de/berlin/600-000-anschluesse-bis-2...
(giggle)
I monitor my internet with Grafana and can provide stats for these problems for the past few years...
IPv6 is also common. In case of DS-Lite you don't even get your own IPv4 anymore.
But yes it doesn't make sense for local wiring at all. 1Gbit-capable LAN cabling is cheap and ubiquitous. On the other hand it sounds like you have wired ethernet in your building... that's also quite unusual. Mine (70s) does not :)
That is suprising, why? Can most people even use that much speed? Netflix only need so much bandwith. Good for homelabs, just most people don't have them.
Personally I'm using as a provider "solnet.ch" (I'm their customer since a very long time and so far I'm very happy with them - it's a small provider headquartered in the canton Solothurn, but my connection originates from the canton Zurich), and so far it doesn't seem that they'll offer IPv6, so this matches your statement.
On the other hand, if I remember correctly, I think (not sure and I cannot check this now) that I did have to modify my DNS configuration of my email server related to IPv6 when my parents changed from Swisscom to Sunrise (in 2020 or 2019 - my mother uses my email-server and the IPv6-entries weren't configured correctly) => can it be that Sunrise is using IPv6 as well, at least partially?
I might be wrong, especially regarding what you mean with "natively" (maybe you mean that customers get "only" an IPv6-address, the access to the IPv4-network being fully relayed at the ISP-level?).
Customers actively have to opt in to 6rd on Swisscom and actively have to set up hurricane electric and other IPv6 tunnels. Which means connectivity is limited to people who are going to do that, so service providers on the internet must offer IPv4.
1. Mandate that all ISPs have a fully functional IPv6 assigned for each IPv4 given to customers. It must route just as their IPv4 does. If a customer doesn't have an IPv4 number, they must assign as many IPv6 as if the customer had one IPv4. 1. Mandate that all servers and all services accessible over IPv4 be accessible over IPv6 1. Institute sufficient fines for businesses that don't follow these requirements.
IPv6 doesn't make anything go faster, or let customers access anything they can't already access and quite likely it will make difficult to diagnose networking problems which break stuff (speaking from personal experience with IPv6 here!).
I don't think ISPs will be motivated to give out IPv6 addresses routinely until there are important areas of the internet which are IPv6 only. Until that point they would just be making more support burden for themselves.
And I can't see important stuff going IPv6 only any time soon since you don't make a new and exciting service which the majority of people can't access.
[0] https://www.reddit.com/r/usenet/comments/k9aqjy/newszilla6xs...
"It Just Works."
And I don't mean only the cost of running it, in my country for example by law the ISP has to maintain a log for 5 or 10 years of all the IP addresses assigned to the user, and in case of a NAT even of all connection and source ports associated with each client. That is a cost that you will save with IPv6, just assigning an entire /64 subnet to every customer.
Of course you will start to save money at the point where we can switch off IPv4, that is not something we will see tomorrow, but if we don't start, the problem will not become better with time, but worse.
IPv6 is an investment for ISP, more than customers (that it's not true they don't care, they maybe don't understand the technical details, but when they find out that they can't play online with their PlayStation/Xbox because they are behind a NAT, they will complain to the ISP).
I don't see that at all.
Everyone still needs an IPv4 to the outside world for compatibility, and pretty much all the time 24/7, so they wouldn't be saving money at all.
And why do they need a NAT? My NAT only happens on my personal router, not at the ISP level. It's not something that concerns the ISP at all.
So I don't understand any of the motivation you're describing.
(And if there are legal requirements around recording connections and ports and whatnot, you'll still have to record each connection made under IPv6 as well right? And may I ask where you live that every TCP connection you establish gets logged for 5-10 years? Recording your assigned IP address is one thing -- and for most people's home connections it rarely changes -- but I've never heard of recording every connection.)
One small thing, though:
> My NAT only happens on my personal router, not at the ISP level. It's not something that concerns the ISP at all.
"Carrier-grade" (what a laughable term) NAT exists. You are fortunate that your ISP does not implement it. Do you happen to have a business plan, or a gigabit plan?
There is also ds-lite which I've read comcast uses extensively. Here customers get ipv6 addresses only, and share a pool of v4 addresses when they exit the ISP's network.
No I've never had carrier NAT. People often need to connect to their home computers from the internet for various purposes -- remote desktop, media server, SSH, NAS, printing, whatever -- which carrier NAT wouldn't allow, as far as I understand it.
I understand ISP's don't want you running high-traffic web servers on a home contract, but I thought it was still considered essential everywhere to at least be able to connect to your personal IP address from the internet for personal usage. (For home internet -- not mobile, obviously.)
Yes! CGN, asymmetric bandwidth plans, dynamic IP addresses, they're all treating the customer as a consumer. As if it's just a cable hookup. It's a shame, really. CGN shouldn't exist.
UDP "hole-punching" would still work with CGN, but in most cases you would need cooperation of a third party. There are also trickier ways like what samy.pl/pwnat does.
I'm on FIOS in NYC now, but when I was on optimum and spectrum they both gave me IPv6 delegations and, as far as I could tell, they never changed. Honestly I would not have switched to FIOS in hindsight -- it's not much better and I don't think I'll ever have IPv6 :(.
The world moving to IPv6 helps them, since they can then use the internet equally, running servers, remote desktop, etc.
> And may I ask where you live that every TCP connection you establish gets logged for 5-10 years?
The EU started doing this, then removed the obligation, then decided it was a threat to democracy and banned it [1]. But since Brexit happened, the UK can continue with whatever they're planning [2].
[2] https://www.wired.co.uk/article/internet-connection-records-...
[1] https://www.privateinternetaccess.com/blog/eu-supreme-court-...
Is this really true/correct?
Assuming that an ISP would implement a pure IPv6-network for its customers, wouldn't their customers by typing on their PCs e.g. "ping 1.2.3.4" in their terminals be routed automatically through "[internal IPv4 network between customer and ISP] => [ISP's public IPv6 address in Internet being translated to their SINGLE allocated IPv4-address] => [target's IPv4 address]", and then back (to get the ping-reply)? So, some kind of "magic" IPv4[internal customer]=>IPv4[internal ISP] => IPv6[external ISP]=>IPv4[external ISP] => IPv4[target], using NAT or however it's called?
I'm absolutely not good in relation with networking, especially not IPv6 (in theory simple, that was at least the tone of the articles that I read a few years ago, but at that time it has been quite difficult for me to set it up on my root servers), so what I just wrote might be plain wrong :P
Yes, but a more and more services pass to IPv6 you can start to resize your IPv4 infrastructure, and arrive at a point where you will switch it off entirely, as it was done for the transition from analog television to digital one (of course we talk about at least 20 years, but if we don't start it we would never see it).
> And why do they need a NAT? My NAT only happens on my personal router, not at the ISP level. It's not something that concerns the ISP at all.
They need a NAT because they don't have so many public IP address to give one to each customer. So they introduce a second level of NAT, where a group of customers share the same IPv4 public address. That of course causes a lot of problems, especially for online gaming where it's required to open ports, or in general for applications that use p2p protocols.
And so if you want a public IP address dedicated to your connection you have to pay more. I don't know the situation in the US, perhaps your IPS have a ton of public IP addresses they purchased in the past so they can afford to assign to each customer one dedicated address, in my country it's no longer the case with most home connection ISP (and all the mobile ones).
> (And if there are legal requirements around recording connections and ports and whatnot, you'll still have to record each connection made under IPv6 as well right? And may I ask where you live that every TCP connection you establish gets logged for 5-10 years? Recording your assigned IP address is one thing -- and for most people's home connections it rarely changes -- but I've never heard of recording every connection.)
No you don't. The law requires you be able in case of a crime to identify the customer that originated a particular connection. It means that the police goes to the ISP with the time, IP address and source port of the connection and the IPS has to tell the identity of the customer. The method how this is achieved depends on the technology used.
With an IPv4 with public dynamic address, they have to maintain the log of the PPPoE connections, to know at one time the customer that had that address. Not that difficult.
With an IPv4 with a NAT, a group of users shares an address, thus the information of only the address is not sufficient to identify the customer that did that connection. So they have to log all the connection opened by the customer, so they an know, from the IP address and the source port of the connection from which customer originated the connection.
With IPv6, you don't have any of these problems. With so many addresses you can just statically allocate a /64 block of IP addresses to each customer, and basically don't keep any dynamic record.
Of course it's also better for the customer since he has a static IP address if he wants to self host something at home, without using unreliable dynamic DNS services. And nowadays with all the new IoT and domotic stuff having a public address is important (for example just think about accessing security cameras remotely).
Flets is most popular FTTH service that available nationwide by telco. Traditionally it only provides IPv4 service via PPPoE, but the architecture is inefficient and getting old so they started IPv6 service directly on Ethernet (called IPoE, a bit funny). VoIP Telephony service is also provided by IPv6 so the network called NGN.
Now the traditional PPPoE service is getting very slow due to they won't invest very well for old architecture equipment. Instead, they advice to use IPv6 IPoE for faster connection. For IPv4 connectivity, ISPs offer v4 over v6 solution like DS-Lite, MAP-E, and 464XLAT for home (shared v4 address) or IPIP for dedicated v4 address.
Many people use both IPv6 IPoE (fast) and IPv4 PPPoE (slow) because their router don't support v4 over v6, or just prefer dedicated IP for lower costs (like me), so it's important for service operator to enable IPv6 connectivity, to provide faster service. Please support IPv6!
I've been using ipv4 because I use LTE with ATT or TMobile links for the past 7 years (RV full time) and I can't wait for a modern internet connection that doesn't suck.
But there's no support for that. So every time I spin up a 1 vCPU tiny VM, which will never connect to the public internet, I'm wasting an expensive resource. Sorry.
Their margins are low, however, so I understand it is possible to get fired as a customer if your support burden is too high and your ROI goes negative, so be on your best behavior to keep access to those prices.
That's not a nice statement.
It sounds like Hetzner will cancel your contract as soon as you submit a support request, which is not true (I personally opened in ~May 5-10 tickets within a few days when trying to boot from UEFI).
I really do not think that they track single customers in relation to their single ROIs.
I don't know what gave you that impression, as that was not my claim.
We've experienced some networking issues, usually not on the Hetzner network, but there have been some peering issues with some ISPs over the years. Generally nothing too bad.
Their Cloud API is a joy to work with. It obviously isn't anywhere near as future rich as AWS, but it's got everything we need, and we can spin up VMs with a couple of simple HTTP requests.
Anyway just fyi:
currently having 2 root servers in germany and 1 in Finland.
If I remember correctly I had within 8-10 years at least once a full unexpected shutdown of a server (don't honestly remember how long in took until it was back online, it was a few years ago).
A few weeks ago I could not reach for ~4 hours my (new!) server in Finland from my own Internet provider at home (it was super weird - I could ping any other server in Finland/world but not the Hetzner stuff) but at the same time it was absolutely reacheable from my mobile phone and from other ping-test-sites in CH and D => interesting, probably something to do with my ISP but I'm wondering why exactly my Hetzner server was involved, mmmhhhh... .
Maintenance downtimes (few) are scheduled and communicated by email.
Throughput is good - currently writing a web crawler and I can go up from time to time to at least 50MiB/s download if I want to (BUT I try to be "nice" to not get banned :) and anyway my processing queue cannot currently keep up with that rate).
Support is good - servers in Germany want tickets to be written in german, servers in Finland want tickets to be written in English. Both are fast (e.g. initial reaction time usually max ~1h to pick up a ticket, answers to replies usually within minutes), german support can be verbose, finnish support wasn't at all in my case (e.g. if you ask "I have problem X because blahblah so I was wondering if maybe boot on disk #2 is disabled in the BIOS?" they might just reply with "boot activated").
About HW replacement: I had so far only 1 HDD failure (some years ago, in a classic mdraid5 array) => I opened a ticket and pasted the proof of the drive failing together with the output of "smartctl" to identify the drive => got a reply asking for a downtime => agreed to the downtime and shut down the server at that time => drive was replaced and the server was booted => I then resync'ed the mdraid and that was it.
About HW upgrades: opened a ticket asking details about feasibility & pricing => got back a statement 1-4 hours later => sent back a reply agreeing to it => I was asked a few minutes later by the tech team "when" to perform the upgrade => I replied "now" and shut down the server => a few minutes later the server was up and running with the extra 32GB RAM.
So, all in all, as you probably understood, I'm currently happy with them. The costs are ok for me (especially for the servers that have >=10 HDDs - is there a better offer anywhere, honestly asking?), the reliability of the infrastructure is good, the support is good.
I was before (many many years ago) at OVH (good support + reliable, at that time) but it then became very expensive therefore I left them. Nowadays they have a more differentiated offering, but it looks messy to me, and bigger servers like the ones that Hetzner offers (e.g. 8+ CPUs with 3+ HDDs and 1 NVMe/SSD) seem to be extremely expensive to me.
Cheers
Working with them is nice, the APIs are a breeze, and are really dirt cheap. And they take security very seriously.
Also, some services, like, say, DNS servers need long-term portability of specific IPs across multiple providers.
I do both, actually on Vultr.
Unless they're TCP services. Or stateful UDP services. Then you're in for a world of pain if you try to anycast them.
The list of sensibly anycast services is surprisingly low. Stateless UDP services, essentially, which isn't a big list. Especially if you're the kind of person who's using Vultr's cloud, and not a megacorp.
If you have the resources to develop backend state sync, you're probably still better serviced with a (set of) load balancer(s).
I run a CDN with anycast BGP, this obviously uses TCP. Works great. I've also done it with a global network of physical datacenters and our own transit/peering network but eventually migated to the cloud for reasons.
Who am I kidding? As far as I remember Lisp Machines were the size of refrigerators :-D
As a tech entrepreneur, I run multiple popular websites that have hundreds of thousands of users. I get emails from users daily. With congratulations, feature requests etc. So far, nobody ever requested IPv6 support.
I have no idea what would happen if I enable IPv6 on my servers. Probably some desaster would strike because some of the code expects xxx.xxx.xxx.xxx style IPs.
What would be the steps to test this? Run the application locally in a Docker container and somehow make the requests to the container go over IPv6?
It would be rather unusual to run a web stack that assumes strictly IPv4. Maybe if you have an SQL field that logs IPs, and a developer was very clever and optimized for IPv4, but that's pretty rare.
I am a strong advocate of IPv6 and early adopter, but would never bother emailing a website about it. Even GitHub. For a long time, AWS didn't have any IPv6 support (I'm sure it's part of their business plan too, to charge extra for IPv4 eventually).
As a hosting provider, the main benefit of IPv6 is that I can have unique IP addresses for my users. Nowadays, most people on mobile and more and more ISPs use a very small IP pool (CG-NAT), not to mention offices behind NAT (ignoring very large offices who use proxies).
But since my dev environment runs in Docker, how would I test IPv6? I did some googling now and it seems that would not be an easy feat.
docker run -p 127.0.0.1:80:80 ...
But with an IPv6 address? Which address would I use?
Although I don't know at what point that will test your application. I guess it will at least make sure that it can handle IPs such as "::1".
docker run -p [::1]:80:80 ..
And then how do I send a request to the container? I tried like this: wget 'http://[::1]:80'
But that gives me "connection refused".so you are already testing it :)
I get the same result when I run "ncat -6 -lp 80" inside the container and try to wget from the outside.
When I do the wget inside the container, I get "Connecting to [::1]:80... failed: Cannot assign requested address.".
As I said, reading around the net about "docker ipv6", it seems Docker is not IPv6 ready out of the box.
Docker's documentation explains how to assign an IPv6 subnet to Docker: https://docs.docker.com/config/daemon/ipv6/ and https://docs.docker.com/network/bridge/#use-ipv6
You then can lookup a container's IPv6 address using 'docker inspect' and then directly connect to it from your host.
Docker's documentation
Yes, I looked at it and that is what I referred to with "No easy feat".I assume your scenario is that you don't currently use IPv6, so you probably can't assign a subnet of your /48 block of IPv6 range to be routed to your docker host. You can probably use a subnet from a reserved range in that case, for example from: https://en.wikipedia.org/wiki/Unique_local_address
With that new subnet set up, you would at least be able to test the services running inside containers from that host itself.
In my own experience I never encountered services that don't work with IPv6 at all, but as others mentioned the most common issues are with truncated addresses in a db column designed for IPv4 or log parsers that refuse to match on IPv6. Worst case I found was a log based rate limiter that ignored IPv6 addresses and therefore let all requests using that stack pass.
If, for example, you limit a user to one concurrently used account per IP (which some gaming sites do to discourage cheating/griefing by one person playing multiple players at the same time), this breaks.
This can also be revenue relevant if e.g. the ability to have multiple accounts per IP is a paid feature.
> So far, nobody ever requested IPv6 support
I have actually put in feature requests for v6 support before (probably not your stuff, since I have no idea what you work on).
That’s the same reason i gave up and disabled ipv6… i think i might be too old to wrap my head around it. Ipv6 seems really complicated to setup compared to ipv4.
You can say that ZFS/BTRFS are more complicated than XFS/EXT4 + device mapper, but while it may be slightly more complicated, the more important thing is that they are different.
It took me a while for IPv6 to "click". I still don't like a couple of RA/NDP related settings, but it works and is much much easier not to deal with NAT.
Personally I find it a lot more complicated, and not just because it is different. Part of it is inherent complexity, part of it is that it's still evolving as a specification, part of it is ISP's not following best practices, part of it is lacking software support.
I'm trying to keep IPv6 enabled. But every few months I hit some issue where IPv6 is the reason stuff stops working or I can't get something to work, and it's just oh-so-tempting to switch off IPv6.
"You will find that on the LAN host, their default route and gateway point to the Link-Local address of the machine acting as the IPv6 gateway/router. This is entirely normal and expected."
If you run your own ASN, you'll probably get a /32 IPv6, then the shortest possible address is even shorter than with a /24 IPv4:
xxxx:xxxx::
is shorter than
xxx.xxx.xxx.x
Of course, for privacy, you're supposed to get a randomly-generated 64bits, but you can disable that setting in your favourite address, and use static addressing.
(Although there's no mention whether HCloud ipv4 pricing is actually affected by those changes)
CX11 goes from 2,49€ to 3,49€ excl. VAT, CPX11 from 3,49€ to 3,99€.
New Floating IPs will also cost more from 1st August - 3€ instead of 1€.
This does not affect existing instances and existing floating IPs.
Source: Received an email from Hetzner as a customer with the affected instances.
https://lists.freebsd.org/pipermail/freebsd-hackers/2013-Apr...
IPv4 was added a few weeks afterwards.
Realistically adoption will slow down if nothing changes, everyone willing to put the effort in for zero immediate reward has already done so, and some will allow their support to degrade due to low usage.
At some point I guess ipv4 availability will really start to collapse and adoption will speed up again.
Not sure which will come first to be honest, but better if adoption is relatively high when the shit evebtually hits the fan, to avoid the temptation of insane NAT solutions.
[0] https://www.potaroo.net/presentations/2021-03-02-ipv6-deploy...
Or someone less tech savvy but legally savvy figures out that IPv4s are scarce resources, just like, for example, housing, and finds a way to impose their use through regulation in some contexts and to ban their use in other contexts.
I think this will be more like a linear function. As the IPv4 prices increase, the IPv6 adoption increases until it reaches 100%. I don't think that there will be a collapse.
I'll say one thing about Comcast in the US: they have atrocious customer service, scummy upselling, and that horrid wi-fi network sharing... but they do 2 things that mean I'll forever give them a free-pass:
1. They have CBC channels in the US so I can watch the Olympics without watching NBC's horribly dumbed-down, artificially time-shifted, and condescending feed.
2. They have a rock solid IPv6 network for everyone.
ipv6.google.com works on my side, as does www.google.com over IPv6 just fine, too.
I just checked all the FAANG websites, and it appears that www.amazon.com is the only one that doesn't have an IPv6 record.
And to think that 20 years ago I had /16 for free and did not even think to keep it. I always thought IPv6 is just around the corner.
NAT has been so successful, that IPv6 is shocking to users who cannot even fathom why public traffic is being introduced to what was 'supposed' to be a private network.
This leads to some very peculiar traffic being routed around. For example, some kind of Logitech gaming driver is broadcasting a constant of packets with someone's PC stats to my publically reachable desktop/server/laptop, because the software thinks it runs behind a trusted NAT. There's also a HUGE amount of devices you can connect to if you open the Windows network overview because everyone clicked "home network" when Windows asked them what kind of network eduroam is supposed to be.
It's funny how scared people are when they realise they're not behind any strict firewall. They all know they shouldn't be disabling the firewall on their devices anyway, or so they claim, but this method of networking still instills fear into people as if NAT is a security measure (NAT slipstreaming works, NAT is not a firewall!)
This is a false meme right up there with "docker is not a security boundary".
If the router is configured as both NAT (SNAT) and firewall, it will drop such packet as not associated with any existing flow, but if it is just configured as SNAT, then such packet would be just forwarded inside unmodified.
(Also there is no requirement that you use RFC-1918 addresses behind NAT.)
NAT was never designed to be a security boundary and should not be considered one. It's only a matter of time until the next NAT slipstreaming attack is discovered. That doesn't mean your computer is in some kind of immediate danger or that you should cut your internet cable right now, of course. It's just good to know what does and what doesn't work when it comes to your network security and why IPv6 changes very little.
In fact, I'd argue that most IPv6 routers are actually more secure than IPv4 NAT because incoming traffic will never be translated as if it came from your router like some NAT implementations do, and incoming traffic is usually always blocked. The lack of a need for parsing and interpreting network packets makes your firewall a lot easier to reason about.
Docker is not designed as a security boundary, but it does provide some security functionality if used correctly that would otherwise be a pain. Sticking something in a docker container and just running it as root is dangerous, but Docker makes it easy to apply strict, complex security measures, which its security bonus comes from.
NAT is the opposite, it's supposed to work like magic. That's why network protocols like UPnP were invented, not to automate firewall management, but to make application use transparent to the user.
After reading up about public IP addresses I realised that my (Dutch) ISP has also provided me a public IP... and that the Netherlands has a lot more IP addresses per capita than most European countries.[1]
1. https://www.ripe.net/participate/meetings/roundtable/january...
The danger associated with public IPs is not that high as long as you use software that binds to localhost instead of 0.0.0.0 for network services or use a firewall on your PC. The problem is that many software developers don't expect end user devices to be reachable from the internet so security practices are sometimes lax.
The Windows Messenger Service alerts that you could make pop up with a simple command-line incantation, you mean?
> It was such a common thing, and the only fix was to turn off the service altogether in Windows XP.
What? Nooo, don't do that! This meant no more cool "There, almost done. Lunch in five? /CRC" messages on your colleagues' screens.
NET SEND * "You are broadcasting an IP address!"Each had their own PC and direct, symmetric 100Mbit/s access to the Internet with public IP and no filters whatsoever.
I don't understand the idea of having arbitrarily limited amount of numbers and selling them. A lot of companies just got them for free and are now selling them for huge bucks because rather than do what I did -- return public good you are not using -- they decided to hog it until such time it becomes scarce good.
https://news.ycombinator.com/item?id=14855347
Now it looks like I was wrong and we got just about 33% and the curve seems to flatten already:
related: major indian telcos like Jio and Airtel are rolling out CGNAT.
And these are companies with more IPv4 than your carrier most likely.
Suppose you're a "big" ISP in Norway. Maybe you have almost half a million customers, and your corporate growth plan says you want a million customers by 2030.
Your engineers need a way to address all the backend infrastructure on your network. So, they give it all 10/8 addresses. No problem. "Do you need IPv6? Our customers are saying they want it?" "Not really, put it on the nice-to-have list and we'll get to it when we get to it".
In contrast your American equivalent has 20 million customers and hopes to expand to 40 million customers by 2030. Their engineers ran out of addresses in 10/8 for infrastructure years ago. So there are awful, miserable hacks they can do, but just go to IPv6 solves the problem. And hey, since your backend network is IPv6 anyway, you can just as well give it to your customers.
Once you bite the bullet, IPv6 first is actually cheaper. But most organisations aren't set up to think that way. The big changes resulting from the pandemic illustrate that. Can some (many? almost all?) of your office workers be more effective if they don't spend an hour every day commuting and then sit in a small cubicle most days of the week? The answer to that question didn't change from May 2019 to May 2020 but whether your employer knew the answer changed.
They definitely did those, I've gotten everything from 172.* to CGNAT 100.* IPs to UK MoD 25.* IPs as NAT, all on the same carrier, hah
That's about half of the worlds population (and I bet more than half of the internet-connected population). If those countries start going exclusively IPv6, the rest of the world cannot afford to don't care much longer.
And yet here we are in 2021 and my carrier is only giving me IPv4 access by default. No IPv6. This is with 4G connection and 70GB data per month by the way, for which I pay about $50 per month for the subscription.
The reason?
They must block pirate tv sites and the Allot network equipment that does that does not support IPv6.
I know a few people who got 5 "usable" addresses with each dedicated server from a provider that shall go unnamed. That actually eats up an entire /29 per server. None of those people ever use more than 1 IP. The datacenter doesn't even bother to configure the remaining IPs on a default install.
"We've evaluated your sign up data and we've decided to not do business with you. Your account was rejected and we won't review it again for the next six months."
There was nothing shady in my sign up data. It took me a moment to realize that the reply e-mail was real. Crazy stuff.
The sole overhead of doing the accounting and even abuse handling for other continents is probably not worth the money.
Maybe it isn't clear from their page and they should be more open about which markets they serve.
From a customer perspective, they made me feel like a criminal for a few seconds :D
> Our dedicated root servers will continue to include one free main IP; there will be no change here.
Virtual machines from Hetzner, however, always come with an IPv4 address. For security reasons, I’d much prefer to get them without one (I disable the interface and firewall it 100% anyway), but it’s not an option to get a virtual machine without the public IPv4 address. One would think they’d provide that option if they are already hitting commercial limits with the IPv4 address space.
I agree and hopefully without leaking anything: This is also an request within their customer forum [1].
[1] https://forum.hetzner.com/index.php?thread/28220/&postID=277...
But it also feels kind of strange to me, that they complain about IPv4 shortage while still handing them out with each VPS instance despite a lot of users actually don't need or even don't want to have them. There should be an option, or even a small fee for a public IPv4 on cloud servers.
Yes, the forum requires registration and is open for customers only. That's why I said that I hope I don't leak anything (by saying that this topic was discussed in their (private) forum).
The marketing page [1] still lists the same €2.49 + VAT /month price for the cheapest CX11.
Product. Price per month / hour up until now Price per month / hour, effective 1 Sept 2021
CX11 2.49€ / 0.004€ 3.49€ / 0.0055€ CPX11 3.49€ / 0.006€ 3.99€ / 0.0065€
Still, it sucks to pay €1.00/mo for an IPv4 address I don’t want or use.
Also, they should update the marketing site to clearly show the impending price change.
Edit: they’ve updated the website.
Edit: I’ve now received an email about the price update, and the marketing site pricing has been updated.
Beyond that, though, I think a lot of the fundamentalism around "IPv6 should mean everything is always available, if you don't like that get gud at network security" has been incredibly counter-productive. IPv4 NAT has given a certain level of network security to consumers, and IPv6 defaulting to always-on, all-the-time is not a comforting story.
Given that's true, what happens next is not so hard to predict. The price will continue to go up for a while, but then it will hit an inflection point. It's an inflection point because what makes IPv4 attractive is better connectivity. Network effects in other words. But once the real migration starts, connectivity will swing in towards IPv6, so an IPv4 address will be worth less than an IPv6 address. Which is to say it will be worth nothing.
That translates into a rapid rise in price presumably artificially inflated by speculation, then the bubble will pop, the bull will turn into a bear, and the price will drop off a cliff.
In other words, you will know the transition to IPv6 has happened when you see that price crash.
The monthly fee I can understand (but also feel there is a bit of mark-up on it to nudge customers towards IPv6).
I guess since it's their service, they have an absolute right to charge what they like (and let the competition decide) but the set up fees are just not going market rates.
Point I'm trying to make is - charging € 435.20 per month for a /24 is expensive but sort of ok ... but the € 4864.00 set-up fee?
Seriously? It costs € 152.00 for a /29 subnet but it costs 32x MORE to set up a /24 subnet? Is it really 32 times more work to set up?
I'd imagine this is a major incentive for long-term ownership of their freshly acquired IP space instead of churning them through customers to end up on every blacklist for every conceivable type of service.
In any case, a link to the so-called tulip mania doesn't answer my question, does it?
Perhaps that was because those BitCoin futures allowed short sellers to take a position?
I mean, I guess there is with 4in6 and Tunnel Setup Protocol? But I've not seen it done yet in the real world.
I think maybe if some quirky software developer wrote something popular that only worked over IPv6, maybe we'd see a slight uptick.
It's sort of like taxing carbon to make non-carbon energy more competitive.
It might make a bit more sense as justification to raise retail prices, but there is a risk that competition will undercut that price.
Though, at some price, they might be tempted to figure out how to get by with fewer IPv4 addresses and sell the remainder.
Of course the market may not be rational (it's obviously not super liquid, either), and it's very plausible the price creeps up over time before eventually crashing, or that we never get to widespread IPv6 adoption after all. Maybe you have some insight that they are underpriced at the moment and IPv6 adoption is further away than the market thinks. But I wouldn't contemplate this as an investment unless I had some plan to collect rent for the assets to make up for the expected eventual depreciation.
The thing that's saleable is routable IPv4 address space. That is, blocks of addresses which can just be announced somewhere by a new owner. I can't meaningfully sell say 81.2.89.126 even though that address is "mine".
The RIRs still manage this namespace. Their rules only allow transfers of space to LIRs that have a justified need for the addresses, the "sale" just allows you to bump their request to the top of the queue matched against your return of those addresses. At exhaustion (where most regions are now), the queue won't move unless either some kind soul gives back some addresses or, more likely they sell those addresses to somebody not at the front of the queue.
So, you can't really just buy 1000 IPv4 addresses. You would need to create an entity that needs 1000 addresses, that could buy them, and then it could use them, but then that's not really an "investment in IPv4 addresses" it's a company (ISP? Cloud provider maybe?) that you founded and provided some capital to in the form of the address space it needed.
The real estate equivalent would be turning a vacant lot into a parking lot while waiting for a good offer from someone who wants to build a building.
Thankfully, we have DNS. A lot of ISP issued consumer CPEs now automatically create lan-local DNS entries for clients based on hostname provided by the client at dhcp time, a lot of clients also natively support mDNS, and there are plentiful free DNS providers if none of the above applies to you, and you can't host your own.
Remembering IPs isn't something that people should need to do at this point in our networks maturity.
But cloud or not, if you setup a private network with v6 you can get a nice /48 prefix, and you give out /64 prefixes to VMs, so you'll have 48 unchanging bits to memorize (or put it into a .txt to have it near). And most of that will probably be zero anyway.
For example 2a00:1450:4001 is a /48, and 2a00:1450:4001:082b /64. Only change is "082b".
I know, it's not the same as just remembering 1.1.1.1, but most of the people working with v4 never had so simple addresses to work with. (And if we're talking about 10.0.0.0/8 and other private addresses, well, folks can continue to use them, if they want to endlessly debug NAT and static routing hacks.)
If we had added 16 bits to v4 we would have 100% adoption by now.
The very slight convenience you mention is far outweighed by 32+ digit IP addresses.
Also please don't bring up DNS. Anyone arguing that DNS is a solution to this problem has never done devops or IT.
You would be surprised how much hardware and software doesn't support IPv6 properly. Sometimes it is the basic things, sometimes the more advanced stuff but that just means it takes a second or multiple days to find out. The problem is, it just is a similar but different protocol so you have to be quite diligent and check everything you need for the device/ service to work.
People do all kinds of stuff on underlay and overlay networks. E.g. some Dell VxRail hyper-converged appliances use IPv6 for the management network https://i.dell.com/sites/csdocuments/Shared-Content_data-She.... This is basically just link-local addresses for L2 reachability if I remember correctly but they could've gone with IPv4 there as well. It certainly would be more common for enterprise appliances to not rely on IPv6 for anything even when it shouldn't make a difference whether you do.
mDNS might also help, I haven't tried that approach.
As an example 2001:0db8:0000:0000:0000:0000:0370:7334 could be written as 2001:db8::370:7334 instead (notice that leading zeros were also culled). This paired with the fact that hexadecimal tends to be easier to memorize and doesn't have the strange subnet masking logic like IPv4, gives it a lot of advantages over IPv4's address notation.
The problem is that it's almost like router firmware and ISPs go out of their way to make their addresses harder to work with by filling out all 8 hex groups in the addresses they grant. Considering the sheer amount of available IPv6 addresses, it's from my understanding, completely unnecessary and I'm really curious if they have any kind of justification or technical reasoning for doing this.
1. easier routing tables if you can add meanings to specific bit ranges of your ipv6 address. In the tightly assigned ipv4 networks we have arrived at this is a bit annoying.
2. If the ipv6 conventions were that you set, say the highest 5 hex groups to 0, and use the lowest 3 hex groups for addresses, it would still be 65536 times as large as the ipv4 space and would suit most needs for the mid term future. You could even write ipv6 addresses nicely using e.g. ::ef13:2.1.7.100. This is a valid ipv6 notation! If this space ever got too tight one could open another one of the available hex groups and use two hex group prefixes. But I think when this happens, a lot of configurations would break because they'd assume that only 48 bits are used of the total 128. To prevent router,switch,firewall, etc. vendors from putting any such assumptions into their devices, using the full 128 bits from the start is a good option.
Giving everyone, worldwide an internet address means they have to be longer than limiting it to the early adopters.
Not really. In fact, pretty much anything would have been easier to memorize than this colon-separated nonsense, which makes URL parsing more difficult, and which is so stupidly complex that it has a special syntax to ignore repeating zeros.
The [IPv6]:port syntax is unfortunate, but I'm not sure what they'd have done instead. Dotted hexadecimal would be ambiguous, because "1.2.3.4.5.6.beef.de" looks like a DNS hostname.
Zero compression exists because it's more convenient than writing all those zeroes, especially with CIDR prefixes like "2000::/3".
As well as decimal:
Both lead to google.com
Except for recent versions of Firefox Mobile: https://github.com/mozilla-mobile/fenix/issues/4343
I've expressed my disagreement on the public mailing list but it seems like it is happening anyway.
* AWS in July 2021: 0.005 USD/hour = 3.65 USD/month.
* Hetzner in July 2021: 0.84 EUR/month = 1.00 USD/month.
* Hetzner from January 2022: 1.70 EUR/month = 2.02 USD/month.
With a 19 EUR = 22.58 USD setup fee at Hetzner since August 2021:
x * 1.00 + 22.58 = x * 3.65;
22.58 = x * (3.65 - 1.00)
x = 22.58 / (3.65 - 1.00) = 22.58 / 2.65 = 8.52 months to recoup the setup fee compared to AWS.
With the Jan 2022 monthly price increase:
x * 2.02 + 22.58 = x * 3.65;
22.58 = x * (3.65 - 2.02)
x = 22.58 / (3.65 - 2.02) = 22.58 / 1.63 = 13.85 months to recoup the setup fee compared to AWS.
It's interesting that the 19 EUR per IPv4 setup fee applies to both single IP addresses, as well as full subnets -- /24 now has a whopping 4864 EUR setup fee! (19*256=4864) Ouch!
If your website/docs/whatever are on GitHub pages, it's IPv4 and a lot of the world can't access them.
Most server software cannot properly handle blocking of increasing IPv6 subnets.
And not only that, but my ISP assigns the same /64 subnet to me for months. Who needs cookies anymore if you can just track the /64? Even unplugging the router for a day won't assign a different prefix for me.
On IPv6, your OS should also enable the privacy extensions, so that your device has two IPs: a stable one for incoming, and a randomly changing IP for web browsing. Sure, it's the same subnet, but it would be silly to rely on this considering the many other ways we can track users.
It wouldn't surprise me if there are already databases which map IPv6 subnets to real names, addresses, banking data, ...
And anyone could just use that database or contribute to it.
And then jurisdictions such as the EU, Canada and California would consider the IP address to be PII, and it would be illegal to contribute to such a database.
Again, there are much more easier ways to track people on the Internet.
> You would probably have the same level of reliability with an IPv4 database currently
That is... a lie. The selling point of today's internet is that you are anonymous.
Also I don't know which "easier ways to track people" you mean.
No, it doesn't. Your ISP is the one who can take that decision away from you. I have Google Fiber, and my public IPv4 address has not changed in around six months, while my IPv6 block has changed twice in that same time. This is despite replacing my router and several multi-hour power outages. I believe the only reliable way to get a new IPv4 address is to call support.
- 1 public IP for my nginx server - N private IPs for my application/db/monitoring servers within the VPC
https://docs.hetzner.com/cloud/networks/connect-dedi-vswitch...
I get why Google and Facebook and the like are pushing the technology hard; it enables casual tracking of individual devices by third parties which are normally blinded.
IPv4 sells for ~$40/IP right now.
The smallest block you can buy that is Internet routable is a /24.
If you're buying, you're likely buying from another speculator, so you're not helping accelerate anything, you're simply a(nother) middle man in a (series of) sale(s) of a commodity, looking to profit until the block eventually gets sold to a user.
None of that is said with any judgement, mind, as I've traded a /22 of IPv4 space for quite a handsome profit over the last few years. Just don't pretend there's any altruism or benefit to anyone else from your speculative activities.
Any other purchase reason is likely to result in ARIN pulling your "ownership" entirely when they discover it.
From what I understand most of what's being sold off right now on ipv4 auctions are from companies who had too much IPV4 that they no longer need, or companies that were liquidated.
lol. SNI exists folks.
This worked from the beginning on for IPv4 and IPv6 (probably also more exotic networking protocols) on Linux, though I don't know how hacky the Windows equivalent to this is.
Let's try a little thought experiment. Abe, Carol, Emma, Gerald, Isobel, Kate and Mark are at the place. Everybody is hungry. Three pizzas are delivered. Each person will be able to eat about half a pizza, or else they'll still be hungry.
Carol and Isobel announce that as Vegetarians they ought to have the two veggie pizzas. Carol eats half of hers and says she's keeping the other half "to eat later". Isobel realises her pizza has red pepper on it, she doesn't like red pepper and so she throws about half the pizza away as "contaminated". All five other people are left to share the Pepperoni pizza, they all still feel hungry after dividing it equally.
Was there hoarding? Yes Carol hoarded half a pizza. Was there waste? Yes Isobel wasted half a pizza. Was there not enough pizza? Yes, three pizzas is enough to properly feed six people and there were seven people eating even before Carol and Isobel announced they were keeping the veggie pizzas to themselves.
When will these dumb large companies stop wasting TWO addresses per subnet?
IPv6 has been available for over 20 years. This is way longer than IPv4 was available when the Internet went "mainstream" in the mid-90's. ISPs need to get their ass in gear.
The fact that some newer ISPs (like Verizon FIOS) are still not offering IPv6 in some areas is embarrassing.
Presumably this is to make it untenable for spammers to churn through multiple blocks of /24s at little to no cost.
Also, a /24 is going for around $10k to buy or sell on the IPv4 market now, or approx 50% of their setup fee, making it much more economical to buy your own space, which is probably what they'd rather you did, since giving you 256 IPs means thats 256 more servers that they cant sell.
EDIT: and before the response of "but I only want a /29", if there's no incremental setup cost to get a larger block, that approach will get abused by nefarious users. This is why we can't have nice things.
EDIT2: ..and a /29 still means 8 more servers that can't be sold. There's opportunity costs involved in leasing IP space that could be better used elsewhere. As the cost of acquisition of IPv4 space goes up, so does the cost to the end user.
This is exactly what it does. Hetzner Cloud will also, to the dismay of my ssh known hosts, keep assigning you the same IPv4 addresses until it becomes the LRU in their pool for a new customer so you can't do this.
Property, in many cases, this one included, should be bound to making actual use of it.
Some of nets (25/8, the CGNAT space) are essentially so established as private-equivalent, they should just be officially declared private. Connectivity to these will forever be spotty now that they made their way into corporate networks.
See https://arstechnica.com/information-technology/2021/04/penta...
Reassigning this space would probably be a worse experience for whoever it is assigned to than those that started using the network internally too.
CX11 is up +40%, CPX11 is up +14% and Floating IPv4 addresses are up +200%.
Existing instances/floating IPs will stay at the old prices, unless rescaled.
Per email, no announcement link that I can find yet:
---
Important customer information: Price adjustment for new CX11 und CPX11 and Floating IPv4 addresses
Dear Client from the moment we launched Hetzner Cloud in 2018 we have continuously been working on expanding our platform and offering you an excellent price/performance ratio in cloud computing. Unfortunately, the prices to acquire IPv4 addresses have since increased dramatically and we have no choice but to respond. For a long time now, the pool of available IPv4 addresses has been almost empty at RIPE, the European IP address management agency. That's why RIPE stopped assigning IPv4 nets. Because of this situation, there is now a fast-growing market in IPv4 address trading with many active brokers, such as on https://ipv4.global/reports/. Supply and demand determine the price at IPv4 brokers, so the prices have skyrocketed.
We have tried hard to avoid passing on these higher prices to our customers, and have accepted the economic loss until now. However, the prices have increased so dramatically that we can no longer do this. We unfortunately must increase our prices.
Starting on 1 August 2021, the price for newly created Floating IPs (IPv4) will be increased as stated below.
Starting on 1 September 2021, the price for newly created Cloud Servers (CX11 and CPX11) will be increased as stated below.
Product Price per month / hour up until now Price per month / hour, effective 1 Sept 2021
Cloud Servers:
CX11 3.088€ / 0.00496€ 4.328€ / 0.00682€
CPX11 4.328€ / 0.00744€ 4.948€ / 0.00806€
Existing Cloud Servers are not affected by this price adjustment. Please note that these prices also apply to rescaling, effective September 1, 2021.
Product Price per month up until now Price per month, effective 1 Aug 2021
Floating IP:
IPv4 1.24€ 3.72€
Existing Floating IPs are not affected by this price adjustment.
All prices incl. 24% VAT.
Demand for IPv4 addresses will likely remain very high. And we will need to continue to purchase nets. We assume that the prices for IPv4 addresses will continue to rise, and that we will also need to increase our prices again in the future. Prices for IPv4 will likely remain high until after IPv6 has become much more popular.
We are confident that this is still a good price/performance ratio and hope for your understanding.
If you have any questions, we are happy to help. To open a support request, please go to the menu item Settings on your Cloud Console. We hope that you continue to place your trust in us as we are constantly working to expand our services and you can look forward to several new features that are already on our roadmap.
I also had several resources there for years. Never got anything to complain about.
If anything they are too picky on who they host.
I remembered one of these players and just being totally shocked had how bad they were in this area - like no care - despite trying to compete with AWS. I don't remember if there was also internal to their network scan / attack stuff going unaddressed in addition to just issues with deliverability out (non marketing) but I honestly felt like I was working with kids vs adults a bit (this is some time ago though).
I'd been told I was an idiot for paying for AWS and that there was lots to be saved on their unlimited bandwidth etc - but it ended up being absolutely not worth it. AWS support is really good. They seem to take abuse issues quasi seriously etc.
They do have very long term customers that are abusive as fuck, spray high-PPS port scans and bruteforces out under the false guise of security research (with no IRB, no studies, no affiliation or notice of who they are), pretty much floods that abuse has ignored.