ARIN down to 1.00 /8 – Akamai got 104.64.0.0/10 yesterday
arin.net
arin.net
Anything that gets IPv6 adoption to mainstream is a Good Thing, but more likely we'll just start seeing the $1/mo/IP become $2/mo/IP, and upward... The squeeze will just continue as people make more money off of it, and we'll still need IPv4 addresses for compatibility with people running Windows XP in 2020.
Just because an IP doesn't answer to someone - especially coming from the general internet - doesn't mean it's not in use. This should be obvious to anyone even with the tiniest amount of understanding of TCP/IP networking and IT in general. Hence the authors of such a 'scan' aren't that credible to me. Unless 'scan' is something totally different.
Of course, some of these machines actually might have valid justification for squatting on a public IPv4 address. Perhaps their firewalls are configured to drop all packets except those from a handful of "trusted" IP addresses, so a random scanner on the Internet gets no response.
But I doubt that such cases account for the majority of "seemingly unused" IPv4 blocks. What's more likely is that some large organization was assigned a massive block of IPs 20-30 years ago and never found much use for them. IBM owns 9/8. Xerox owns 13/8. HP owns 15/8. Apple owns 17/8. Ford owns 19/8. Several pharmaceutical and chemical companies also own an /8 each, as do some universities. Do they really need 16.7 million public IPv4 addresses? Of course not. But I wouldn't be surprised if they started to sell bits and pieces of their blocks once the price per IP goes up enough.
That's a horrible hack and those people are wrong. Separate your concerns; addresses for addressing, firewalls for firewalling. Using private addresses adds extra complications; what if someone's home network uses the same range and they want to connect to your VPN? What if you merge with another company that's using the same range? What if you want to use FTP or SIP or any other protocol that uses the internet the way it was intended to connect to a server in a different office, are your packets going to make it through or not? You'll observe that private addresses have been deliberately left out of IPv6, for good reason.
B) I agree there are inconveniences and complications with using private addresses in ipv4. But it seems to be necessary thrift in the ipv4 world of rapidly expiring address space; using public routable ipv4 addresses for machines which do not communicate with the public internet is perhaps a luxury we can not afford, even in cases where to do otherwise is inconvenient or complicated.
I imagine the only reason you would use a IPv6 private address is if you didn't have allocated global ones. It's just replacing no chance of collision with some chance of collision.
Yes, but they were a late addition, postdating IPv6 by 10 years, and aren't meant to be used lightly.
IPv6 is designed for easy & automatic renumbering so there's less need to hold on to a specific prefix as an "island of stability".
Just gotta make sure OSPF, (E/I)BGP and L2/L3 drop these ranges though.
Why? A router could still offer private IPv4 and encapsulate IPv4 packets in IPv6. The carrier can decapsulate IPv6 packets and perform NAT.
In fact, this is how my home cable connection works (per DS-Lite [1]). Our modem/router only gets an IPv6 address, but IPv4-only devices work fine.
SNI removes the requirement from HTTPS websites to host one domain per IP. This is done by having hostname part of the initial handshake.
Many websites or at least most (hopefully all) webapps these days serve over https, at least the ones that require user input like login. So there's the need for at least one public IP per site.
With SNI these could be all served from the same IP.
Now imagine CDN services like AWS CloudFront -- to support sites with SSL certificates you must use one IP per cert in EACH region or whatever the distribution granularity is.
Now this my friends is why AWS CloudFront asks $600/mo for each custom SSL cert domain and with SNI custom SSL it costs $0/mo.
As soon as all the 99.9% browsers/clients support SNI we'll be living in a better place with more free IPs. So we can finally distribute static content from CDN through custom SSL without the $600/mo pricetag.
It's naive to think everyone would go to SNI-based hosts with IPs shared with strangers but at least within the same datacenter for the same company IPs can be more easily conserved.
[1]: https://blog.wireshark.org/2010/04/t-mobile-clever-or-insane...
I think if ARIN wanted to, they could give everyone a year to "substantiate their allocation" and set the policy something like "companies must return for reallocation any overallocations."
The risk of not returning an overallocation, well I'm not sure. ARIN certainly has teeth, and companies should simply be expected to correct these huge overallocations.
Just like the open source community comes together to solve serious problems, if we as a community enforced an ethical standard and some key people stood up raised this as an issue, I'm willing to bet ARIN could replenish a stockpile of IPv4 space.
So the question I'm asking is, since ARIN is empty, clearly they aren't interested in keeping a stockpile of addresses. Why not? I guess the more generous alternative is simply they have failed spectacularly at their stated goal.
ARIN can go over the pool of post 1997 addresses they have allocated, but I think you would find much smaller unallocated blocks.
When the three months are up you can go looking for four more companies, and hire some more lawyers too.
Watch this clip to understand why fractional solutions wont save us : https://www.youtube.com/watch?v=F-QA2rkpBSY
Warning, its "Perhaps the most boring video you'll ever see, and definitely the most important."
The only way they are going to give them up is if the is worth their while financially.
Put another way, what is the incremental value to provide access to your service to those IPv4 only users/devices? Whatever that value is, in theory you would be willing to pay a portion of that for access to IPv4 address space.
Luckily supply is not really constrained, so much as it is controlled. You can always get more IPs if you need them, but the cost associated I think will continue to increase... until enough people not only just support IPv6, but actually abandon their IPv4 addresses.
When the only devices that your software or service is designed to run on all support IPv6, then there's "no point" in having an IPv4 address. You almost have to get to the point where IPv4 is "not worth the trouble". And we are very, very far from that point I think. More to the point, more people are likely to think that it's IPv6 that is not worth the trouble.
Could of course just ignore that, but it's a good low pressure reminder to get around to sorting out IPv6...
Windows XP is a pain all right, the lack of SNI along with the limited v6 support means anyone using it really is stuck on v4.
Maybe the recent EOL for XP will cause a dramatic shift in the number of people continuing to use it? At least in the more well-off countries like the US, UK etc, opening the door for SNI :)
This is the source of a lot of problems.
The end user then doesnt even know or care that the website he/she is using is ipv6
btw does cloudflare support ipv6 only domains?
Btw, your math is off. ⅕, not ¼.
Even then, I wouldn't rule out partitioning your big net - there is enough stupid software and OSes around which happily blabber (ie. broadcast) to the attached subnet. Becomes quite a nuisance when you've got hundreds of Nodes.
See also here: http://serverfault.com/questions/502305/linux-networking-por...
NAT does tuple mapping - src/dst addr/port and protocol. That is - two TCP mappings can use the same local external port even if they go to the same remote address, for as long as they connect to a different remote port.
Of course, nat has a bunch of other pain in the ass problems, especially in that if I want to be able to track abuse, I've got to log every new connection (flow, whatever) that you make. When I get a complaint, I've got to match that up to my logs, which can be goddamn difficult if the complainer's clock isn't just right.
With static IPs it's way easier to track abuse, and I don't have to actively log what you are doing, just who has what IP when, and because IPs stick around a lot longer than connections, I'm way less vulnerable to clock drift.
My argument still stands in case all peers behind a common NAT router try to access the same IPv4 server (which may just happen with centralized services like youtube/facebook/google). It also stands in case UDP based services are used (stuff depending on a Cone NAT and using STUN like VoIP or online gaming).
Some proposals were superset-like, so v4 and v6 addresses could ping each other. But not all v6 addresses. As soon as the v4 space was used up, those variants had to allocate v6 addresses that could not ping v4 addresses, so you got a sneaking incompatibility. Worse: you'd never know for sure whether there were any v4-only hosts left on the network.
Clean break or sneaking, what's your preference?
The size of the routing table has been growing faster than the cost of fast router memory has been falling for some time now.
I mean, if you are only pushing a gigabit of traffic (and /maybe/ 10 gigabits, especially if the packets are large.) it's not that big of a deal; you can use dram and CPUs with large caches, and it's fast enough. But if you own a real pipe and have to push 40 gigs, or really, even 10gigs of small packets, my pair of vyatta routers on Xeons just isn't going to cut the mustard.
It's kind of a 'tragedy of the commons' because when I buy IPs, that money goes to ARIN (or to the previous owner of those IPs) - none of that money goes to all the router owners who have to pay for more fast router memory - even though I'm costing those people money.
The problem with runout intersects with this. If I need, say, 4000 IPs, I can get one /20, and occupy only one routing slot, or I can get 16 /24s and occupy 16 routing slots. From my point of view, from the point of view of the person who owns the IPs, there really isn't much difference between one /20 and 16 /24s. But the rest of the internet has to pay 16x as much if I get 16 /24s.
http://www.hbs.edu/faculty/Publication%20Files/09-091_0077c0...
I mean, it might work out okay; that's pretty much what ARIN does now. I'm just saying, it's not exactly a market-based solution; that document proposes a market in IP addresses, but it largely leaves the routing table as a commons, even if it does propose to regulate that commons in ways that are similar to the way it is being regulated now.
In the general case, sure, I like markets, too. It's just that markets deal very poorly with externalities, and I want to make the point that the way most people want to set up a market for IPs, routing table slots are externalities.
There is currently a process for selling IP addresses:
https://www.arin.net/resources/transfers/index.html
My understanding is that you give the previous owner enough money to make them happy, then you satisfy the requirements that you would have had to satisfy to get ARIN to give you the resources if you were requesting said resources from ARIN directly.
Edit: it's kind of mind boggling that people on a site about startups are so anti-market. Lord knows they don't solve all the world's problems, and all of us can think of examples where they don't work, but they generally work pretty well, and I don't see evidence that this is not the case here.
If maybe this helps folks managing news.ycombinator.com to click the button and dualstack their site ? (Being behind CloudFlare, it is really just a click away, I am told).
We run Windows and Linux machines.
My ISP (Andrews and Arnold) in the UK give us IPv6.
I was thinking of switching to either A&A or fido.net this summer as they are the only ISPs in the UK that offer reasonable priced IPv6 broadband.
A&A rock - no complaints at all.
IETF should have taken a pave-the-cowpaths approach and cleaned up ipv4, not created a huge incompatible ipv6 mess.
A broken cable modem for month (mandatory, btw) that went into a freeze whenever the ipv6 prefix was renewed (not even changed, necessarily): Every 2-3 days the box locked up.
While I appreciate the 'No addresses left' argument, I was 'upgraded' to this crap. Before that I had a (dynamic) ipv4. My cable provider sits on ipv4 addresses and won't jump from providing cable in Germany into the huge Indian/Chinese market and run out of addresses.
Why do we allocate huge networks (was it a /10 recently?) to Akamai if we're scarce?
No way to access my home machines anymore. Dyndns is dead. I could implement that for ipv6 and that would be even better in theory, alas .. most people/networks/mobile carriers are on ipv4. So my AAAA is utterly useless, even if I keep it up to date.
In the end I'm a fan of ipv6. I ran ipv6 tunnels in the past, native ipv6 is cool. Somewhat. CGNAT is bullshit for the reasons above and more and forcing it down to your customers is a tough sell (-> The ISP loses goodwill here). For new or exploding markets? Probably no other way. Here it's just useless. Dual Stack is fine, DS Lite causes trouble again and again in my setup here.
And there's never an excuse for a known issue that requires your customers to unplug the cable modem you provided, because .. well .. it's not quite ipv6 ready yet. [1]
1: That was an issue for month, was solved around end of February. Support hotline knew about it, device manufacturer knew about it, official workaround see above.