IPv6 may already be irrelevant – but so is moving off IPv4
theregister.com
theregister.com
While not universal, some ISPs support PCP, where you can ask for a port mapping to your CGNAT-ed IP and port. They might or might not honor the external port (if it is taken, they obviously cannot), but you will get some hole punched.
But will they? Domestic ISPs are pretty hesitant to offer such, or anything at that manner.
At least not without doing fancy stuff like using an externally-hosted VPN to shuttle connections to you.
Of course you can punch holes there. CGNATs can be asked for port forwarding using PCP, unless your ISP disabled that.
Perhaps it's different for a mom & pop ISP, but I don't see the big ones configuring anything that makes it easier to do what they already don't want you doing anyway. They see the inability to forward ports as a feature, not a bug.
So even if you expose your Home Assistant web to the wide web, no ISP is going to have a problem with that and won't interpret it as hosting services. What they really want is that you don't run a bandwidth intensive services on a consumer connection, which is going to be overbooked somewhere in their infra, causing service degradation to other users.
And for example Orange does provide PCP for their CGNAT.
> If you are behind NAT or CG-NAT
Not wrong, but if you want multiple servers of the same service, you're now doing custom ports (myhost:port1, myhost:port2, etc) which isn't the end of the world, but is kind of sucky.
And if we're not talking just about servers running services, but clients that want to do peer-to-peer stuff, you also have to use things like STUN/TURN/ICE which is more infrastructure that is needed (as opposed to 'just' hole punching since your system already knows its IP(v6) address).
Given the prevalence of these technologies (kludges?) they've kind of been normalized so we think they're "fine".
Where I'm, I can choose 1 out of 1 broadband provider available in the area. With this provider, I can either have a public IPv4 address (or several) with their CPE in bridge mode, or DS-Lite, with IPv4 CGNAT without PCP and /64 for the IPv6 addresses (i.e. no address space for subnets, no prefix distribution) AND having to use their router with the limited settings they allow.
With offers like these, is it any wonder that I stick with IPv4?
IPv6 is pointless and still a security risk but I’m guessing you’re misconfiguring something.
Assigning only /64 & no DHCP-PD. There's not much to misconfigure, since in IPv6 you have to use their router and they are pushing the config.
And since you have only /64, you cannot put another router behind theirs.
> The following sections explain why /48 and /56 are the recommended prefix assignment sizes for end customers.
* https://www.ripe.net/publications/docs/ripe-690/#4-2--prefix...
And it's not like it's a new policy:
> RIPE-690 outlines best current operational practices for the assignment of IPv6 prefixes (i.e. a block of IPv6 addresses) for end-users, as making wrong choices when designing an IPv6 network will eventually have negative implications for deployment and require further effort such as renumbering when the network is already in operation. In particular, assigning IPv6 prefixes longer than /56 to residential customers is strongly discouraged, with /48 recommended for business customers. This will allow plenty of space for future expansion and sub-netting without the need for renumbering, whilst persistent prefixes (i.e. static) should be highly preferred for simplicity, stability and cost reasons.
* https://www.internetsociety.org/blog/2017/10/ipv6-prefix-ass...
The other big one I know, Jio (from Reliance) also offers just a single /64.
I think it’d be nice to self-host things to, but it’s inaccurate and even a bit insulting to claim that the millions of people creating content on the internet today don’t exist.
It's not just about self-hosting, but peer-to-peer clients as well.
When Skype originally came out it was P2P, but because of NAT they created (ran?) "super-nodes" that could do things like STUN/TURN/ICE. Wouldn't it be nice to be able to (e.g.) communicate with folks without a central authoritative server that could be warranted by various regimes?
I haven't heard of anyone else doing this, but I doubt I'm completely alone in trying to minimize hosting costs.
They basically created entirely different products that provided a marginal immediate benefit to the users and then said "upgrade whenever you get around to it". They are both now in the 2nd decade of their upgrade cycle.
PowerPC->Intel, Xbox/PlayStation emulation, x86 32-bit>64-bit, and Java are all technologies that had successful upgrade strategies that were centered around replacing the original product rather than indefinitely providing an alternative.
I haven't moved my systems to IPv6, and have no current plans to do so, because it's a pretty major change (meaning a ton of hassle) that brings me no benefits that I care about.
If/when IPv6 becomes mandatory to connect to the internet, I'll go to the trouble of shifting my systems.
There was no other way to do it with IPv6: IPv4 has 32-bits of address space and >32 was needed for more addresses. That 32-bits is hard-coded in data structures, APIs, and even DNS formats (e.g., A records).
So regardless of anything else related to IPv6 (ARP vs ND), you would have still needed to release a bunch of code that had to be installed on every router, L3 switch, firewall, DNS server, and end device.
It was also recognized that, given the size of the Internet even in the 1990s, that a flag day like was done for the NCP->IP transition would not be possible:
We believe that it is not possible to have a "flag-day" form of
transition in which all hosts and routers must change over at
once. The size, complexity, and distributed administration of the
Internet make such a cutover impossible.
* https://datatracker.ietf.org/doc/html/rfc1726#section-5.5So you were always going to have to have a 'rolling upgrade' to get a larger address space. You were always going to have translation systems.
It was also recognized that the 'legacy' may never go away:
Furthermore, we note that, in all probability, there will be IPv4
hosts on the Internet effectively forever. IPng must provide
mechanisms to allow these hosts to communicate, even after IPng
has become the dominant network layer protocol in the Internet.
* IbidIs it accurate to think of it as an "upgrade" versus "addition"? It's not like HTTP 1.1 went away just because HTTP 3/QUIC came around.
HTTP 3 may have certain useful features, but lots of folks do need/care about them and so may never activate it (at least on purpose, unless Apache/Nginx have them default-on). This thinking may not add much burden to the rest of the Internet for that protocol.
Whereas not supporting IPv6 can add burdens to others:
> Our [American Indian] tribal network started out IPv6, but soon learned we had to somehow support IPv4 only traffic. It took almost 11 months in order to get a small amount of IPv4 addresses allocated for this use. In fact there were only enough addresses to cover maybe 1% of population. So we were forced to create a very expensive proxy/translation server in order to support this traffic.
> We learned a very expensive lesson. 71% of the IPv4 traffic we were supporting was from ROKU devices. 9% coming from DishNetwork & DirectTV satellite tuners, 11% from HomeSecurity cameras and systems, and remaining 9% we replaced extremely outdated Point of Sale(POS) equipment. So we cut ROKU some slack three years ago by spending a little over $300k just to support their devices.
* https://community.roku.com/t5/Features-settings-updates/It-s...
* Discussion: https://news.ycombinator.com/item?id=35047624
Getting people to follow new standards and follow best practices can be more difficult than herding cats.
* https://news.ycombinator.com/item?id=41893200
(The The APNIC article is a repost of the potaroo.net article.)
• https://news.ycombinator.com/item?id=41893200
– https://www.potaroo.net/ispcol/2024-10/ipv6-transition.html
– The IPv6 Transition
– (224 points / 416 comments)
The argument is somewhat thin "CDNs use DNS so it doesn't matter what the IP is"
I mean yes, that true, but it should have always been true. Dishing out raw IPs is bad anyway, it limits your flexibility (yes yes anycast exists, but if you're big enough to setup any cast, I bet you're using ipv6 internally already)
Ipv6 is here, and will slowly grow as time goes on. There will be growing pains, but its plain cheaper to run at any kind of scale. (especially now AWS are charging for public IPv4 addresses)
If you are hosting thousands of servers, and you haven't drunken the batshit K8s networking schema, then ipv6 becomes really rather practical, especially if you are giving out unique addresses to containers 10.0.0.0/8 runs out pretty quick.
Incidentally, if you want to play with anycast on the public Internet, BuyVM[1] will let you do that on $10.50/mo (3×$3.50/mo very resource-limited VPSes). Catching those VPSes when they’re in stock is something of an ordeal, though.
16,777,216 containers, wow.
Consider that 200 servers is a drop in the bucket at some scales, you can see why data centre is moving to V6 only.
> 16,777,216 containers, wow.
Have you ever been involved in a corporate merger? IP conflicts are a huge pain point. Quite often you have to NAT with-in the company itself because the acquirer and acquiree are both using 10/8.
We quickly discovered it was easier to get the new location up and running on IPv6 and mesh that so all inter-office traffic was IPv6 rather than resolving the conflicts. Sure you couldn't reach the printer in Boise from New York because it was IPv4 only, but for the stuff normal users were doing it worked great.
But, subnets need to be located next to each other physically, otherwise performance suffers. subnets have affinity.
but once you have subnets, you then start loosing packing efficiency.
for example, in the batshit world of K8s, you give each node its own /24 to dish out. Not only cant that limit the number of containers you can host, it also is really inefficient. (eating 256k addresses)
More over, it also means that you need to reuse addresses. in a large cluster of say 1000 nodes, each hosting 40 containers, starting/stopping anything up to 30 containers a second isn't unreasonable. Its not inconceivable that you'll end up trying to connect to a stale address (either because its not propagated yet, or your brand of service discovery isn't that fast). This can cause hilarious transitory errors.
but if you could assign an IP per container, and have enough space to not re-use that address for at least a few hours then that goes away. so instead of getting weird fuzzing errors(or misc 404/401), you get a connection timed out.
“The last couple of decades have seen us stripping out network-centric functionality and replacing this with an undistinguished commodity packet transport medium. It's fast and cheap, but it's up to applications to overlay this common basic service with its own requirements." The result is networks become "simple dumb pipes!"
Given that, Huston wonders if it's time to revisit the definition of the internet as networks that use a common shared transmission fabric, a common suite of protocols and a common protocol address pool.
Rather, he posits "Is today's network more like 'a disparate collection of services that share common referential mechanisms using a common namespace?'"