Show HN: A Short IPv6 Guide for Home IPv4 Admins
gist.github.com
gist.github.com
However, looking decades back I realise I felt the same way when first learning about and working with networks. Nothing about it is intuitive. It's all complex, until it isn't through repetition and familiarity.
That said, I still don't want to spend the mental effort on IPv6 yet. I'll deal with it when I have a need for it.
One set of firewall rules, easy to view ip addresses, machines don't leak.
I would put the extra braincells to work learning vlans. putting machines in jail is a liberating experience.
You can also learn to use privoxy to control IF machines have internet access, who they talk to and when.
That's because it's familiar and comfortable. Once you get hang of IPv6 you dislike the idea of fiddling with numbers as protocol takes care of most of things.
This is quite a loaded question. You need some sort of IPv4 to access the IPv4 Internet. You need some sort of IPv4 if you have devices that don't support IPv6.
What you need in each case depends. If it's just to access the IPv4 Internet, you might get away with NAT64 and a single public IPv4 on the WAN interface.
> my static ip addresses are ipv4.
Ok? You can have static IPv6 addresses if you want.
Predictable addresses are messy. Changing ISPs is a nightmare unless you run NAT. Firewalling being decoupled from NAT is a more complex experience. Memorising addresses becomes much harder. Old devices have varying support and common brand routers still have various IPv6 bugs.
I have IPv6 running at home and love it, but familiarity and comfort aren't the primary reasons it's less managable. Many existing configurations simply don't translate across very well.
> With IPv4, when your router connects to your ISP, you get one public address for the WAN, and you use a picked private address like 192.168.0.0/24 for your LAN. With IPv6, since you want a globally routable address for hosts on your LAN also, you need to ask the ISP for a routable prefix.
jive with this:
> You want to use these ULA for all your LAN communication. If you want to reach your printer or a media server, put their ULAs in the DNS and not the globally routable one.
Why have globally-routable IPv6 addresses if you're not going to use them?
I was put off initially by the first quoted paragraph because while the hard-outside-chewy-center security model is not a strong model, it is easy to reason about especially when you have very heterogeneous devices on your home LAN, including ones you don't control the OS of. I like using private addresses for my home LAN and even if I had an IPv4 /24, I wouldn't give addresses from it to machines on my LAN.
I use wireguard to access things on my LAN, with a somewhat-janky split-horizen DNS setup where the DNS server is on my LAN, so I have to be connected to wireguard to even resolve the names.
Because globally routable addresses are not static. Your prefix may change.
> For your externally visible servers, use dyndns type service, and update it with the globally routable address. Residential internet will rotate the prefix over time (the prefix is dynamic), so this is the same as running a server on a residential dynamic IPv4.
> For firewall, drop all inbound packets by default. For externally visible servers, you can match the last 64 bits only, so that changing prefixes don’t affect the firewall rules.
Since I don't (currently) want anything at all to be generally externally accessible, it seems that I could just use ULAs for the LAN machines and not assign them globally-routable addresses..... but at that point I guess there's no reason to be configuring IPv6 at all (?), which is exactly the current state of my LAN. I guess if there were services that were better-accessible (or only accessible) over IPv6 that would be a reason.
You can have ULA address and globally-routable addresses (GRA) at the same time: they are not mutually exclusive. IPv6 was designed to (possibly) have multiple addresses on the same interface, while with IPv4 this is a (bit of a) 'strange' configuration (to have multiple addresses/aliases).
So go ahead and assign a ULA if you wish, but your system will also just get an address which is globally addressable (but not globally reachable address because of firewalls).
https://blogs.infoblox.com/ipv6-coe/ula-is-broken-in-dual-st...
I've seen some of that - that said I can't figure out how I'm supposed to do DNS registration with GUA addresses. The only way I know to register addresses in DNS is with DHCP. Should I just have my IPv6 DHCP server advertise the GUA addreses? Is there some other way to do this?
I'm actually genuinely confused about this.
Without a non-link-local IPv6 address, resolvers will often omit IPv6 addresses in their response.
Another big difference between IPv4 and IPv6 is in the localhost address scheme.
IPv4: 127.0.0.1/8 - 24 bits of free addresses IPv6: ::1/128 - no free addresses
Many people won’t care about this but some local hacks make use the localhost address space for fun and profit.
[1] https://github.com/suntong/dbab/pull/10#issuecomment-1603857...
Step 2 says to set up ULAs. Are these static or dynamic? It says "don't pick numbers." If dynamic, how does step 5 work? If static, what about visitors in my house?
Step 3 mentions a LAN DNS. Where do I set that up? I don't recall my router having that option somewhere, and I'd rather not rely on a machine for it.
Once a host picks a ULA (prefix + id), you can get that from the host. It's the same as getting a mac address of a machine, but instead you get the ULA, and add it to your firewall rules.
Step 3 answer: I run unbounded on the router.
Your ISP can change your prefix delegation, in practice this shouldn't happen often, but if your in a situation where you need to deal with it frequently on the same network (running a service with a short lived delegation) DDNS still works for IPv6.
Some providers (eg: Starlink, when I last checked and a Calyx WiFi hotspot) will only advertise a prefix. I was forced to figure out a way to bring the /64 that is in front of my router (Linux iptables) and expose it to a LAN behind my router. It looks something like [1]
Depending on your setup, there may be an easier solution.
[1] http://imoverclocked.blogspot.com/2022/05/ipv6-wifi-access-p...
How do clients discover the DNS server in a SLAAC environment?
For Internet-facing DNS you don't. For your internal resolver you could create a static address within a ULA (e.g. $PREFIX::1).
How do clients discover the DNS server in a SLAAC environment?
Mine specifies the router's ULA, which is effectively static, and it runs unbounded.
This seems like the "rogue DHCP" problem in v4.
Your link local or ULA is static address and can be used for DNS.
DNS server is advertised when prefix is advertised.
2. Then you have your router advertise that prefix.
3. Then you have your DNS server pick a non-temporary address within that prefix (either manually set it, or let the OS pick one).
4. Then you tell your router to advertise that address as the DNS server in the RA.
Depending on how you have your network set up, your DNS server will have probably four IPv6 addresses: A link-local one; one on the ULA prefix you created; a non-temporary address on the prefix delegated by your ISP; and one or more temporary addresses on the prefix delegated by your ISP.
Outgoing connections (for recursive resolving) will be on one of the temporary addresses from the PD prefix. The DNS server listens on the static ULA address.
You need to configure your firewall such that traffic from the delegated prefix can get to the ULA one, and vice versa. This usually just means blocking traffic from the WAN port to the ULA prefix.
Then there was a bug in CoreDNS that wouldn't bind link local. What I learned from the text is that I should have probably generated a unique address for the DNS.
It is not only confusing theoretically but also the ISP router config makes it even more confusing.
$ dig +short wk1 AAAA @192.168.1.1
2601:646:...
fd7c:b0fd:fd6a:1::ba5Only one run of zeros can be condensed as :: because two or more would be ambiguous.
For a given prefix, the interface will always pick the same identifier, (in fact, the eui-64 algorithm will pick the same identifier across multiple prefixes)
How does the algorithm typically work? Is there a loss of privacy since identifiers are reused across prefixes? If I replace my NIC or install a different OS on my machine will the address change?
There are other more privacy sensitive ways to generate obfuscated addresses.
But none of these matter, because RFC 4941 says a new random address is used for each request. If you surf the web on a server with a static address, it'll create hundreds of temporary, random addresses to make requests from. The server is reachable by the static address, but outgoing requests come from a random address.
I know, weird, right? Concept 2: IPv6 uses multiple addresses.
Yes, if you replace the NIC, the address will change. Different OS won't, if it uses EUI-64.
I imagine I might be able to go looking for an answer to why I'd want this, but I would have expected the case to have been made casually by now if it had any utility in my home. I never stopped reading technology and computing sites during my sabbatical, though they did become more mainstream. Yet I still have no clue why I'd want this on a home network. This seems like a solution in need of a problem (in the home – I'm not discounting the utility on a global scale).
I feel like I'm doing a lot of plugging of IPv6.rs [1], but I guess that's a testament to just how much demand there is for IPv6.
[1] https://ipv6.rs