Enabling IPv6 support for IPv4 only apps on Linux
pavel.network
pavel.network
clatd https://github.com/toreanderson/clatd/ is a nice and practical CLAT implementation: it does not "require" dns64 but can use it for single stateful translation instead of double
Most of the pieces are in place already but not all clients operate the same way. I think there's stil some streamlining to be done before any ISP will bother implementing such technology into their routers.
One small issue: I think T-Mobile is giving /56 but for some reason the Qualcomm 5G card only gives /64 through wwan0.
However, checking the IPv6 returned by qmi with `--wds-get-current-settings` returns a different one each time, so I think the embedded Linux inside the Qualcomm cards does SLAAC and the equivalent of net.ipv6.conf.wwan0.addr_gen_mode=3 to randomize the IID for EUI64
If v6 people didn't hate nat with the white hot intensity of a thousand suns [1] we could have had a smooth ipv6 path with the only necessary change being on consumer routers.
Come on github! It's not that hard!
Most of the services I need for work do support IPv6 and the only exceptions is GitHub.
> "Most of the apps I use support IPv6 but there are some cases when lack of IPv4 connectivity on my machine negatively affects experience."
Just install clatd to get 464XLAT so hardcoded ipv4 get routed to 192.0.0.1 (the clat iface is the default gw for ipv4) which does NAT64 through tayga too.
IMHO the best strategy is a mix of strategies:
- 1. Clatd doing 464XLAT (RFC 6877) so:
- 1.1 Stateful protocol translation (RFC 6146) at CG-NAT64
- 1.2 Stateless protocol translation (RFC 6145) at the UE
- 2. DNS64 (RFC 6147) mechanisms at the DNS server returning padded AAAA for A only entries
- 3. IPv4 embedding into IPv6 addresses (RFC 6052 section 2.2)
Suggested reading: https://www.apnic.net/wp-content/uploads/2017/01/IPv6_Migrat...
So I intentionally decided not to have IPv4 connectivity system wide to catch apps with issues in IPv6 only environment and then carefully evaluate issues and report them to authors: https://github.com/mozilla-mobile/mozilla-vpn-client/issues/... https://github.com/signalapp/Signal-Desktop/issues/4121
Dual stack setups tend to hide IPv6 implementation issues and may create illusion that app is IPv6 compatible but in reality it's not.
Clearly my setup is too hostile for home users but as developer I enjoy it a lot.
> Clearly my setup is too hostile for home users but as developer I enjoy it a lot.
If you want to discover which apps need IPv4, that's indeed a great way!
As another angle to make it even more interesting but on network scale I've implemented option for Unbound to suppress A records even if they do exist: https://github.com/NLnetLabs/unbound/pull/819 and push dual stack apps to be IPv6 only.
I'm using it to run electron-like apps, abusing Bonjour to provide .local domains with reverse (ex: spreadsheet.local could go to 127.1.2.3 if you forge and send the right mDNS packet on port 5353)
Unfortunately, I haven't found a way to do the same in IPv6: fec0::/10 for site-local address precedence 1 was deprecated by RFC3879
See my proof of concept https://github.com/csdvrx/PerlPleBean/blob/main/experiments/... and the IPv6 explanations around line 70
For your usecase, if you don't want to be restricted to ::1/128 you could maybe replace the 127/8 by fc00::/7 but it would require setting the link up while I want everything to be automatic
Like you I've detected a handful of applications that couldn't cope without local IPv4 - if they couldn't be patched they got dropped.
The issue I do hit - and report - from time to time is services that advertise both IPv6 and IPv4 addresses in DNS but do not respond to IPv6. Those are really annoying and even when I manage to get a response from the admins very rarely do they fix it either by accepting IPv6 connections or dropping the DNS AAAA record.
Another solution when emergency IPv4 is required (e.g. if the gateway has died!) is an IPv4 in IPv6 tunnel on the local network to the local IPv4-only gateway - think Starlink terminal.
This article made me put into a script the code I had for setting those tunnels up to make it easier, and avoid forgetting!
https://gist.github.com/iam-TJ/135b47d29bd8ee4e0f3330aef7324...
dig -t aaaa news.ycombinator.com @8.8.8.8 +short
Returns empty result.
Doesn't LD_PRELOAD only work for non-statically linked executables?
They should support IPv6 out of the box though.
However, if you don't need to pull in any c libraries, you can use `CGO_ENABLED=0 go build` to build completely without linking to libc on linux. It is pretty common that applications will do that if they are not using the parts of the go standard library that need libc, and don't pull in C libraries.
Does anybody have experience with this behind an ISP CGNAT network that provides IPV6 as well? I'm getting worn down from trying to deal with CGNAT and IPv4 for my homelab...
And please post the results of `dig -t AAAA ipv4only.arpa @$DNS` with $DNS being each of the DNS servers from your ISP:
"Using draft-ietf-behave-nat64-discovery-heuristic, the CLAT discovers the Pref64/n. The CLAT component sends an AAAA query to the DNS64 for the well-known IPv4-only name “ipv4only.arpa”. The Pref64/n is derived from the received AAAA response. The CLAT determines the used address format by searching the received IPv6 addresses for the well-known IPv4 addresses (192.0.0.170 or 192.0.0.171)."
Some ISP provide different pairs of AAAA depending on which of their DNS server you ask (maybe for round-robin load balancing?)
; <<>> DiG 9.18.13 <<>> -t AAAA ipv4only.arpa @8.8.8.8 ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 19770 ;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 1
;; OPT PSEUDOSECTION: ; EDNS: version: 0, flags:; udp: 512 ;; QUESTION SECTION: ;ipv4only.arpa. IN AAAA
;; AUTHORITY SECTION: ipv4only.arpa. 568 IN SOA sns.dns.icann.org. noc.dns.icann.org. 2022072100 7200 3600 604800 3600
;; Query time: 14 msec ;; SERVER: 8.8.8.8#53(8.8.8.8) (UDP) ;; WHEN: Mon May 01 14:10:21 EDT 2023 ;; MSG SIZE rcvd: 99 """
DNS2 209.244.0.3 (it's at Level3) """ dig -t AAAA ipv4only.arpa @209.244.0.3
; <<>> DiG 9.18.13 <<>> -t AAAA ipv4only.arpa @209.244.0.3 ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 14893 ;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 0
;; QUESTION SECTION: ;ipv4only.arpa. IN AAAA
;; AUTHORITY SECTION: ipv4only.arpa. 1481 IN SOA sns.dns.icann.org. noc.dns.icann.org. 2022072100 7200 3600 604800 3600
;; Query time: 10 msec ;; SERVER: 209.244.0.3#53(209.244.0.3) (UDP) ;; WHEN: Mon May 01 14:11:08 EDT 2023 ;; MSG SIZE rcvd: 88 """
Major question: is something like this feasible with Opnsense as a router, or should I only try it with a Linux solution?
Minor related questions: * How much does this complicate my firewalling? * Do I deal with firewalling IPV6 only from the outside world? * Or do I need to worry about RFC1918 addresses on my LAN "leaking" out to the IPv4 world via the IPv6 connection?
It should be possible but I'm not familiar with opensense. If you can't use clatd there, you will need some other implementation of 464XLAT.
Then, if you want to offer IPv4 on your network, you'll have to use DHCP on a RFC1918 block (ex: offer IPs in 10.1.2.3) and masquerade to the 192.0.0.1 gateway you've created with your 464XLAT implementation (whether clatd or something else)
Here you'll have to use tayga as you don't seem to have a GW provided by your ISP level3.
> How much does this complicate my firewalling
Not much. The ip4 rules would be as before, but the clat interface would be your default ipv4 route so you'd need to replace all instances of `eth0` or `wlan0` by `clat` in your scripts on the machine running clatd
> Do I deal with firewalling IPV6 only from the outside world?
It depends if you want to firewall IPv6? If you fear some services are reachable by IPv6 while they shouldn't be, use ip6tables. Just remember in IPv6 you should keep icmp flowing as it serves many purposes.
You can also decide to not offer IPv6 at all on your lan (making it IPv4 only on 10.1.2.3, with the packets going to clatd 192.0.0.1 on your router)
> Or do I need to worry about RFC1918 addresses on my LAN "leaking" out to the IPv4 world via the IPv6 connection?
It shouldn't: IIRC 464XLAT implementations will only route non RFC1918 packets. Check the RFCs if you want to be sure, or forge packets to try.
BTW, my ISP has been promising a /60 for many months now. Apparently, it's about their "provisioning software" they inherited. Huh, equipment less of a concern in this case.
export YOURFAVORITEDNS=2001:4860:4860::6464
drill -t aaaa ipv4only.arpa @$YOURFAVORITEDNS
clatd dns64-servers=$YOURFAVORITEDNS