AWS charge for using IPv4 expected to bring $1B/year and speed up IPv6 adoption
tomshardware.com
tomshardware.com
https://docs.aws.amazon.com/elasticloadbalancing/latest/appl...
> You can configure your Application Load Balancer so that clients can communicate with the load balancer using IPv4 addresses only, or using both IPv4 and IPv6 addresses (dualstack).
I'd love to go IPv6 only. Amazon won't let me, and charges for the privilege.
Look at the list of "no"s on https://docs.aws.amazon.com/vpc/latest/userguide/aws-ipv6-su....
While AWS is a bit (just a bit) more removed from the end user than Cloudflare, there is still the potential for it not being good PR.
People can of course manually test here [1] from their homes, schools, work place. I would wager most cellular data networks would be fine. The impact would probably depend on how a website is utilized. Stats on mobile vs. non-mobile would probably be telling. The people on their cell should test LTE vs Wifi and clear cache between tests.
[1] - https://test-ipv6.com/
Want IPv6...... please hold forever.
I specifically asked for IPv6 and was told they don't offer that.
The price keeps slowly going up, but that seems to be par for the course with ISPs.
That being said, the CGNAT thing is just silly in 2023 - give us IPv6.
But the real number (at least on mobile networks) may be closer to 20%: https://www.internetsociety.org/resources/2018/state-of-ipv6...
I'd assume that when you have IPv6, the majority of your traffic (in bytes) will be IPv6 simply because all the CDNs and big video services do support IPv6.
Once my router at home crashed in a way that IPv4 stopped working but IPv6 kept on working and it was actually kind hard to figure out what went wrong because so much of the internet still worked fine.
Obviously we couldn't subnet it back when we derived the last 64 bits from the MAC address. But since then everyone decided that's a bad idea, so why not use the address space?
If you pay for a business connection you can get 1 or more static IPv4 addresses, but then you get no IPv6 connectivity.
Literally one instance with VPC service endpoints deployed and an egress NAT gateway. Surprisingly common when you have a random shitbox which sucks data up from somewhere and doesn't fit within the constraints of a Lambda or something. They mostly exist to tick the compliance and architectural documents which are all under AWS "best practices".
Note that I do not consider AWS "best practices" to be best practices necessarily. In fact a lot of time they are completely over-engineered against hypothetical scenarios which if they did happen, fixing some EC2 integration shitbox would not even remotely be the first problem you had to worry about.
But someone demands it and someone pays for it and Bezos ain't complaining so meh!
Or something crypto. Pay to your IPv6 address, or nodes must be IPv6.
Or social network.
Start with an edge case that gets insiders to change behaviour.
"Elastic Load Balancing pricing" - https://aws.amazon.com/elasticloadbalancing/pricing/
"AWS Free Tier now includes 750 hours of free Public IPv4 addresses, as charges for Public IPv4 begin"- https://aws.amazon.com/about-aws/whats-new/2024/02/aws-free-...
Some AWS customers have released 80+% of their public IPv4 addresses. The alternative isn't IPv6, it's private addresses. Many AWS customers have been slapping public IPs on EC2 instance just because they could or because they didn't know any better.
I.e. address exhaustion pressure isn't only about the complete inability to buy an IP it's about how much work you have to do to use IPv4 addresses.
AWS charging for IPv4 will help with the former, because companies now have more of a reason to care about IPv6. But it might delay the latter, because fewer IPs wasted on internal servers means less price pressure on useful IPv4 use by ISPs, giving those that still hold out less financial incentive to change anything.
That percentage should be well above 99% for a popular website operator to even consider going IPv6-only; needless to say, in most markets, this figure is way lower, with no clear path to improving.
The only way I can think of getting the behaviour you describe is if you configure the network to hand out v6 addresses and routes to hosts, and then just black hole the packets. What you have then is a broken network.
If your network has broken v6 then yeah, that's gonna cause problems. That's not v6's fault, that's down to having a broken network.
If everything host on AWS becomes dual stack and gets first class IPv6 support after this move, that's a win for IPv6.
The price for v4 address is going to bob up and down as more networks and content providers adopt v6 and are able to reduce their public v4 usage to just their edges.
There will definitely be a long tail of v4, especially in the corporate world, but I think we'll get to 90-95% v6 capable within the next 5-10 year
Yup, this has been obvious for a while if you read the better economic analyses. Charging for IPv4 doesn't on its own remove it. It creates some sort of economic balance between the value and scarcity of the IPv4 address space.
When you're trying to fit the entire world of 7 billion people into 4 billion addresses, the space looks pretty scarce. But assuming a roughly power law distribution of services and their importance of being on IPv4, as you cut off the people with lower-end needs, like, "my cell phone needs to communicate on the internet so let's give it an IPv4 address", you extremely rapidly cut through orders of magnitude of the old uses.
That long tail of "Facebook is not willing to cut off even .01% of its user base so it has IPv4 addresses to serve on" may take a long time to get through, but we're well through getting huge swathes of the other users off of it.
What kills IPv4 is in the far future when the expense of maintaining it specially exceeds the benefits. Since maintaining it is rather cheap, this is going to take a while. But as IPv4 diminishes in importance, ironically, so does the value of entirely eliminating it. When it is 1% of the traffic, who will really be desperate to drop that to zero?
And of course if you are in the 0.01% you will discover that while Facebook and google won't give up on you many other providers will as it just isn't worth the cost. By that time the cost won't be IPv4 addresses - they will be again free - it will be the cost of maintaining IPv4 on all the routers and servers. (the routers mean IPv4 will cost more, but it won't be for the address it will be for routing access)
Should be more like 8bn now
The service providers who have to maintain IPv4 and IPv6 configurations in their networks.
For example Apple has already been requiring that appstore apps work in ipv6 only networks since 2016. They can just keep tightening such rules until ipv4 dies.
It's naive to think that maintaining ipv4 (/dualstack) networks is (and will remain) cheap at large global scale like Google.
I really wish more AWS services or workflows worked with private addresses. Sometimes a service can be completely internal but needs a public address to either talk to Dynamo or install packages; but those endpoints aren't available via private IP, even though they physically live in the same region
If you’re in a 6-only VPC/subnet, an egress only gateway will allow you to grab packages from IPv6 enabled public data sources.
Historical evidence is on this: cell phone ISPs have started doing this a long time ago and look at how high the IPv6 adoption is on mobile.
Also, an IPv6-only network removes the happy eyeballs algorithm so any routing issues on the IPv6 internet won't be papered over by the speed of the IPv4 internet, so there's more incentive to fix that.
(If you are interested in doing this at home, the most up-to-date documentation is a presentation from RIPE https://ripe87.ripe.net/wp-content/uploads/presentations/8-I... that covers NAT64/DNS64/DHCP108/PREF64).
Of course everything I said above is conditioned on speeding up IPv6 adoption as a goal. Unfortunately for many, IPv6 adoption is not a goal at all, so nothing I said above applies to them.
The problem for NAT64 in general use is that there is lots of IPv4-only software. NAT64 is great for business networks where control the software, but home users are going to try to use their Xbox 360 or Windows game from the 90s.
https://www.google.com/intl/en/ipv6/statistics.html
Anecdote, my ISP gives us IPv6 but not my employer. We use the IT equipment till the last breadth. I have seen, permanent table-fan running towards Floor's network hub. I guess that one is NOT IPv6 ready. :D
Maybe companies use the same opportunity to make sure their services also work via IPv6. But they won't stop offering their services on IPv4, and AWS changes don't put meaningful pressure on ISPs to roll out IPv6. If anything it will reduce the pressure on the price of IPv4 addresses, making it more viable for ISPs to hold out.
I doubt it, especially that there is an option of using private/CGNAT ranges instead of adopting a whole new protocol. Everyone who cares about IPv6 have already done their part, and people who don't care about it will likely use the lower-friction option, and between private IPv4 networks and IPv6 I bet that a lot of people will see private IPv4 as a lower-friction option.
Of course you can do all this via IPv4 by setting up proxies or gateways, but that's more work and more moving pieces than checking the checkbox that you want a public IPv6 and having it just work ... provided everyone you want to talk to talks IPv6.
The more likely story is places using AWS pay 1$/m for a public address and use private/IPv6 internally. I.e. an incremental step, not a revolution in the chart.
IPv6 adoption is not uniformly distributed. Some usersbases might have higher penetration. But yeah, I doubt there are many where it's high enough to be worth it.
Personally, I think I'd pay the fee to not be dual stack these days. Everything in your infrastructure has to now check two things. Your website uptime checker has to probe via both IPv4 and IPv6. You have to maintain two sets of firewall rules. You have to remember to "ping -6 example.com" in addition to "ping example.com" when checking connectivity. I don't think it's worth the effort, and I say that as someone who first made their website available over IPv6 in like 2008. (I moved providers in 2020 and the new one didn't have IPv6. It made me sad. But now it's just one less thing to worry about.)
... for all services.
There are internal servers talking to other servers which don't need ipv4. There's zerotier that gives you a private IPv6 network regardless of your network capabilities. The only part that actually still requires ipv4 is the general public user.
So, no need to bother with IPv6 and its myriad complexities just for that.
Or until you want you network segment to grow beyond a few thousand hosts.
Or until....
It's always tradeoffs. The complexities of IPv6 (and in some cases, the simplicity) at least comes after learning about what they got wrong in v4.
There is very little extra simplicity in IPv6. The only thing it really does that most people fight with in any common place is to get rid of NAT, which is a fairly well understood technology by now. But getting rid of DHCP didn't work, peer-to-peer networks still get bogged down in firewalls even if they don't fight NAT, MTU problems are still around when running VPNs, etc. Maybe getting rid of ARP has helped in some scenarios for more complex networks?
Instead, you have to deal with both DHCPv6 and SLAAC, with multiple IPs on every interface, with much harder to remember IPs, with always changing IPs, with the myriad IPv6/IPv4 conversion schemes, with larger DNS responses (requiring DNS over TCP more often), and I'm sure I'm forgetting a few things.
To the public internet, no. To internal services, possibly, and if you use a CDN you can have everything on the origin side using IPv6.
But I refuse to let them switch me, because their IPv6 offer does not include a v4 address, only CGNAT. Of course if everyone was on v6 that wouldn't matter, but until then I need the ability to forward ports to my server!
This isn't even technically in breach of the ToS; I have a business line, mostly for the customer support.
And thus I add to the problem, because now anyone who wants to connect to said server also needs a v4 option...
Also, in general, it just adds a layer of complexity that I wouldn't want to deal with if I didn't have to.
Tailscale connections are primarily peer to peer. The service Tailscale is providing is orchestrating the connectivity and hiding the complexity, but the data flows directly.
The internet is supposed to be peer-to-peer, and I shouldn't need third-parties in between my computers, or between my friends and me. Switching to IPv6 breaks the peer-to-peer nature of the internet.
On one hand, that gives me hope that we're getting closer to near-universal ISP support. On the other hand, it's been like this for so long I question if it'll ever improve.
Adoption is limited by enterprises who are change-averse and already entrenched in ipv4. Residential ISP’s have made much more progress.
When people complain about IPv6 and IPv4 being incompatible, the fact that you can establish a cross-protocol TCP+TLS session with just a NAT is a remarkable counterexample. It could've been a lot worse.
To this day I'm not sure what are the best options available now for different scenarios. 4rd/MAP-T/MAP-E/464XLAT/Dslite, nat64/siit/a+p, these things are enough to get your head spinning
NAT64 is used for IPv6-only networks to talk to IPv4. It puts the IPv4 address in the IPv6 address. The downside is that doesn't work with old IPv4-only software.
XLAT is used on mobile phones, and does the translation on the device. It only works for devices where translator can be installed.
MAP-T can be used for IPv6 ISP to provide IPv4 access. It is basically CGNAT but using IPv6 as stateless transport.
You have to pay for it, but paying for NAT Gateway for IPv4.
I find these articles on HN focus much more heavily on consumer use of IPv4 for simple things like web browsing. But not a lot of consideration is paid to massive corporate systems and API surfaces. Would be interesting to know.
Sadly, I think they're more hesitant now.
I can't believe the cost of NATs! If you're running in triple AZs that is 3 nats you're paying for.
Except that their alternative to per-VM addresses is a NAT gateway that isn’t zone-redundant. Literally everything else is — including IP addresses and virtual networks — but not outbound Internet access. That’s going to just break and leave your entire network dead in the water if one of three zones has a hiccup.
IPv6 can’t replace this garbage fast enough…
edit: Some little tips about it.
* The smallest subnet should be /64. Anyone making a smaller subnet than that is doing it wrong (looking at you, every ISP that assigns me an address)
* Subnets should be created in four-bit chunks. You should always make /64, /60, /56, etc. for readability. That's because 4 bits make up one hex character in the address.
* If you want to have private (non-internet-routable) IPv6 space, create a ULA. https://www.unique-local-ipv6.com/ Imagine never having to worry about address overlap with VPNs or routing between two internal networks.
I know that my ISP only gives my WAN router a single address (/128) so a private local network is a requirement for me.
In another 10 years it's probably worth putting more effort into the other cases as well, but so far I'm happy with getting 80% of the way there for 0.1% of the effort.
When we first got Fiber, years ago, Amazon’s store was one of the things that broke until I turned off IPv6. Wouldn’t load at all, on any device on our network.
Works fine for VPNs and such, but I don’t talk to the Internet with it, because my experience has been it’s terribly unreliable.
My cellular connection supports IPv6, but testing sites report it’s misconfigured in a bunch of ways. I don’t see problems in practice, though. But on my home network, it’s turned off.
Well if you don't actually have IPv6, and you're turning off a broken ghost of IPv6, that's very reasonable.
But in that case it confuses people when you call that "turning off IPv6".
I'd be happy if the HackerNews typers would just end the affectations; in either direction. But this teeth-gnashing is such an incredibly garish instance of NIMBY-ism, it's unbecoming.
I know IPv6. I can route it. I can setup networks with it. And my ISP supports it, but just kinda. For some arcane reason, it only supports it for some types of transport.
Got Cable/Coax internet? Great! You get IPv6 and a subnet too!
Got Fiber to the Home? You get IPv4. And no subnet.
I'm in the latter segment, and I just don't get it.
The ISP in question is Telia, a pretty big ISP in Scandinavia. If someone in the know-how could tell me at least why they're doing things like this, that might offer some mental consolation.
Projects aren't the real problem.
My point is, software typically isn't the problem.
EDIT: my take on IPv6 is this. In the early 2000’s I wanted to run a web server at home. Figuring out how to make my $10 gateway/router do port forwarding was hard. IPv6 sounded like the right solution. Now… none of those problems really exist
If a major player is making $1B out of it "not catching on", I agree it never will.
Yes.
>and speed up IPv6
Fucking lol. It's still not enough of a financial hit for people to want to deal with IPv6.
Should have just come up with a better protocol in the first place. That's what really would have stimulated adoption.
there's nothing wrong with ND and it addresses several security vulnerabilities, namely ARP cache poisoning. But the real reason why ARP was removed is because it's a layering violation.
> NAT support (because it's everywhere these days)
nothing at all is stopping you from doing NAT on IPv6, except for the fact that everyone hates NAT, even people that pretend that they like it.
> Correct DHCP support (SLAAC wasn't a great idea after all)
SLAAC is a great thing. Also, DHCPv6 also exists, which allows you to do exactly what DHCP lets you do. Android doesn't support DHCPv6, but that's not IPv6s fault.
- IPv6->IPv4 interop (one way)
There's no such thing as one-way communication if we're talking TCP. Besides, it's still fundamentally impossible if the other end has no idea what to do with the source address.
Never heard about ND tables overflows? They fixed one thing, broken another. ARP poisoning is mostly fixed problem.
I like NAT myself. Im dualhomed (el-cheapo), using policy routing and NAT. Everything works like a charm. I cant imagine such setup w/o NAT actually.
SLAAC might be great thing for you, but not for others. This is why IPv6 is such a failure. Instead of creating simple protocol to meet middle ground, they slapped together annoying techs for specific cases like IoT. Great job.
If you had a /24 of v4, you easily could.
> SLAAC might be great thing for you, but not for others.
[citation needed]
SLAAC is the best hope so far, but regular hosted customers do not understand that slaac is calculated by mac, so theyll need education to ensure immutable architectures dont crash and burn on lift-and-shift redeployments. either that, or enjoy hardcoding ip's in your prefix to the boxes.
then theres networking. most corporate network engineering that would handle ingress or peer traffic to clouds (especially azure tenants) treat ipv6 as a cursory knowledge...something theyre aware of in theory but have never taken it upon themselves to practice. i predict AWS will send a lot of them scrambling for mouldy ccna texts and taking down the hybrid cloud at least twice a month until the basics sink in.
and finally, firewall and security devices. There are a lot of vendors that have gotten a free pass to grandstand about how stellar their IPv6 support is, only to send customers to phone tree purgatory trying to find support for a device that either cant route between local, unique local, special purpose ranges, ::1, or even the special discard ranges for things like DDoS protection. frankly its not an AWS issue (yet) but the only guise ive seen handle this competently are...cloudflare.
Maybe some P2P applications will magically start working or have lower startup time because of no need for STUN/TURN/ICE for NAT traversal.
Gamers get errors about "strict NAT." Traditionally the solution to this problem caused by NAT was to forward the ports. If their ISPs has chosen CGNAT port forwarding is impossible.
VoIP calls that have one way audio are a symptom of reachability issues caused by a firewall or address translation problems. VoIP services have adapted to IPv4 NAT by relying on proxying instead of STUN but CGNAT really degrades reliability.
Smaller newer ISPs that can't obtain one IPv4 address per household are incurring significant CGNAT costs. https://news.ycombinator.com/item?id=35047624
Video chat uses the kludges of TURN when peer to peer connectivity does not work. This increases costs for the video chat service who in turn require a paid subscription as they will not relay traffic for free.
BitTorrent and file transfer services need direct IP connectivity. If p2p file transfers worked on any network we would not need to mind Gmail's 25MB attachment limit, or pay for intermediary cloud storage.
This might give IPv6 the final push it needs to convince the last few ISPs who are still stuck on IPv4-only
Some games assume there’s only one console per public IP, and expects ports NAT forwarded as such.
Giving each end-user an IPv6 prefix completely solves that mess.
That doesn't contradict that "most users" don't benefit, though.
And while network providers can provide dynamic IP addresses, it's pretty trivial for them to provide static addresses and just never bother changing them - it's not like there's a shortage of IPv6 addresses.
So from the perspective of a home internet user, acquiring a static IPv4 address is harder and more-expensive-than-$0.