Comcast begins IPV6 deployment
blog.comcast.com
blog.comcast.com
NAT traversal was always a pain the behind...
Now Bobby can run his game server on port 2275 and Billy can run his game server on port 2275 both connect to the same cable modem, and each will be able to get their own traffic routed to them.
The tuple for a connection is:
source IP = 4 bytes
source port = 2 bytes
dest IP = 4 bytes
dest port = 2 bytes
For 12 bytes, or (in theory) 96 bits of ephemeral address space.
It doesn't seem very meaningful to talk about tuple space, because we don't assign a tuple to each host. If we had 2^8 addresses, we wouldn't be nearly so worried about IP address exhaustion. But we don't have 2^8 addresses. We have 2^8 tuples.
To illustrate, let's say my network's external IP address is X. Let's choose some port number Y. A packet addressed to X:Y could be going to any one of several machines on my internal network, because the NAT uses the source (not just the destination) as part of its lookup. So X:Y does not uniquely identify a machine... it's only part of the total address.
Comcast has been working on IPv6 for years, and they've got senior technical people who know it inside out, but it needs to disseminate throughout the organization all the way down to the front-line support people. That's going to be hard enough even before third-party gear is brought into the picture.
Then, there is the perspective of what the end user can do (with or without telling comcast) - obviously, in the IPv4 case, you can PAT/NAT to your heart's content, and Comcast will be none the wiser.
So - depending on whether you want to stay within the confines of what Comcast is "officially" supporting, or working with the realm of what you know will work - you may or may not want to NAT4 (I personally would have no problems doing it)
Which brings us back to the question of IPv6 - I don't think there is any mechanism to allow multiple hosts to hide behind a single IPv6 address, so, from that perspective, the "What will Comcast support" and "What will I do" - turn out to be the same perspective. :-)
The weak link of Comcast for a while was their lack of not providing IPv4 forwarders on IPv6 DNS servers. Many public DNS servers (including Google DNS) are also in the same boat.
On a somewhat unrelated hardware note, Comcast actually supports IPv6 on the Motorola Surfboard 6121, contrary to what their compatibility list suggests. The 6121 is simply a revision of the 6120, and typically they provision 6121s as a 6120 with 6120 firmware.
IPv6 doesn't have that problem, and it seems to me that keeping them fixed is probably cheaper in terms of billing and accountability.
If pooling was the true original reason for dynamic IPs, it usefulness for that purpose has already passed, regardless of IPv6.
I could definitely see scenarios where you end up connecting to a different CMTS and thus it's cheaper for them to assign a new prefix rather than carry your old prefix in their IGP. Or something like that.
The questions I need to go find answer for are:
1. What do I need to do for Comcast to give me an IPv6 address? 2. What for my FreeBSD gateway do I need to modify to do DHCPv6 (stateful)? 3. What modifications do I need to make to my Firewall rules that currently assume NAT? 4. What is the easiest way for me to take the /64 and split it up so that even my test virtual machines now have direct accessible IP addresses (currently adding static routes using DHCP, which is a pain in the behind!)? 5. Start verifying that all internal devices that are requesting IPv6 and are using IPv6 are also fire-walling it correctly and all services are prepared for it. I can firewall at the border (gateway) at the moment, but eventually I don't want to police that traffic. 6. How will this interact with my IPv4 10/8 network I have set up? 7. What legacy devices are on my network that do not speak IPv6? 8. How does this change services that broadcast themselves widely and freely (looking at you mDNSResponder, Samba, UPnP media servers)?
These questions are just the ones I can think of at the moment. It is going to be interesting to see how this all works out, and I feel like I am going to have to learn networking all over again.
However, it's an excellent time to make sure you can answer all your other questions.
Edit: If I am off here, I want to know.
Can you say a bit more about this? I haven't actually seen any implementations of NAT that will allow you to do NAT/PAT for multiple internal IPv6 hosts onto a single external IPv6 address. Does such a thing exist? If I were asked today, I would say "No." - but I clearly could be wrong.
Except the issue of doing IPv6 completely wrong.
"As the world gets faster, it turns out that the glacial changes of years and decades are become more important, not less." -- Seth Godin (http://sethgodin.typepad.com/seths_blog/2010/08/resilience-a...)