Czech republic sets IPv4 end date
konecipv4.cz
konecipv4.cz
But the thing is, even though IPv6 is such well established tech, it was not a great migration experience.
I'm not a network engineer, and you have to figure out how to update a bunch of networking configuration to make this switch on an existing instance, with lots of potential footguns. Even after I got the IPv6 address provisioned and the virtual networking correctly configured, the connectivity was still broken until I found an obscure security group setting that was still set to allow only IPv4 traffic. A lot of basic debugging tools like curl are designed to use IPv4 by default. You have to figure out how to get your webserver (nginx in my case) to listen on the IPv6 interface, which is fiddly. And it's easy to inadvertently break ssh connectivity, which turns out to also be set up to expect IPv4 traffic only...
In the end, it took about 90 minutes of fiddling, including migrating to Cloudflare, fixing DNS, etc. I mean, it's fine. I learned some things.
But if we're all going to switch to an IPv6 world, it would really be nice if the systems and tooling made it slightly easier, somehow.
Amazon is horribly behind on a lot of things (just look how long it took them to get DNSSEC working, and it took them a couple of tries to not break entire domains for people using it!). They're ahead of Azure, but that's about the best you can say about that.
I suppose it makes sense, IPv4 addressing is now an additional method to make money for Amazon, so why make it easy for customers to migrate?
If AT&T and AWS went IPv6 by default, most of the US would convert over quickly.
Comcast and the mobile carriers went ipv6 years ago, that's already something like over half the US endpoints? It hasn't sped adoption (Github STILL isn't ipv6 for git).
Another example, I've been trying to get Georgia Tech to fix their ipv6 linux mirrors for over half a year, they advertise they support ipv6 and publish AAAA records that don't work. http://rsync.gtlib.gatech.edu/ < check it out.
So yeah, even when it's deployed nobody checks to see if it's still working when ipv4 is fine.
It's not the only issue it has continued to have.... https://bugs.gentoo.org/585524
I'll continue to follow up here, but it seems like an actual human has read the message this time.
Any word? Why not look up email for one of the staff here https://www.pace.gatech.edu/staff seems like they unfortunately don't check any of the primary emails for the mirror as we've not heard from them in a year or two.
Again, we get it if they have upstream issues not being able to support ipv6, but drop the AAAA records and stop advertising it if that's the case, that's not a big request.
Well, their default images come with a script that'll allow you to `sudo -H enable_ipv6`, but I removed their customisations so I had to do it manually.
They have raised their prices since I last ordered a server there, it looks like €5,45 is the cheapest server you can get these days (includes VAT of course).
Ideally it'd be 5 minutes (1 minute to locate and click a checkbox, 4 minutes to test all services from a few locations), but this is still fast. It includes zero tech support tickets, for instance.
This has more to do with AWS, less with IPv6.
(And "NAT gateways are an extremely cost prohibitive device in AWS, costing at least as much per day as medium sized EC2 instances!")
Which setting was that? I've had 0 issues with IPv6 on EC2 for a while now. Not all services support v6, though, but that's a separate issue.
It was very informative, and I also found out they offer free courses about IPv6 networking, with certificates included.
I think CZ.NIC offers something similar, but they should be promoted more often so sysadmins can prepare themselves for the eventual shutdown of public IPv4 addresses.
I'm sure that many HNers would appreciate the information here, but if you prefer my Gmail username is the same as my HN username. Thank you!
https://www.knowmatic.app/how-to-migrate-aws-ec2-instance-fr...
I didn't find such great docs on the Cloudflare part, but some of these were useful:
https://www.reddit.com/r/selfhosted/comments/14d16lt/if_i_on...
https://community.cloudflare.com/t/the-page-isn-t-redirectin...
https://stackoverflow.com/questions/4616521/nginx-configurat...
https://developers.cloudflare.com/support/troubleshooting/cl...
Actually, why doesn’t Apple mandate the IPv6 transition for iOS?
At roughly the same time, Android added 'clatd' so existing apps would just work in an IPv6-only environment via NAT64.
Apple refused to implement clatd, instead forcing app developers to fix their own code. More work upfront, but now iOS apps should have an easier time transitioning their server-side components to IPv6, compared to Android apps.
I would go back to the 5/mo VPS if it became clearly better than the alternative. I don't really need an IPv4 for what I use it for, though, as long as someone else wants to provide an inexpensive (or free tier) proxy service.
It's actually not, and I think you learned that, and why it's not, in this process. Sorry.
IPv4 is 43 years old
But even that was negligible since nobody actually had IPv6 connectivity. Even now I still don't have a home wifi router that supports it, though at least my ISP does since last year.
The real driver of IPv6 was the rise of smartphones.
Hmm, I just went deep into the settings and there's an IPv6 toggle (disabled by default, and requires playing with menus to make it actually work) now. I don't remember seeing that (and I explicitly checked) when we switched the ISP-side last April. But the firmware is dated after that, so I choose to trust my memory.
Actually trying to connect to ipv6 stuff besides the router itself (in fd00::/8, that's good) just gives "Destination unreachable: Beyond scope of source address" though (probably because I only have an fe80 link-local address though?). If I play with the settings some more I get a ::/64 address, but that just gives me a black hole ... wait, is that even a legitimate address? Do I need to fill in the prefix manually or something?
I'll play with this some more in the morning I guess. But I certainly wouldn't expect a normal user to get IPv6 working under these circumstances if I haven't figured it out yet ...
Turn IPv6 with stateless RDNSS on (should be the default on all modern routers)
ping6 google.com
That's it as long as your ISP supports IPv6. No need to figure out a fd00::/8 that you maybe may not have.
> sudo ping google.com PING google.com(par21s03-in-x0e.1e100.net (2a00:1450:4007:810::200e)) 56 data bytes
I'm testing with `ping ipv6.google.com` as well as the router IPs. Between each change, I disconnect from wifi.
The router itself has a ping tool and can ping ipv6.google.com just fine. So I assume the upstream options are correct.
For the LAN, I have 4 options:
* ND Proxy gives me an fd/8 address. I can ping the router via its fd/8 or fe80 address, google blackholes.
* DHCPv6 gives me an ::/64 address. I can ping the router via its fd/8 or ::/64 addresses, google blackholes
* SLAAC + Stateless DHCP does not give me any address (I still have the default fe80 address). I can ping the router via its fd/8 or ::/64 addresses, google gives Destination unreachable: Beyond scope of source address
* SLAAC + RDNSS does not give me any address (I still have the default fe80 address). I can ping the router via its fd/8 or ::/64 addresses, google gives Destination unreachable: Beyond scope of source address
In all cases, the IPv6 addresses the router says are its DNS servers blackhole. I do have working DNS returning IPv6 address for google though; presumably because the ipv4 DNS server it advertises (which is the router itself) still works.
If I bypass the wifi router, the ISP router gives me both an address in both fd/8 (in the same /64 as the wifi router gets assigned, which makes sense) and in 2607/16, besides the usual fe80. The ISP router is really bad, all it has is an "it's connected" indicator and a bunch of phone numbers and URLs for support.
Still bypassing, pinging `ip6-allnodes` gives me 3 responses, all with fe80::/64 addresses: my computer, an unknown, and the wifi router; I can ping those addresses, as well as the wifi router's fd/8 address.
Maybe I should play with the router's upstream settings ... "Get IPv6 address" has auto, slaac, dhcpv6, non-address ... since I can ping it from outside that has to be right. If I disable "Prefix delegation" the ::/64 box is editable but it complains about literally anything entered. And I don't have anything meaningful to manually enter a DNS address.
Hm, I just noticed that the last bit of the router's address varies between some of its addresses ...
Do you have any smart home devices? Protocols like Thread and HomeKit establish their own randomly-generated ULA prefixes and advertise them through RA’s (router advertisements) and correctly-configured devices in your LAN will observe the RA for that network and generate a local address for it (including your router.) So just seeing a fd/8 address doesn’t mean your actual router gave you it, it just means that something on your network is using a ULA prefix.
Basically, it’s possible the real problem is that you’re not actually seeing an RA from a “real” (routable) IPv6 subnet when behind your router.
> If I bypass the wifi router, the ISP router gives me both an address in both fd/8 (in the same /64 as the wifi router gets assigned, which makes sense) and in 2607/16, besides the usual fe80
When you do this, can you ping out? (`ping6 2607:f8b0:4004:c17::65` or something to rule out DNS issues.)
> Maybe I should play with the router's upstream settings ... "Get IPv6 address" has auto, slaac, dhcpv6, non-address ... since I can ping it from outside that has to be right. If I disable "Prefix delegation" the ::/64 box is editable but it complains about literally anything entered. And I don't have anything meaningful to manually enter a DNS address
What you want here is dhcpv6 and prefix delegation. This will make your router ask the ISP for a real IPv6 network to use, and upon receiving this from your ISP, will send RA’s out to your local network for a “real” (2607/16 or whatever) network. A prefix length of 64 should do it, unless you need multiple subnets inside your router. (People say dhcpv6 is obsolete by SLAAC, but prefix delegation is a different thing… if you want to have your own router obtain a network prefix from an ISP, DHCPv6+PD is the only way to do this.)
2012? Wow, that's pretty bad. We were talking about how ridiculously slow IPv6 rollout was while I was at university, and that was 2002-06.
As a fun aside, global smartphone sales in 2021 were 1.4Bn units. That alone is enough internet devices to exhaust the entire IPv4 address space every three years. I wonder if anyone was imagining that 43 years ago.
https://www.gartner.com/en/newsroom/press-releases/2022-03-0...
It's fine. The only breakages I've had are when the ISP's v4 DHCP goes down (v6 websites keep working) or when IPv6 delegation fails somehow and my machines lose v6 (v6 only stuff breaks).
Your mobile phone probably already uses IPv6 (especially if you use VoLTE) and it's fine, too.
What made me disable it was some issue in Linux network stack, with ipv6 broadcast, on by default, exploitable to root execution.
For me it is yet another complex service that I do not need, and that should not be exposed to network. Ipv4 network stack code is far smaller, simpler and way more tested over decades!
"We will accelerate the large-scale deployment of 5G networks, increase the user penetration rate to 56%, and promote the upgrade of gigabit optical fiber networks. We will build up technology reserves for the future deployment of 6G network technology. We will expand backbone network interconnection nodes, set up a number of new international communication gateways, and comprehensively promote the commercial deployment of Internet Protocol Version 6 (IPv6)."
There is a migration schedule.[2][3] As of this month, there are supposed to be no new IPv4 services. The goal is IPv6 only by 2030. Actual adoption in China is reportedly only 25-30%, though.
[1] https://cset.georgetown.edu/wp-content/uploads/t0284_14th_Fi...
[2] https://blog.apnic.net/2019/06/06/100-by-2025-china-getting-...
[3] https://www.theregister.com/2023/04/28/china_ipv6_control_ad...
https://stats.labs.apnic.net/ipv6/CN
I don't call this abysmal at all. It very possibly is higher, there are reasons why APNIC may undercount, but noting that APNIC and Akamai tend to agree on their numbers.
Google's own numbers for China are far lower for reasons which do not affect the APNIC or Akamai data.
1. Most Chinese websites or apps don't work properly or at all in a pure IPv6 setting. They claim to be IPv6 compatible, but have a lot of problems (e.g. images not loading).
2. Most Wi-Fi networks (be it home WiFi, restaurant WiFi, hotel WiFi, school WiFi, etc.) have no IPv6 addresses. Half of the IPv6 enabled WiFi networks I've ever seen are set up by myself.
Not nothing, but the adoption rate of IPV6 on computer side is still very low.
I believe 80% or more of the planets internet is handhelds.
You think the US home users on comcast are all PC's?
More on the technical side. Most of mobile devices and their modems need (or even allow) zero to no manual configuration, so adopting ipv6 with these hardwares are easy -- the ISP just need to deal with their side.
This is in contrast to "fixed-line" internet devices like computers and their routers.
Non-casual computing and multiple screens. ex: Work, research, editing, complex creation, engineering...
Mobile can sometimes touch those things but the core is mostly done on desktops.
Also, in a country of more than a billion people, most of whom use the internet with at least 1 device, IPv4 quickly leads to address shortages.
You can't find me a single sysadmin or casual user who would look at an IPv6 and say, nice, I prefer that one over an IPv4 or find it easier to type or communicate.
You can argue about merits of IPv6 and very reasonably so all day long, but this fact remains.
I don't think governments or other institutions can strong-arm IPv4 out of existence. I don't know what the long term solution would look like, but I strongly doubt it will be IPv6-only. Ever.
Take `2001:db8::1`. Here `2001:db:8` would be your network address and `1` your host-id. For example, a router. `2001:db8:2` could be a server and so on.
And yet still, nobody cares.
Hundreds of million of users in Africa that are growing at a very fast pace, still on IPv4.
In Europe outside Germany and Belgium, the IPv6 usage is between 5-20% max. Millions of people.
There is also millions of industrial systems, ATMs (heck, some of them still run XP!), and whatnot that will not get IPv6 short of complete replacement.
You can't price IPv4 out with that kind of numbers combined with the fact that it is an extremely open market.
just look at the ND table. Nobody is ever going to scan a single /64 of v6, ever.
...
how would configuring DNS even work without having to see the addresses, and how would SSH'ing to a device on the LAN work without seeing the addresses
...which a local IP address is, conveniently
I'm not willing to spend the time to set it up on my internal network until I start to lose connectivity to some places, sorry.
When people tell me ipv6 is already widely used, I ask them what name I should use when I want to ssh to their ipv6 device, their phone for example. People don't notice ipv6 isn't working because the Internet has evolved into a world of two classes of people, the rich and powerful like Amazon with addressable IP endpoints, and the second class citizens like you and me who can only connect to the rich and powerful, not to each other.
Problem is, that's not my only fiber. I have two from different ISPs (Romania, so they're cheap). With ipv4 i only need to change the default route to the other router to choose which ISP i use. With ipv6 where my internal machines get an address from the ISP, i don't know where to start.
And I definitely don't want to spend a couple thousand on an "enterprise" multi home router that will do it for me...
No shit Sherlock: an IPv4 is 4 bytes. An IPv6 requires 16. This is four times as much data, it has to be less readable, that’s just the price of a bigger address space.
Now one could have argued that 8 bytes, heck, even 6 bytes, would have been enough. I guess it would have, but having a /48, or even a /64 range, per user, is quite convenient: we can ditch the NAT (we probably won’t, but we can).
But even then, 8, or even 6 bytes, remain harder to read than 4.
If it were 16 bytes, the other options from the same 16-bytes space would be, for example, "\xa3\x80W%\xa3\x82\xa1\xea\x10\xf9\x8b\x07'\xf93J" or "\xf0\xef\x9b\x8f[0\xe5\xb9,\x0b\xd4^\xb00\xed\x00" (chosen by a fair /dev/urandom roll).
If you want to convey 16 bytes using similar encoding, you need to use about 10 to 12 human words -- see for example Bitcoin wallet 12-word seed phrases or https://xkcd.com/936/ (xkcd correct horse battery staple).
For IPv6, if your addresses are not SLAAC, but DHCP or manually assigned, you can go with half of it - the "random" part is the 64bit network prefix.
Or if you want mnemonics on your /64:
[prefix]::dead:beef:1 [prefix]::b00b:1 [prefix]::b00b:2
etc
Or simply just /think/ of it as a /112 subnet with [prefix]::0001-ffff available - still room for 65535 addresses in that one, more than I'll ever need.
No need to rely on long autogenerated SLAAC addressses if you don't want to, you can have whatever you want after your prefix and you don't have to pad it out with garbage random-ish values. A sysadmin can get creative :)
Of course your ISP will need to have proper v6 support.
Also, in our desktop/laptops, we set the DNS servers to an IP address, not to a hostname.
What? This comes up in like 95% of ipv6 threads on HN (see also: ‘they should have just added an extra quad to v4 addresses’)
My grand father used the dots in the address!
My father used the dots in the address!
I used the dots in the address!
Henceforth every human being should use the dots in the address till heat death of the universe!123.123.238.217.110.100.1.1 would still have been perfectly readable.
fdd2:1228:3372:1sdf meanwhile is pretty unreadable even at IPv4 length.
123.123.238.217.110.100.12.255.123.123.238.217.110.100.242.176
On 17 January 2024, the Government of the Czech Republic approved the material "Restarting the implementation of DNSSEC and IPv6 technologies in the state administration". On the basis of this decision, the Czech state administration will stop providing its services over IPv4 on 6 June 2032. Thus, the Czech Republic knows its IPv4 shutdown
Oh, for all of those that keep saying it will take forever for the USA to switch to IPv6 follow the link with your cell phone.
https://www.google.com/intl/en/ipv6/statistics.html#tab=per-...
More than that though, IP addresses in both v4 and v6 varieties are unreliable sources for tracking and basically no actor you'd want to guard against depends on them anyway. With mobile phones being common, your public addresses are changing all the time anyway. On IPv4, CGNAT is becoming increasingly more common so that you might share a public IPv4 address with thousands of other people at the same time.
Which is an advantage from an anti-tracking perspective — an advantage you won’t get with IPv6, no?
Another very strong counterpoint to this is that, you can't really build a truly-P2P network nor self-host a service on Internet, when everyone is behind CGNAT. At some point, as IPv4 resources get scarcer, only corporates will have the ability to host services on the Internet, and I don't think it is in their interests to host Tor nodes, for example...
Depends. It makes it harder for someone outside your ISP to track you, but it makes it easier for your ISP to track you, and harder for them to justify not keeping logs of where you've connected to (since that data is necessary for their CGNAT system to work).
Great, so I can't connect my laptop to my desktop across reboots without setting up some internal dns?
inet6 2406:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:62c9/64 scope global temporary dynamic
inet6 2406:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:a31c/64 scope global dynamic mngtmpaddr noprefixroute
Temporary IPv6 address changes every now and then, but your stable IPv6 address will never change unless your ISP changes your prefix, you change your network, or your network card entirely.When you are browsing the internet, the OS will use the temporary address for outgoing connections (unless the application forces stable addressing). But when you are hosting a service, you give your users (in this case, your laptop) the stable address.
With limited IPv4, many places have dynamic IPv4 in a way or another, or have IPv4 behind some sort of NAT, so the actual IP of the accessing device may be hidden, or are private addresses. Anyway, that doesn't mean that i.e. your ISP couldn't be asked what person was using certain dynamic IP at some time.
With IPv6 it depends on implementation. Your device may have a public IPv6 address, persistent or not, and you don't need to be behind some sort of NAT (unless it is something to access ipv4 addresses), so if a lot of those conditions apply you might be tracked.
But there is a lot of conditionals in both sides, and the elephant in the room is that you are tracked for more things than just your IP address.
Of course, all of this needs to be included in a broader discussion around myriad vectors of tracking and fingerprinting to arrive at a meaningful conclusion.
All the tricks for anonymizing IPv4 (VPN, NAT, Tor, etc.) are equally feasible on IPv6.
practically irrelevant thou, because your browser is a much better source of fingerprinting data
BTW the full name includes the definite article, so it is "the Czech Republic".
Funnily enough the distinction between regions exists in english language - Bohemia being the name of the region. So Czechia as name for country could work. But in czech language word for Bohemia region is "Czechia" (there is no Bohemia).
So thats why for years you had people insisting on the Czech Republic. Because you don't want to overlook the other two regions Moravia and Silesia.
No. Bohemia is Čechy, Czechia is Česko.
Yes, they are sometimes confused, and maybe people are unhappy with Česko because it's just too similar to Čechy. People from Moravia and Silesia feel underrepresented when someone mistakenly uses "Čechy" (Bohemia) for the entire Česko (Czechia; Bohemia+Moravia+Silesia).
Sure, you can do a IPv4 VPN with your friends, but that means no more games with strangers over the internet.
And even if ISPs stopped issuing IPv4 addresses to end users, there's nothing stopping anyone from setting up a public VPN into an IPv4-based virtual LAN -- if there was demand for it, it could easily be offered by the same services you're currently using to find "strangers over the internet" right now.
Not that I think we should entirely/forcefully remove ipv4, but saying that it's going away will force ipv6 migrations
For the Internet use, it's mostly just more addresses to me, but on LANs, there are so many more useful features. Unique link local addresses, various multicast addresses...
I can drop 10 new devices into a VLAN, and ping ff02::1%iface to enumerate them all and start communicating with them right away without any kind of configuration, not even SLAAC or DHCPv6 needed.
Why the desire for a NAT? It's technically possible on IPv6 too (NAT66), but SLAAC dynamic addresses + a non-NAT firewall + possibly ULA are generally a better way to get the combination of privacy + security + local addressing I think most people associate with NAT in IPv4.
Well for me until Linux shall support IPv4 my machines shall be on IPv4 behind NAT. And yet I'm enjoying IPv6 with my ISP-provider router transparently doing the heavy lifting and using IPv6.
> and completely block outgoing and incoming per-device-IPv6.
Same. I do just that: it's disable by a kernel parameter, in sysctl and in the firewall, just in case I'd mess up and re-enable one or two of these.
You can pry IPv4 on my LAN from my cold dead hands.
If you want to avoid v6 altogether, you can use a proxy on the machine you're currently calling your router, and configure all of your programs to use the proxy. But... nobody wants to use proxies.
Two years till it becomes illegal to offer something on IPv4 for the general public and not offer it on IPv6, two more years and no ISP may route IPv4.
Also no ISP NAT bullshit. A default enabled firewall refusing incoming connections is fine, but the internet should be a network of machines that can talk to each other, and for that to happen it must be possible for owners to accept incoming connections, even if it is for nothing more than remote access to their PCs.
Their real reason though will probably be that the truly peer-to-peer networks enabled by a world free of NAT and symmetric bandwidth would undercut their precious market.
Finally, I’m not sure our governments would like the rise of Anarchist networks where speech is so free they can’t even control it. See all the attempts to criminalise or put limits to encryption. Such things would never happen under democracy, but the representative governments we live under are a little different. (Historically, representative government was conceived in explicit opposition to democracy, and democracy lost.)
Why? Is there any pressing need for ipv6 only connectivity that you'd make ipv4 only illegal?
> the internet should be a network of machines that can talk to each other, and for that to happen it must be possible for owners to accept incoming connections
The importance of this is quite obvious if you’re politicised enough. Stuff like Free Speech.
But in the EU speech is restricted and hostings won't kick you out unless you say something illegal... and at that point you'll be in trouble hosting stuff using your home connection.
And while Europe is more restricted than the US, it is not like we are the Soviet union.
So no, it does not mean screwing over the poor.
But for some things you are dependent on others, for instance, the colo not having IPv6. (and in th case of Internet.nl: IPv6 for email is still opt-in on request with Office 365, DANE is not supported yet, etc)
8 years is plenty of time to make the transition even for a government, right?
Five years is a long time, let’s work on other things.
Three years isn’t terribly soon, it’ll probably be fine.
Two years is getting close, let’s consider checking.
One year is too close, let’s ask for an extension.
AFAIK they allowed extensions for vendors in 1990 and that's why original EOL date for IPv4 continuously slipped until success by Network Translation and its PIX devices helped kill the attempt completely.
It's the BSD Sockets using code that is a problem - the OSes has supported v6 for a long time now.
I've heard that under 10 years is the optimal for a long term government project. Anything longer, and it's equal to "forever," and it's never done. This was the rationale for setting the goal of landing on the Moon to within the decade.
More last week: https://news.ycombinator.com/item?id=39060187
Read for example https://www.whitehouse.gov/wp-content/uploads/2020/11/M-21-0... (does anyone have more recent ref?)
Call me a dumb hippie.
Of course, if that hardware needs to access IPv6 services, they might as well disable IPv4+ICMP+DHCPv4 support and enable the IPv6 size in firmware, and probably get similar savings.
To be honest, I'm not sure why companies still ship ESP32-like hardware with that little storage given how cheap flash storage is, but these optimisations are more common than one might think or hope.
Publicly reachable IPv4 on the consumer side is dying rapidly, but IPv4 LANs and servers can still work exactly because of the versatility IPv6 allows.
Wait a minute, kilobytes? That much? It’s not like one needs to duplicate the entire IP layer, it seems to me the only changing parts are parsing & generating the packets.
The documentation for ESP-IDF (https://docs.espressif.com/projects/esp-idf/en/latest/esp32/...) says:
> Disabling CONFIG_LWIP_IPV6 can save about 39 KB for firmware size and 2 KB RAM when the system is powered up and 7 KB RAM when the TCP/IP stack is running. If there is no requirement for supporting IPV6, it can be disabled to save flash and RAM footprint.
> Disabling CONFIG_LWIP_IPV4 can save about 26 KB of firmware size and 600 B RAM on power up and 6 KB RAM when the TCP/IP stack is running. If the local network supports IPv6-only configuration, IPv4 can be disabled to save flash and RAM footprint.
IPv6 takes up more ROM than IPv4, and as far as I know ESP-IDF doesn't actually fully support IPv6 either.
At this point we're talking microcents of storage, but unfortunately the 13KB of size difference can make the difference between "the code fits" and "we need to spend a dollar more per unit".
I'm not talking about just phones, tablets, and laptops.
Then there's a veritable black hole of various crappy security cameras, IP phones, and WiFi printers. And they can live for a veeeeery long time.
And I don't think I've ever seen a hotel network with IPv6 support. And I've actually seen a hotel (in Palo Alto) that gives out real IPv4 addresses to clients.
This is also about the Czech government sites removing IPv4 support. What devices that would be used to access site won't support IPv6? They all do today.
This said, by then, maybe the core OS will not be metal, but Linux on all these device and we'll get top ipv6 support.
More likely, in 2032, well have a bunch of crap, built from very old SOCs running Linux 2.4.
“DAD, YOUR SPRINKLERS ARE HACKING THE RECYCLING COLLECTION TIMETABLES AGAIN”
(spend enough time around places like this, though, and one could easily imagine this being a thing in 2032)
That said, I have to imagine that there probably are plenty of those devices that do access Czech internal services at least.
Something like 0.0.0.0.0.0.0 and everything without the correct number of octets just gets filled with zeros. So 192.168.0.1 becomes 0.0.0.0.192.168.0.1. Then also don't give out /8's to universities and the like (repeating old mistakes).
This is probably naive, but it seems it would be easier for people to use vs. 2661:919a:023e:911a:44dc:f656:233e:8816
Are you going to lie and tell it it's 1.1.1.1? Congrats, you've just reinvented NAT. Enjoy your stateful boundary system and all that complexity again.
Are you going to add some extension to IPv4 and try convince everyone to upgrade all their hardware, software and configurations? Then you have the exact same problem IPv6 adoption had, except IPv6 adoption is at like 45% globally and your new scheme is at 0%: https://www.google.com/intl/en/ipv6/statistics.html
If you have some other idea, make sure to check it against the list of IPv6 transition mechanisms before commenting - it probably exists for IPv6, and ultimately all of them have been displaced by dual stacking: https://en.wikipedia.org/wiki/IPv6_transition_mechanism
> link -> The graph shows the percentage of users that access Google over IPv6
How does this work in practice, does user equipment end up with dual IPv4 IPv6? if not how do they access IPv4 only sites (of which there are still plenty)?
Alternatively, cellular ISPs may make use of NAT64+DNS64. In this case, the IPv4 addresses are combined with a NAT64 prefix (most likely 64:ff9b::/96), producing addresses such as `64:ff9b::198.51.100.1`. It is effectively the same as CGNAT, but pretty much everything is single stacked IPv6 up to the IPv4<->IPv6 border relay in the ISP network.
Yeah, so I'm going to say that's just not true. If IPv6 had been significantly simpler (e.g. by mainly focusing on increasing the address space) then adoption would be much higher today – probably universal. The problem is that IPv6 changes a lot, and that implementing it is a fair amount of work. The entire business with tunnel brokers and other compatibility schemes are complex and difficult to use.
To completely change gears now would be silly and too late, but it's been almost 30 years and it baffles me how anyone does not consider the entire thing a spectacular failure. People use Python 3 as a warning about compatibility, but IPv6 is a much larger catastrofuck, and that's largely due to decisions IPv6 people made. Whether IPv6 is "better" or not doesn't even come in to play.
(Shrug) It works. What problem is being solved here, again?
And porn for those who like overcomplicated 'enterprisey' solutions where they aren't needed.
IPv6 is 128 bits... so we already made a change. Why can IPv7 not be 128 bits as well, but vastly more readable/recognizable than IPv6. Hex is hard on the eyes, especially for those who don't stare at it all day.
I'd argue that the most common format such as 2001:db8::f00f is already pretty darn readable, and not hard to copy+paste when you need bare addresses. Base85 is an alternative if you'd like something that's purely optimized for fewer characters, but it only really helps with exceptionally long addresses like 2001:db8:424b:b4ff:fcb5:b643:f721:b703 becoming 9R}vSk6QzV!G$<lwB;|~
Memorize that :) Then try to tell it over the phone.
But also do you think 24414.64517.21200.44298.46574.49887.23623.7394 is really that much easier to type? Or 231.22.96.68.14.229.38.41.242.44.72.220.156.50.232.95 if you keep to 8 bit octets?
But -
> The move to hex is to avoid people having to memorise all these offhands
Point taken. It does seem in practice though people will still have a need to memorize/recognize addresses for various purposes, such as administration/dns/etc.
I mean... yes, actually; I can type those blindly on a normal numpad. I'm sure somebody somewhere has made a hex number pad, but realistically on any normal keyboard entering hex means going back and forth between number and letter keys.
(There's already at least 4 different ways you can write an IPv4 address, and your OS is happy to accept any of them.)
[ff00:abcd::0]:1234I think the reason they needed to use a different delimiter is because IPv6 addresses can also omit entire portions of zeros as a convenience feature to shorten addresses, which means there are a subset of shortened addresses that look exactly like IPv4 if not for the delimiter.
It was entirely inappropriate for small scale personal networking and assumed an "administrative scope" that's too cumbersome and without purpose for most implementations.
I wonder if a dedicated "local" network prefix with a fixed /64 mask and an operating system recognized "alias" would have been a good mechanism to introduce. Something like fec0::/64 with an option to call it "local::". Then you might be able to more easily move from a world of 192.168.10.1, 192.168.10.2 to a world of local::1, local::2, that being translated to fec0::1 and fec0::2.
Thankfully there is near-100% compliance with PTR reverse-dns for IPv6 addresses and networks. /s
https://www.google.com/intl/en/ipv6/statistics.html ~50% worldwide with lots of countries way over that is not what I'd call awful.
> introduce IPv7 and just extend the IPv4 scheme?
Every proposal like that requires changing all the routing hardware anyway, because we effectively ran out of bits in the IP packets to mark anything new. And once you need to change hardware, you may as well just go with a better designed protocol like ipv6.
> This is probably naive, but it seems it would be easier for people to use vs. ...
People don't use IP addresses anymore. DNS and local discovery covers this for anyone apart from geeks and IT people. If it doesn't, it's a bug at this point.
IPv6 was drafted in 1998, and ratified in 2017. 7 years after becoming "official" only 50% adoption rate world-wide is not what I would call stellar either.
Also, looking at that chart it's closer to 40%...
The IETF has multiple standardization levels, with Proposed Standard being the first and Internet Standard being the last (there used to be Draft Standard in between but it was eliminated). Proposed Standards are deemed ready for deployment and lots of important protocols (e.g., TLS, QUIC, etc.) are at Proposed Standard. IPv6 went to PS in 1998, and people have been trying to deploy it ever since, so it's really more like 25+ years since it was official.
Also, my provider fully supports IPv6 and so does my hardware, but I have to click a button in the control panel to activate it explicitly. That's practically around a million of people who could be on IPv6 right now if they just opted in.
Any change to IPv4 to extend the IP space (eg your example) would require a breaking change to the specification. So this would require changing every router on the planet to support it.
You're also focusing on how the IP address is written when that doesn't really matter. Changing the format isn't dragging out IP adoption.
IPv6 isn't THAT different from IPv4. It's a 128 bit number instead of a 32 bit number. When righting it out we use hex (because it's shorter).
We use multicast instead of broadcast so your Subnets can be bigger
The smallest subnet is /64 so vendors can do optimization hardware.
Routers announce the prefix they route (and a DNS server) and let endpoints autoconfigure(with built in IP conflict detection!). Instead of a stateful DHCP server(which is still an option).
And we let nodes have local and global addresses so issues with the router don't necessarily break local communication. (And they're easy to tell apart, if starts with an f it's a local adress, if it starts with 2 it's a global address)
That's pretty much all that's different. 80% of what's different is the address space.
That's not IPv6's fault, but it is a pain. Especially considering that local networks differ from router to router, making it impossible to write a manual to access a router's settings for when the thing needs to be configured before it can connect to the internet.
Of course, in those cases there's nothing preventing manufacturers from providing some 192.168/16 IPv4 addresses for those specific use cases (and not route them to the internet). I've even seen one manufacturer listen on a bunch of 169.254/16 addresses for when DHCP fails somehow, and I think that'd solve the problem perfectly without even needing a DHCPv4 server.
Windows will try to auto configure with a 169.254 link local if DHCP is unavailable. Not sure if anyone is actually using them for LAN. They come up sometimes in point to point or for other shenanigans (commonly on cloud or virtualized networks for special services)
Afaik for Firefox and Chrome you can add a trailing / to prevent it from doing a web search and attempt to do a DNS lookup instead
The trailing slash trick sometimes worked, but not always. It took a couple of tries to get working every time I needed it to work. I bet it's some kind of problem on the mDNS layer, but regardless, the quickest way to fix it was to use an IP address.
Another annoyance I have (which isn't the protocol's fault) is that on my phone I can't even hand-type IPv6 addresses because Mozilla is using some kind of regex to detect if things are URLs and that regex doesn't support IPv6. It did for a short while, but the IPv6 regex was too complex and slowed things down, so that was reverted.
I've seen it done few times for niche devices and I've done it a few times when I needed a really quick network operational and didn't want to bother setting up any supporting infrastructure such as a DHCP server. Never for any production environment though.
I've toyed around with an IPv6 link local only environment but browsers don't support adding the zone identifier[1] for link local addresses. There's workarounds but in most cases for a fully isolated network it's about the same effort to setup a small DHCP server somewhere.
That said it's not a comprehensive solution, Android AFAIK still won't support DHCPv6. To get that to work AFAIK requires router advertisements and some more odd finagling if privacy extensions are enabled on the device.
[1]https://ungleich.ch/u/blog/ipv6-link-local-support-in-browse...
It's sitting just shy of 45%, based on what Google sees, and growing at a steady pace. The main issue is not technical, it's need. Right now, everything is accessible over IPv4, and probably over IPv6. There's no negative consequences from not having IPv4, it really needs initiatives like this one, and the US federal government one to drive things forwards (US federal agencies have to be single-stack IPv6 within a couple of years, which is forcing every government dealing vendor to get their act together on IPv6)
I tried that solution early because when I first got Google Fiber the Amazon store website didn’t load, on any machine in our house, until I turned off ipv6. If stuff tries to route over ipv6, it doesn’t work, has been my entire experience with the protocol on the open internet (private networks seem Ok)
If you get 10/10 here everything should work. Most likely your issue was a firewall rule on the IPv6 part, or a misconfigured DNS server (only returning A records)
Kicked my phone over to my T-Mobile cell connection. Finds that I have an ipv6 address, but dies on one of the first tests.
It’s 2024 and I have two major US ISPs available and neither will let me reliably use IPv6 unless I’m on a vpn and the addresses are all private ones that don’t (logically) route to the Internet.
If you want a near-exact equivalent of 192.168.0.1, then you can use fec0::1 or fd00::1. That's even shorter than IPv4! You kind of shouldn't, but it'll work fine for a tiny network.
But as other people have explained, the compatibility will be just as bad. And IPv6 does have address ranges like that. Nobody talks about them because not much can be done with them.
If you're on 192.168 and you just want the convenient addresses, go for it.
40+% adoption rate since the World IPv6 Launch Day in 2012 is not what I would call awful [0].
>extend the IPv4 scheme with additional octets?
To clarify, IPv6 and IPv4 addresses are effectively just a number. On Linux, you can even do `ping 16843009` and see the tool actually pinging the address 1.1.1.1! The octets you see in typical IPv4 addresses, or the hextets in IPv6 ones, are just a way to represent those addresses.
If you think the address representation is the main thing holding IPv6 back, you are thinking it wrong. The most likely reason is actually software & hardware support, and the industry's general sentiment of "if it ain't broken, don't fix it" keeping NATs alive.
>seems it would be easier for people to use
The ship has already sailed. If IPv4 addresses are really that easy to remember, DNS would not have been invented.
Furthermore, when it comes to memorization of IPv6 addresses it's very helpful to split them into two halves. The second half can change rather arbitrarily (to maintain privacy by preventing address tracking), but the first half often won't because it is assigned to you by the ISP.
I think the lagging services about ipv6 are steam, github, HN, and a few smtp servers here and there.
It seems ipv6 is slowed down by big tech, the one with the bucks to move to ipv6, paradox, or they know IPv4 mechanically favor strongley centralized services? As it is toxic to clean and simple p2p protocols?
mmmmmh....
About the only part that would be easier is that more people use less broken APIs compared to BSD Sockets, with getaddrinfo and similar solutions ported from XTI/Plan9 finally becoming the norm.
So no more "you need to duplicate code to add support for new IP version".
But that's still worse than migrating to v6, which has widespread hardware support in switching equipment, considerable preference in mobile networks and not only (TL;Dr it's cheaper to use v6 to carry v4 traffic using 464 stateless translation rather than other forms of CGNAT), and some IOT systems (industrial, not home stuff) are v6-only if they have IP connectivity on the embedded side at all.
having a public ip = possibly reachable, depending on what other devices can be compromised on the network.
given the number of government machines already that participate in the various ddns botnets moving to that second one is going to be a lot of fun
at the very least all the cnc servers can move local.
> having a public ip = possibly reachable, depending on what other devices can be compromised on the network.
Lateral movement is hacking 101. Private IPs don't provide any security.
Got a webserver open to the internet and a database server on a private IP only accessible to the web server? Guess how you get to the database server?
guess what happens when the database server gets a public ip.
What component of your router prevents a packet with destination IP 192.168.1.2 arriving on the WAN interface from crossing over to the LAN interface and reaching a LAN machine with that IP? Hint: It's the same one that prevents IPv6 packets from making that same crossing.
but on a private network a compromised device can only make outgoing connections.
public facing devices can be administered by incoming connections, thats a whole other level of complexity, potentially for every device.
you can supply all the ACLs and firewalling to your heart's content on either private or public, it's just that public addresses have a heck of a lot less shitfuckery when you actually want to do useful things across the internet
The second is UFW on the server itself + fail2ban.
The open ports are 22 and 443.
It's basically as secure as it gets apart from not having it public at all. Public IP != open for all connections on all ports...
You obviously need to use a ULA prefix, they are not routed (just like RFC1918 space in IPv4).
Or you can just use your allocated IPv6 space, and firewall at the border. And you hopefully have BGP hijack monitoring set up anyway.
afaics, the biggest issue with ipv6 is if its active all devices on a network can easily be coaxed to never route traffic anywhere near the router/firewall the network admistrator intended, simply by handing out extra routing info for alternate networks.