Posters of the IPv4 and IPv6 internet as of Jan 1, 2023
vad.solutions
vad.solutions
APNIC runs modified sparse: the /12 is divided up into pools and bigger and smaller parts are used to make two sets of binary chop headroom reflecting the scale.
The outcome should be visible in the chart: a grey peppering of blocks spread throughout the /12s and for APNIC evidence of at least two densities of scatter.
Broadly speaking, it's worked. The RIR collectively haven't gone back to IANA very often, a lot of IPv6 space remains. Scarcity isn't driving the dynamics of BGP announcement and disaggregation. Compare that to IPv4, costs of entry to market for new players, avg number of prefixes and relative disaggregation of holdings.
(Disclaimer: work in an RIR)
And that was in addition to the ARIN /32 we already had.
And the /40 would be an actual "ASSIGNED-BY-LIR" sub-allocation that you could also sub-allocate as you see fit.
I love IPv6 and it’s so exciting to see it used widely at last. My mobile device is v6 although it’s still dual stack. Home networks are doomed to by v4 forever so your 1990s eToaster can display Yahoo! News! but I wonder how many ISPs are doing 4to6 or CGNAT nowadays? That’s what my cell provider does.
I only know a little bit about BGP. Why does Tesla announce 6x /48s instead of having a /32 of their own and handling their routing internally? https://bgp.he.net/AS394161#_prefixes6
Why? I've had dual-stack at home for many years, and I can hit sites via IPv6-only: way back when, I blocked Facebook connectivity for privacy reasons, but at some point I noticed I started getting those little FB icons again that came directly from their servers. Turns out that I was hitting them via IPv6 and had to update my (DNS filtering) rules to block AAAA records as well.
Even my not-very-new Brother HL-L2360 (running firmware from (AFAICT) 2015) supports IPv6, and has both a fe80 link-local address, and a 'proper' address that it got via a prefix advertisement from my Asus router.
Most IoT devices run Linux under the hood and get IPv6 support 'for free'.
There is certainly an upfront cost of getting IPv6 going for a 'legacy' ISP, but once the infrastructure is there it can reduce the ongoing costs of CG-NAT (because IPv6 will just be part of the fixed costs that you need/have anyway to be an ISP).
Possible further benefit, reaching India and China who certainly aren't issuing IPv4.
Hopefully the day comes when people can get static IPv6 addresses instead of a dynamic one behind an ISP NAT.
This is important for servers, but not so much for consumers, IMHO. Sites in India and China are highly likely to be dual stacked, so v4 only users aren't likely to be missing any content at least currently. Although certainly missing access to v6 preferred peers. There's very few really v6only use cases out there yet, almost every consumer access network has some way to get to v4, there's too much v4 only content not to; even if the v4 access is much worse than v6, as it sometimes is.
I find this very, very hard to believe. I haven't found anything online. Can you give me some pointers?
>Possible further benefit, reaching India and China who certainly aren't issuing IPv4.
All Indian and Chinese websites have ipv4 addresses in case I wanted to reach them.
I think people should come to terms to the fact that everybody is moving to cgnat and the world is not falling apart as they said it would.
As someone who's behind CG-NAT, I agree that the world is not falling apart. It is, however, very inconvenient.
The IPv4 Internet has more fluctuation in latency - I imagine it gets worse in periods when many more connections are having to go through the ISP's CG-NAT router, and/or when a lot more volume of data is going through that same bottleneck. It's not the end of the world, but it's not ideal.
On top of that, my IPv4 traffic is bundled together with a cohort of cusotmers whose Internet behaviours I know nothing and have no control about. This affects my reputation on things like CAPTCHAs and other forms of access control. It's not the end of the world, but it's not ideal.
I can't get into my own network from an IPv4-only external network without resorting to routing contortionism. It's not the end of the world, but it's not ideal.
CG-NAT requires expensive and power-hungry equipment, which in turn means more maintenance, more complex infrastructures, more equipment failure and replacement and increased energy usage.
It's not the end of the world.
But it may well be contributing to it.
> I find this very, very hard to believe. I haven't found anything online. Can you give me some pointers?
Google Wifi, Mercku M2, etc. have been reported as not having support for 6rd or 6to4.
Some UK ISPs give out /48s (cough Sky) but with dynamic allocation. So you reboot your router and every single IPv6 device on your network needs to re-address. Makes routing/port forwarding a PITA and nearly impossible using IPv6.
If you have two ISPs (say a backup 5G) then you have to renumber every time the main goes down. If you want to load balance you’re screwed, unless of course you use nat.
Residential ISPs won’t allow you to bgp peer your own /48
Kind of: if you use IPv6's ULA (fc00/7 [1]), then you can have a NAT-like translation layer using NPTv6 [2]. The advantage of NTPv6 over NAT44 is that you get an entire prefix to play with instead of a single IP on your router's WAN interface.
If you wish to have multiple services (web, SSH, Minecraft), then with IPv4 hole punching you can only have one server on the default port and the second system with the same service needs to be on a different port. With IPv6/NPTv6 you can have each service on a different IPv6 address and live on its default port.
You also have the flexibility of either only allowing one particular port in for that service/IPv6 address, or just allowing all traffic in without any firewalling/filtering.
So NPTv6 is no worse than NAT44 in the simple cases, but also has extra functionality over it.
[1] https://en.wikipedia.org/wiki/Unique_local_address
[2] https://en.wikipedia.org/wiki/IPv6-to-IPv6_Network_Prefix_Tr...
I bet most people change ISPs with a frequency that's a fraction of the frequency they reboot their routers.
In any case, only a few devices in most households require static public IPs (only the ones you connect to from the outside directly). If you put those in DNS, all you need to do is change their AAAA records.
For internal comms, IPv6s in the link- or site-local ranges are better anyway.
Probably the same reason they annouce /24s and not aggregated prefixes on v4 when they're contiguous. We can't tell from the he bgp tools, and I'm not going to look at other tools, but I'm guessing those /48s are distinct sites and are advertised differently (or maybe one is used as anycast, the others being distinct sites). Theoretically disconnected sites could each have their own AS, but it's very common for an organization to use a single AS globally, and only advertise locally served addresses at each site/BGP session.
Not really your point I know, but I was curious about this so I looked it up. The closest Earth and Mercury get is 77.3 million km[1], which is 515.7 seconds round-trip (ping) at the speed of light.
[1] https://nssdc.gsfc.nasa.gov/planetary/factsheet/mercuryfact....
That said, if you know your equipment can handle it like some network operators know theirs can, there is nothing stopping you from using it as a /4 local address space.
Though that would just exarcerbate the problem by producing yet more resistance against allowing that gigantic network to become useful public space.
That would be 224.0.0.0/4, no?
Longer answer: it doesn’t really matter in the scheme of things. I saw where someone did the math of recovering all the corporate /8s (assuming that there was a justifiable reason for repossessing address space that they requested and were allocated fair and square). It would extend the IPv4 timeline by like a month and a half.
IPv4 is used up, and it’d be exceptionally difficult and expensive to claw back subnets.
Same with General Electric and the 3.x. It was sold it to AWS a few years back, introducing the burden of internal re-addressing.
Before cloud providers/FANG behemoths, these were some of the largest networks around.
Realistically, Ford may also have use their IP range in a kinda of haphazardly way, simply because they never had a shortage or had to deal with multiple public range. So cleaning up their network, to be able to free any number of IPs would be a lot of work, at a high cost, with no real benefit for the company. Sure they could sell the surplus IPs, but they aren't that strapped for cash.
And, yes, it was absolutely inspired by Randall Munroe’s xkcd Map of the Internet, which someone has already linked.
There’s a fork that uses ColorBrewer palettes, which may be what they actually used: https://github.com/hrbrmstr/ipv4-heatmap
(I used to work at Akamai and used this to produce monthly versions with each /24 colored based upon how many addresses within it had connected to the company’s network.)
Personally, I'm very positive about IPv6. I find a lot to like in the protocol. From an end user standpoint tho, it's very much a club. If your ISP is in you're golden. If not, you don't exist to other members.
This is one of the biggest FTTH networks in France, where IPv6 is deployed a lot.
Of course, the bigger operators can collect their traffic straight at the OLT, so they don't have to go through this mess, and get better quality of service (the DHCP interceptors fail often) as well as native IPv6.
We small operators need to set up tunnels to provide IPv6 to our clients. Even for additional IPv4s or just anything bigger than /32 we need a custom tunnel. And these tunnels are a mess to manage when the customers have their own CPE. It's so sad, and that's all done with public money.
And yes, of course, this infrastructure operator, Covage/XPFibre is owned by Altice, who also owns SFR, one of the big four operators. How surprising.
> We small operators need to set up tunnels to provide IPv6 to our clients. ... And yes, of course, this infrastructure operator, Covage/XPFibre is owned by Altice, who also owns SFR,
I might be misunderstanding who the private and public actors are. To clarify, is Altice is over the tunnel infrastructure?
But services supporting it is the other side of the problem. Both need to be addressed.
Last I looked, a lot of these either require a public IP address (do not work behind CGNAT), are defunct (not accepting new registrations, or even have a parked domain), or no longer work as well as they used to (both 6to4 and Teredo depend on public anycast relays, and their connectivity seem to have gotten worse; and Teredo also requires that the native IPv6 hosts do not filter ICMPv6 Echo Requests and Echo Replies, which unfortunately are too commonly filtered by overzealous sysadmins).
Please expand on this (besides ‘wow such large numbers’…). I’ll take my answer off the air.
It not evident if you are an admin of localhost, but working with hundreds devices make you really appreciate it.
This is the whole config what allows the device to talk to IPv6 and provide IPv6 addresses to the clients in the vlan3003. No DHCP, no ip helpers, nothing.
interface Vlan2999
ipv6 address 2000:1111:1:1::2/126
!
interface Vlan3003
ipv6 address 2000:1111:1:4::1/64
!
ip forward-protocol nd
!
ipv6 route ::/0 2000:1111:1:1::1
> in case anyone is wondering why IPv6 is where it’s at after a decadeBut.. I'm tired to juggle this nonsense. We have /21, a couple of /24 and a bunch of /28. I recently decided to move out our services from /21 and /24 to some specific /28 and despite what all those /28 are pretty close (most of them sits in one /23) I can't have a few laconic network rules with aggregates for separating our own and customers traffic. I would need to have a whole let of rules, almost for each /28.
I like feeling like a member of the club.
^^ in case anyone is wondering why IPv6 is where it’s at after a decade…
Sigh.
At a previous company I worked at, this was literally the impetus for going IPv6. We were in a regional business and were growing by acquiring companies in other regions. Every new company we acquired, we had the major pain of making the networks talk. Almost everyone is using 192.168.0.0/16 or 10.0.0.0/8. IP conflicts were a given, and re-address networks was a big painful operation. NATs were an option, but came with their own permanent complications. IPv6 made it go away. If the new site already had IPv6, collisions were still a non-issue, and if they didn't, well getting them IPv6 ready was easier than re-address everything. Once they were IPv6 ready we could go ahead and establish VPNs, and with most traffic now going over IPv6 we could re-address IPv4 without causing significant outages.
IPv6 has other advantages, better multicast, better routing, flow labeling, automatic link-local addressing, but the large IP space is definitely the elephant in the room.
Also Ford, Daimler, and Prudential owning huge network blocks and neither even doing business in networking, nor announcing prefixes can be referred to as outright IP squatting (if that term exists). The US DOD seems to be a squatter, too.
Based on professional experience, I doubt that networking equipment can not handle reserved blocks. And if it does not indeed, patches could be provided by vendors for sure within reasonable time.
The problem is not severe enough: neither for a switch to IPv6 (also conceived almost 30 years ago!) nor to make use of unused blocks.
I refuse to believe that IPv4 address exhaustion is actually a thing.
My company operates big networks and it caught us off guard when 44/8 got used on the public Internet. Internal tooling used the space because it was assumed to be non-routable. Assumptions like this always carry a risk and sooner or later, they need to be fixed. In our case, a workaround could be produced within hours, and it was fixed within weeks.
0/8 support has been added in the Linux kernel as well.
Edit: scdown.qq.com resolves to 0.0.0.1 and is possibly related to WeChat. I am not sure, if the address is actually routable in China, though.
... which is just another example of the zillions of cases that would have to be dealt with.
Sure, each one is probably quite easy. But the sheer number of them is huge, and many of them will only be uncovered after they fail, setting off a frantic search for the retired guy with the source code.
With Y2K there was a combination of self-interest and hysteria that motivated organizations to tackle it. With this, it's harder to make that case because IPv6 is here already. I'm sure very few of those applications with hardcoded 0.0.0.0/8 are IPv6-ready, but everyone else can move ahead with IPv6 and those old apps will keep working for years to come. Unleashing 172.0.52.7 as someone's residential IP address will result in seemingly random failures that cause headaches for the ISP, application developers, and corporate IT departments. It'll be a very unpopular idea.
I have no idea to what extent 0/8 is being used today. I do see quite a bit of 240/4 in private networks. It's a shame that last may never be publically allocated.
I agree many howtos tend to get into the little obscure differences and weird rabbit holes (ex: tunnelling).
Edit: I just saw that my question has already been answered in this thread.
Precision Time Protocol (which many if the above are also dependant on) is also based around it and used across a number of domains where tight clock sync is required.
Closed circuit IPTV systems use it constantly. I’ve got about 500 addresses ok my network encoding different video and audio channels for desktop use.
That said I only use addresses in the 239/8 and 224/8.
Currently not needed.
The IETF/IANA folks were a bit cautious, so only 2000::/3 is officially designated to be assigned. If, a few years down the road, they find out that a mistake was someone made in address allocations, they can then 'start over' from the lessons learned, and start assigning things from 4000::/3.
If they made a mistake again, they can start over again with 6000::/3. And then 8000::/3, a000::/3, and c000::/3.
* https://www.iana.org/assignments/ipv6-address-space/ipv6-add...
So that's why all global unicast addresses start with 2: they're to be 'conservative' in what is usable so that if there are problems there is room for corrections in the coming years/decades/centuries.
We don't want to have to go through another IP protocol transition.
Asking as a nerd, but maybe not a very specific data oriented nerd.