NAT between identical networks using VRF
blog.oddbit.com
blog.oddbit.com
Though I'm not sure the complexity is worth it. Suppose it would be nice if tailscale implemented this type of substitution-routing-NAT this for users.
I've been really careful about selecting virtual network IP spaces throughout due to this concern.
The hardest part is accounting for the point-to-site VPNs on top of everything else (i.e. employees connecting from home/Starbucks/airport).
For internal corporate networks, I typically will provision smaller targeted networks in order to get around this. Lopping-off all of 10.0/16 or 192.168/16 for your internal LAN will put you at a fairly high statistical likelihood of overlapping domestic ISP address spaces. Smaller, odd networks like 192.168.111/24 are much easier to plan around.
I learned on that day to put everything in our IP address management system (netbox). Allocate private networks like we allocated public networks to our customers. (It would have been nice if I allocated Docker's defaults before they had been allocated to an internal network, but ... hindsight 20/20. At least with that network in the IPAM system, people could figure out why it broke though.)
When you add a network, it gives you a network. It allocates a pretty big address space each time, and eventually it'll run out of 172.16.0.0/12 space and move on to 192.168.0.0/16 networks.
Why can I get to this from the guest network but not the client network? Oh...
It sucks, but I manually set networks now. And keep track of them.
Windows (and probably macOS?) still block that as of today so it can be an extra safe (and large) space if your only worry is "I don't want my virtual network space to collide with outside or client sourcing networks".
The down side of this is that if you have, say, a wider announced network routed over your tailscale (say 10.0.0.0/16), and then you have machines within that network also connect to the tailscale (say a machine with 10.0.1.1/24), it now will try to reach machines on its local network interfaces via routing over the tailnet. Pretty unexpected.
E.g. in the example middleman could rewrite a query for `outernode0` that comes from the inner node network to resolve to 192.169.3.10 (instead of .2.10).
I’m not sure which dns servers allow rewriting logic like that though.
Of course a screwdriver also has a feature called Quick Eyeball Removal which may be preferable. That or I'm just bitter about having done this :).
My home router is a Raspberry Pi running Ubuntu server. VRF, Wireguard, VLANs, bonding, llrp, route advertisement, prefix delegation, dhcp server and leases, all configured only with systemd-networkd.
I also found some information about using VRFs in the documentation for RHEL 8: https://access.redhat.com/documentation/en-us/red_hat_enterp...
Collisions between two private networks is very low was my primary point, and thus NAT is not a thing that needs to exist.
If you don't need Internet connectivity, yes, NAT-free ULAs work fine.
Erm... why the hell would you use NAT for that?
One of the features of IPv6 is first-class support for multiple IP addresses on a single interface. Your interface should have a one (or more) routable IP addresses that should be used for packets traveling to the public internet and one (or more) ULAs for reaching internal networks.
Note that "IPv6 NAT" really should be NPTv6:
* https://en.wikipedia.org/wiki/IPv6-to-IPv6_Network_Prefix_Tr...
It allows for 1:1 mapping of external IPv6 addresses to internal IPv6 addresses, without the silliness of port mapping and such.
Of course your firewall/network device can still have a default-deny rule so that only responses to internally-initiated requests get through. Stateful firewalls are still effective (and were invented before NAT).
And even for internal networking, why not just use properly addressable IPv6 addresses?
Because you're gonna need a firewall either way.
I have a couple of /40s to my name. My internal network has an assignment of /48. It's not announced (and is also firewalled off, not that it matters, since there's no routing table entry for it). The chance of collision is nil, because nobody should ever be using addresses within my IP space.
Endpoints that require external connectivity simply have 2 addresses on it. One that's routable, and one that isn't.
Address stability. If you use the prefix your ISP gives you via DHCPv6-PD or whatever, it might change on you, and then all of your hard-coded configs are wrong.
> And even for internal networking, why not just use properly addressable IPv6 addresses?
It costs $250/yr (and hours of bureaucracy navigation) to do this in the ARIN service region. If you've got a prefix, it's certainly a good way to use it! But we can't expect everyone to get PI space.
I’ve taken to having both a ULA prefix and a public prefix for hosts in my subnet, but the public one is basically worthless because it changes seemingly every week. I had to put a ton of effort into making a templated pf.conf updated by a dhcpcd hook so that my firewall rules update automatically, but it’s still a shitshow. When my prefix changes, my router doesn’t seem to want to rescind the old RA’s so now I have two public prefixes floating around and half my hosts can’t get to the Internet any more. I had to drop the lifetime to <1hr to mitigate it but it’s a complete joke. If ipv4 fallback didn’t work I’d have a broken network every week.
At this point I’m considering just using NPTv6 and dropping the concept of routable IP’s for my internal hosts altogether. It’s just not worth it. At which point, it’s a stretch to even say IPv6 is worth it.
ISPs being retarded is not a fault of IPv6 though.
They can give you a static IPv6 prefix, too. But you have to pay extra for a static IPv4 address to get it (which makes what kind of sense?) and you must rent their equipment (ie their router, not just a modem) to get it. So that’s easily $30-$40 more a month (equipment rental plus static IP charge) they’re holding your network hostage for. Pay up or get re-prefixed every week.
It really makes me want to puke that they’re literally incentivized to fuck up my network to try and make the extra upcharge seem worth it. There’s no reason whatsoever they couldn’t just give me the same prefix forever. There’s no shortage of IPv6 space. If I had literally any other choice in ISP I’d drop them in a heartbeat. They should all be thrown in jail.
Somewhere out there there’s a Comcast engineer whose management told them to intentionally configure their DHCP6-PD server to forget (and likely intentionally shuffle) delegations, to pressure customers into ponying up for a static IP. Maybe you’re reading this post some time in the future. I hate you and I wonder how you sleep at night.
In my old house where I lived for ~9 years, I had the same IPv6 prefix (/60) from Comcast for a little over 5 years since I turned on IPv6 in 2015 and had not changed until I moved to SF.
Sounds like there's something wrong with your CPE where it is not sending the same GUID to the DHCPv6 server and thus is getting a new prefix delegation each time.
I’ve since changed to my own modem and my own OpenBSD box with a statically configured DUID (randomly generated UUID persisted via the config file) in my dhcpcd.conf. My prefix still changed a few times.
I’ve heard a lot of people saying their prefix has been mostly stable, but it hasn’t been the case for me. Maybe my account is misconfigured on Comcast’s end, maybe something else on their end is wrong, but I’ve checked everything and it looks right on my end.
(My IPv4 address has remained perfectly stable this whole time too. Only my IPv6 prefix seems to be constantly changing. It’s the exactly the opposite of what I’d want, I could care less if my IPv4 address changes, I only need my IPv6 prefix to be stable.)
Right. I've been using my own address space at home for a while now that I've forgot how dumb ISPs can be.
I've got a BGP session on a VPS that's located in the same facility as my ISP (my upstream and by ISP are even peering there, over both, v4 and v6. The only thing missing for me is IXP access, which the VPS provider offers, at €50/month, so in this instance it's not worth paying for, but damn I'd love to give my own ISP the routes to my home network myself), so I'm just running a WireGuard tunnel from that box to my home (mainly because my ISP still doesn't offer any IPv6 whatsoever). This setup actually costs me less than a static IP from my ISP would. They charge €15/month for a static IP. My setup costs me €6/month for the VPS and additional €5/month for the BGP session.
I could even do iBGP between the VPS and my home router over that tunnel, but that's far too hardcore. I think the /56 I've given for my home network will be enough for a couple of lifetimes. After all, it's 256 subnets of /64, and how many VLANs do I need at home? :D
Unfortunately not everyone can do this. :(
And then there is SRM on Synology... the amount of bugs I have reported on that is insane.
Which makes me think: is DNSMASQ the right tool for the job? It's extremely complicated in my opinion. If this, then that, but not when you do that thing over there.
I think the only OS that handles IPv6 correct is Microtik. But they have no decent all-in-ones.
But we definitely should. The number of IPv6-only networks is growing by the day.
The next generation of tinkerers and internet engineers will have no IPv4 address space at all, because it makes no sense whatsoever paying $14k (at current prices) for /24 of legacy IP address space.
Unfortunately, the best we can hope for is for giant corporations like Cloudflare, Microsoft and Amazon to buy up most of the IPv4 space.
if this is a network you own either end, then if you really do have the same subnets issued to different sites, then you would be better served having virtual interfaces/VLANs to have a second IP address.
Or, just use ipv6, and you have enough IPs to do what you want. You can use 6to4 or nat64 to get IPv4 connectivity. most modern networks terminated services on the edge with loadbalancers, so you can use them as 6->4 bridges.
What is the business case for all that extra pain?