IPv6 for local networks, makes no sense is completely unnecessary, and is a hill I will die on. IPv4 is here to stay.
IPv6 for local networks, makes no sense is completely unnecessary, and is a hill I will die on. IPv4 is here to stay.
The users are behind CG-NAT.
But instead of using IPv6 which is cheaper (no need to maintain CG-NAT, translation devices, or deal with traffic that is being routed way more expensively) the Roku devices are only streaming over IPv4.
Each new user that adds an IPv4 only device adds additional load the CG-NAT and additional capacity will need to be provisioned. That is an additional expense and burden.
Most of my traffic at my house (on Comcast) is over IPv6, because most if not all streaming services now support IPv6 for content delivery, so the small amount of data that may need to go over IPv4 when the majority can go over IPv6 reduces the load on IPv4.
Is this simply bad planning from the ISP where they didn’t handle it correctly? Or is there something I’m not understanding about NAT?
I think in an ideal world all devices would be using IPv6. But I thought it would be common knowledge among network engineers that many devices still use IPv4, so you have to either handle it somehow or tell your customers that some of their devices simply won’t work.
If you translate at the customers router that's fine and all, but now you have an IPv4 packet in an IPv6 packet, that IPv6 packet needs to get routed to a device that knows how to then turn it back into an IPv4 packet so that it can then go travel on the open internet like the electrons intended...
Once that IPv4 response come back, it needs to get translated back to IPv6, sent to the customers edge, which translates it back from IPv6 to IPv4 to send to the Roku device.
I was assuming that there was some way to translate the IPv4 address of the server to an IPv6 one and process it that way, putting the burden of supporting IPv6 on the server side. I had no idea that Roku would actually need to be exposing an IPv4 server to handle these requests.
That makes sense then that the ISP would need some number of IPv4 addresses that it could use to communicate with IPv4 servers on behalf of IPv4 client devices.
Shame on Roku for perpetuating this problem.
I'm unsure if consumer routers would pass on the appropriate RA flag to tell the OS they need to do this in their default configuration however.
HN and similar mostly-text websites would barely show up on the statistics.
When I was last working at an ISP, various CG-NAT solutions charged not just based on the connection table, but also there was various licensing for various slide-in cards.
If the ISP is having to buy additional hardware/additional ports on upstream providers just to power their CG-NAT that is an additional cost.
If the POP where you have your CG-NAT doesn't have more bandwidth available you end up running your ports hot... so now you either need to rent a new location, get your connectivity up there and start figuring out how to route the traffic.
It's not as simple, and it all costs copious amounts of money. Especially if your IPv6 can more easily be distributed across multiple POP's with multiple forms of connectivity and traffic shaped using BGP or other solutions thereby reducing the load on a single upstream port.
156.78.92.154:6781<->8.8.8.8:53 UDP
156.78.92.154:6781<->8.8.8.8:53 TCP
156.78.92.154:6781<->8.8.4.4:53 TCP
156.78.92.154:6781<->8.8.4.4:53 UDP
Can all exist simultaneously even though only 1 port is in use and we haven't even started changing the destination IP or ports yet (e.g. 80 and 443 as the destination won't double count and thousands of web servers on different addresses can be accessed via the same source port).With CG-NAT you can usually support somewhere around 30k customers on the free /24 you get from ARIN for having only IPv6 and needing space to translate in (for new orgs like new ISPs this is assigned immediately out of a reserved block, bypassing the waitlist for existing orgs trying to get free reclaimed space).
Why would you make everything gratuitously complicated by having two separate forms of addressing? All that IPv4 gains you is new and exciting ways to mess up your networking. Just give every device a normal public address (of course you probably want to firewall off inbound traffic from the WAN to the LAN, but that's got nothing to do with addresses) and have a normal network rather than some bizzare frankenstein mashup.
> Why would you make everything gratuitously complicated by having two separate forms of addressing?
How is IPv6 itself not "gratuitously complicated". You think I am going to remember the IP of my firewall, my network switch, if it is that mess of characters that is an IPv6 address? I can easily recall 10.10.10.1 is my gateway, or that 192.168.1.1 is my gateway. You think instead setting up local DNS server and domain so I can do myrouter.lan is somehow "less complicated"?
Hard pass.
https://www.ripe.net/participate/member-support/lir-basics/i...
Hate to break it to you but that is how the internet was intended to work for end-users. Firewalls are cheap and easy to install :)
So that your addressing works normally, and you don't have to deal with the same machine having two different addresses depending where you are (e.g. my photo server's address is the same whether I'm travelling or at home). Even if you only ever access your home network from outside via a VPN (which may well be a good idea), having globally unique addresses eliminates a whole bunch of possible issues - no more weirdness because the coffee shop you're in picked the same private subnet as you did.
> How is IPv6 itself not "gratuitously complicated".
IPv6 is needed for the public internet, there are just too many hosts for anything else. So you either learn IPv6 or IPv6 + another similar, but somewhat different thing.
fd65:<16-bit-mnemonic>:<vlan-id>::/56
The 16-bit-mnemonic is something memorable to me (e.g. b37a:7357 would be addressable l33tsp34k for "beta test" - that's not the one I use :P). In this case, VLAN 10 would be in the fd65:b37a:7357:10::/56. Gateway for it is fd65:b37a:7357:10::1.
It's really not harder than IPv4 for these cases.
Servers and services are assigned static IPs either via DHCPv6 or directly on the boxes (or both as I kinda use the DHCP table as a poor man's IPAM). Other devices internal IPs and globally routable IPs are assigned through SLAAC with privacy extensions where available.
Why are you so militant against the idea?
But all modem/routers are doing it anyway, they might as well do that on ipv6.
Effectively all router appliances (at home and soho level) are linux appliances, and the firewall is built into the kernel (and in use anyway).
While people may say "NAT is Not security", it is in fact a layer (ahd huge one) in the security onion, that ipV6 is likely going to increase drastically the amount of ransomware and other malware on the public internet simply because that NAT layer is gone
It was indeed a shit-show. Adding a NATting router to those set-ups instantly increased their security tremendously. Sure you could use a proper firewall, but the router w/NAT Just Works.
The problem IPv6 seeks to address has mostly been engineered around for now.
For now is the operative phrase. These are band-aids to keep IPv4 running, but they won't be effective forever.
NAT is only kind of a firewall and there have been plenty of terrible router firmwares out there that have lead people to subvert it (UPNP being one of the most problematic).
If you in your other thread don't trust the ISP device, then don't trust NAT on your ISP device either. Quite often the ISP can have their modem route traffic from their internal 10 net to your internal network if they so choose to.
Instead IPv4, or IPv6 setup to drop NEW/SYN connections to your devices via a router that you provide.
There is no logic there. firewall configuration is much harder to secure than NAT configuration.
Disagree. Just the XML parsing logic required for uPnP alone is more complex than a basic firewall implementation.
malware has connected outwards to c&c servers for more than 20 years
Neither do I, but that's a fixable situation. Get an appliance router that lets you put DD-WRT (or similar) on it. Or use a computer instead of an appliance and set it up any way you like.
I am not running a home router or dd-wrt. But I am not a typlical user going down to best buy to pick up the latest Belkin or Asus wireless AP / router combo they have on sale for $99 and hooking it up to my internet using default "wizard" settings from the mobile app...
Nor I am I trusting Comcast, or ATT to configure their residental rented equipment properly with proper firewall rules
My comment is not about me, I have enterprise grade nextgen firewalls that are $$
My comment is about Grandma that calls up comcast to have them set it all up, or Sally that is going into best buy for the "Geek Squad" so hook her up...
ipv6 most configuration end up with all devices publically routable and must have a firewall deny policy inplace to block inbound connection
Shodan is filled with people with misconfigured ipv4 routers that end up with all kinds of device that should not be on the public internet (webcams, printers etc) out there for anyone to connect to. This requires a user to actively do something on the device (most likely following a bad online tutorial) in order to port something though the NAT.
with IPv6 this problem will get FAR FAR FAR FAR worse.
No they're not. They're by default obscured, but anyone can guess your internal IP and send a packet for it, and the router will happily forward it on unless its firewalling tells it not to. And that's without even even getting into all the extra attack surface opened up by legitimate and not-so-legitimate workarounds for the issues NAT causes.
I'm only familiar with the largest ISPs in Britain, but they also have default-deny configurations on the IPv6 routers they supply. Obviously.
> Grandma / Sally
Try avoiding the casual ageism and sexism.
Try not to find offense in all things, feel free to refer to my comment thread from the other day about offense being a you problem not a me problem ;)
Just switch to it alrready.
> It's costing ISPs
I hate my ISP so this is actually a feature. If they add an IPv4 surcharge to my bill then I'll reconsider.
IPv4 has stopped working for a lot of people already, especially if they're not with a fancy-pants ISP with lots of legacy IPv4 addresses already 'in the bank'. From another discussion:
> I've actually run into this [CG NAT] helping a friend host a game server on their residential internet in a more rural part of Texas. They had to call their ISP and request a static IP address at an extra cost of something like $5/mo.
* https://news.ycombinator.com/item?id=35046929
IPv4 is also not working for the Indian reservation mentioned in the article: they had to spend >$200K to support these Roku devices.
"Just switch to it." Sure, pal, You pay all of the transition costs for everyone and you got a deal.
Not everything needs or should have a public IP address much less a bunch of IOT garbage. I suspect you, like everyone else who just says, whY aReNt We On IpV6 yEt??!11 imagine that most people's security practices are like yours and most people's ability to maintain software and security practices are like yours.
They are not.
I'm holding out for a modern address space extension conceived this century that doesn't suck, or at least a naming convention that doesn't suck. But no one will change until it's really needed and "hack" that improve the Internet, even if by accident, like NAT, can't fix it.
Except at this point the costs are reversed - IPv4 costs more than IPv6. Just look at the article we're commenting on - supporting IPv4 clients is costing them a lot more. At the same time more and more cloud hosts are charging more for IPv4. In 2023 it's supporting IPv4 that costs more, not IPv6.
If it ain't broke, don't fix it? If IPv6 brings no benefit to my LAN, why should I spend all the effort needed to shift it to IPv6? I can just make the connection to the internet IPv6 and leave everything else alone.
Although I have additional friction in my case, in that I have numerous devices that are IPv4-only. So no matter what, I'd have to at least have one LAN segment that is IPv4.
The thing is you really don't realize how shit your network experiences are because of this. Everyone is just attempting to tunnel more services via HTTP/HTTPS and the particular fun problems that entails rather than having byzantine hacks built in to their NAT routers. IPv4 is no longer fit for purpose.
But in my LAN, there is no IP address exhaustion. I have orders of magnitude more IP addresses than I'll ever use. IP address exhaustion applies to the internet at large. I'm not talking about that.
In the internet at large, IPv6 has to happen. In my LAN, I don't see a need for it. I can route between the IPv4 endpoints in my LAN and the IPv6 endpoints on the internet.
And because I have IPv4-only hardware on my LAN, I need an IPv4 segment to support it at the very least. So why not keep the entire LAN IPv4?
As long as you never VPN into or out of another network whose administrator thought the same thing. But yes.
> And because I have IPv4-only hardware on my LAN, I need an IPv4 segment to support it at the very least. So why not keep the entire LAN IPv4?
v6 uplink is going to increasingly be cheaper and/or faster than v4 uplink (as with the issue in the article), so presumably you'll want to run v6 on your LAN at least for the devices you game/stream from (and sooner or later there will be v6-only services that you want to connect to). I would think that any device not supporting IPv6 is so obsolete/unsupported as to be dangerous to connect to the internet, so you already need to deal with having two distinct segments on your LAN. But sure, if you've got good v4 uplink at a reasonable cost then no need to migrate yet.
We had every host on an IPv4 address at the University of Washington back before 1998 and NAT was actually banned by the CAC Department since they billed by number of nodes on the network, so NAT was a way to cheat their billing system.
I learned quite a lot of internet security from having 1998-era Unix servers hanging directly off onto the internet with no firewall or NAT.
Which leads me to believe that the main barrier to IPV6 is just that people don't want to re-learn anything.
I disagree, actually. I think the main barrier is that networking folks have been pretty bad at explaining this to non-networking folks. IPv6 isn't exactly simple to understand.
I'm a reasonably network-savvy guy, and I'm sure that I understand less about IPv6 than I think I do. I just don't know what parts I'm not understanding properly, and what parts I just don't know about.
It's pretty hard to find good explanations of this stuff that aren't aimed at networking experts.
I get tired of this "I'm an expert you're an idiot" trope that comes up about it. Here on this damn website you have people who hack kernel, people who manage massive databases, people who hack front end stuff that scares me, experts in functional programming, language designers, fpga designers... In short it's very, verry flipping technically adept crowd. You didn't reach them.
Networking "experts" who want to blame everyone else for a lack of understanding need to look in the damn mirror and ask themselves "How did we fail so very, very hard at explaining this stuff?" "Why are we not able to provide a link to an article with an estimate of time taken for everything you need to know about ipv6 to use it exclusively?" "Why don't we want to make this easy for everyone?" "Why can't we be minimally polite?"
I'm an expert in being a jerk on occasion and this occasion the "Everybody else is stupid and lazy because they don't understand it's not us at all" trope is definitely being a jerk. And I'm jerk enough to point it out.
The end result is that they will continue to object to the thing, but won't raise their objections to the experts anymore. And why would they? Nothing good came from it the first time.
It turns what should be a cooperative relationship into a combative one. I see this happen in pretty much every discussion of IPv6 around, including this one.
The other issue is that the subject matter experts rarely actually explain anything. They just toss out acronyms and buzzwords and consider the matter corrected. But it's not -- they're talking as if their audience is another subject matter expert, when it's usually not. Acronyms and buzzwords mean little to them.
And telling them to "google it" likewise does little good. The audience isn't a subject matter expert, doesn't want to be, and shouldn't have to be. If IPv6 really is so complex that you have to be an expert in order to use and configure it properly, then isn't that a problem with IPv6?
My assumption is that's not the case (but I'm not sure on this point), but instead, the experts are failing to actually teach people about this stuff.
In the end, I blame the rollout of IPv6 itself. Exactly zero attention and effort was paid to evangelizing and educating people about it. There was no gradual rollout plan put into place and encouraged.
The IPv6 rollout effort failed to do the things that are necessary to facilitate a shift of this magnitude. This makes the whole thing very confusing and leads people who aren't elbows deep in the topic to lean toward "I don't feel that I can do this safely, so it's better that I don't do it at all". Which is not an unreasonable stance.
The tragedy is that it all could have gone so much better than it has. It could have been a thing everyone unified about rather than a thing that is rapidly becoming a kind of holy war.
"You're gonna move your home network to ipv6, here's what you need to know to not f&^k up hard and get pwned" At the level like we know for ipv4.
Right now, I actively disable ipv6 in devices on my network because I don't have a clue about how it all works. Am I making something addressable from the public internet? Am leaking every mac address I have? So much more I'm sure I havent even considered.
Then when you look at ipv6 tutorials you see nuts things like each octet containing a zero value can be shortened to just a single zero :00000000: becomes :0: ok fine, but consecutive octets of zero are removed so :00000000:00000000: becomes :: swallowing a delimiter so programming this stuff you can't even just split on the delim and /know/ what octet is where. Now maybe theres a good reason for that but where is the explanation? Not in any of the tutorials that have to explain how this stuff works rather than something, you know, useful. As presented it's pure additional, utterly meaningless, learning overhead.
So yeah. I'm too stupid to run ipv6 and I know it. But I'm not nearly as stupid as those who claim it's ready for prime time because it damn well isn't.
Anyone thinks it is. Link the document with a time estimate on running a home network with ipv6 knowing what you need to know (and know already for ipv4) to not do something idiotic.
In this crowd, we'll learn stuff just because it looks cool and you can't reach us? Get outta here.
I didn’t think it was even possible to have DOCSUS3.1 without IPv6 :S
Even if that price decreases in real terms, washing a whole bunch of traffic through a big-ass NAT is always going to cost more than just not doing that.
That's a lot less than the cost of an Apple TV.
This is a position of privilege. The developing world would like access to the Internet and lack access to the (mostly) exhausted IPv4 space. Should we not work to make Internet access ubiquitous?
my mobile phone in the UK on one of the big 4 carriers only has IPv6 addresses
and only has IPv6 connectivity
(using 464XLAT)
Ditto for NAT, where devices can reach v6 endpoints (though stateful firewalls should stick around!).
Honestly, I really hate change. but ipv6 does have some upsides and rather than complicate things, embracing actually simplifies things.
The issue is that we have a lot of sunk cost on how we bolt on shit to ipv4 to make it passable in the modern day, and we begrudge having to relearn what we think is solved.
IPv6 makes sense everywhere.