> You also said
> > NAT is here to stay
It's not generally good form to cherry-pick things I said from other threads and put them out of context. "NAT is here to stay" can for the purposes of this discussion mean "Thinking about global vs local addresses is here to stay", even if it's not NAT per se that is happening (ie. if you're using a ULA + global unicast, like I do.)
> you're almost certainly confused
I'm not confused. I do split horizon DNS. I serve WAN and LAN clients (not currently from the same DNS server, although that's what I'd prefer to do. The same hostnames are currently configured in different DNS systems depending on who's asking, hence "split horizon".)
To be clear, here's my setup. It's not unique or interesting compared to any other "home lab" setup:
- I have multiple machines that I want to be able to access by DNS name externally.
- I also want to be able to use those same DNS names for local configuration, to keep things sane.
To do this, I have two options:
1) Use the publicly-routable global unicast addresses in my DNS, and make a system to keep them updated in a reprefix
2) Use a ULA prefix for local DNS, and the global unicast equivalent addresses for public DNS, and make a system to update only the public DNS when I get reprefixed
I chose option (2) because I want to mitigate the damage that happens when my ISP reprefixes me. (It's happened 6 times over the past year, it's not uncommon.)
When I get reprefixed, any local traffic that's using DNS to lookup the address keeps working as usual, because the ULA address doesn't change. I have to worry about reconfiguring public DNS, but that's the lesser of two evils IMO:
Because if I picked option (1), I'd have to reconfigure public DNS and my local traffic would all be disrupted while the reprefix happened: My hosts would all be trying to communicate with one another via their old prefixes, and failing until DNS reconfigures.
And this is all not to mention that I have to do the exact same reconfiguration dance with my firewall config: When I get reprefixed, my pf.conf is now referencing invalid IP's. I disable-by-default so it's not a security issue, but it's something that I had to solve with automation (in my case, by templatizing my pf.conf and writing dhcpcd hooks that reconfigure it when the prefix changes. It wasn't trivial.)
Now, to get back to my original argument: IPv6's simplicity benefits "erode" when you consider that worrying about internal vs external addresses is still something you have to deal with in the real world, at least in residential deployments where you don't own your own prefix. Granted: These issues are inherent to any system where your ISP is dynamically assigning you IP's, but it's important to understand: Yes you can have real endpoints for all of your hosts simultaneously without dealing with NAT, but you still have complexity to deal with to make this work, due to it being the real world.