Goodbye, IPv4 IANA Starts Allocating Final Address Blocks
internetsociety.org
internetsociety.org
I generally agree. Putting those in circulation would actually be a bad thing. It would allow IPv4 to continue to zombie-walk for another couple years, maybe another decade, and in so doing to become more deeply entrenched, harming us in the long-run. IPv4 is technical debt.
It's also important to consider why DoD (and some large corps too) likes to sit on these address spaces. The problem with IPv4 isn't just that there isn't a big enough address space for every device on the Internet. IPv4 also lacks enough address space to permit the easy allocation of non-conflicting private address spaces. Ask any large-scale enterprise network engineer what happens when two companies merge or want to interconnect corporate networks and both use 10.0.0.0/16 as their address space. The answer is a visit to the bottom-most circles of NAT hell where sinners are boiled in firewall port remapping rules for all eternity. Either that or one of the merging/linking entities must renumber their entire network, which is often even more painful.
It really, really pains me that so many cloud providers are taking so damn long to support IPv6. Does Amazon even support it yet? I heard Digital Ocean was finally doing a limited beta. Jeez.
We currently only use the IPv4 address (I know, I know!), but it does present a bit of a problem when/if we decide to move.
I work at Rackspace and I'd love to get our product engineers involved and review this issue for you. Would it be possible for you to email your account number and any pertinent server information (hostname/IP address/etc) to help@rackspace.com so that we can investigate?
Thanks! Andy Pape Social Media Support @Racker_Andy
I don't work at Amazon, but I spoke with someone about this recently, and I believe the issue is that Amazon provides virtual hardware and a virtual networking stack, and the tooling required to virtualize the networking stack in IPv6 isn't mature enough yet.
For providers that offer dedicated hardware, this isn't an issue, but Amazon's services abstract over a very complicated and intertwined stack, so I can understand why it would take them longer.
Not sure about cloud providers, but several VPS companies already offer discounts for you to go IPv6 only.
"I have a different take on that. Yes, a lot of people were dissing tunnels yesterday. I'm actually a big fan of tunnels. I think the way the IPv4 Internet was built originally was basically by tunneling over the phone system. Ignore, you know, getting leased lines, putting computers on the end, building a network with no cooperation at all from the phone company. In fact, I once saw a phone company memo that referred to the Internet as a 'hostile overlay'. You know, and we basically, you know, demolished their billing plans and everything, and built this network in spite of the desires of the carriers. And, as I see the IPv4 Internet getting more and more like the phone company, I thought one way to deploy IPv6 is basically tunnel over all that junk. Iterate the same thing again. And I gather, you know, some people, you know, who are concerned about this are looking at other ways of sort evolving the Internet, where you, you know, tunnel over HTTP or whatever you have to do to basically get over all that cruft and build a new network on top of it. So that, to me, was one possible way, you know, as the IPv4 Internet rotted the underneath. We would tunnel over it and then we would throw away the rotted bits and replace them with wires."
[1] "Internet as a 'Hostile Overlay'" -> http://www.youtube.com/watch?v=mwRVNwa6nJc#t=11m07s
I really like that.
How are RBLs and other useful internet institutions that work on the basis of IPv4 addresses along the way with their IPv6 adoption?
It would take some time to adapt implementations. I speculate this gives attackers some opportunities to use old-style hacks that were largely mitigated, but suddenly re-appear with IPv6.
firstmillion:~▻ host -t AAAA news.ycombinator.com
news.ycombinator.com has no AAAA record
firstmillion:~▻ host -t AAAA twitter.com
twitter.com has no AAAA record
firstmillion:~▻ host -t AAAA cloud-images.ubuntu.com
cloud-images.ubuntu.com has no AAAA record
firstmillion:~▻ host -t AAAA ubuntu.com
ubuntu.com has no AAAA record
...BTW, there is a nifty Chrome extension that tells you whether the site is doing IPv4 or IPv6. Always nice to see a green 6 in the address bar.
[0] https://chrome.google.com/webstore/detail/ipvfoo/ecanpcehffn... [1] https://addons.mozilla.org/de/firefox/addon/ipvfox/
$ host -t AAAA fedoraproject.org
fedoraproject.org has IPv6 address 2001:4178:2:1269::fed2
fedoraproject.org has IPv6 address 2607:f188::dead:beef:cafe:fed1
fedoraproject.org has IPv6 address 2610:28:3090:3001:dead:beef:cafe:fed4
while Red Hat doesn't: $ host -t AAAA redhat.com
redhat.com has no AAAA recordAnyone know what IPv6 adoption is looking like these days? Google is showing like 3% of their connections are native to it [1], which does not look promising.
1: https://www.google.com/intl/en/ipv6/statistics.html#tab=ipv6...
http://www.internetsociety.org/deploy360/ipv6/statistics/
Eric Vyncke and Lars Eggert have two good sites at:
https://www.vyncke.org/ipv6status/
https://eggert.org/meter/ipv6.html
Cisco 6Lab has a nice map at: http://6lab.cisco.com/stats/
10/8 is off limits, but there are a bunch of /8 blocks which could likely be reclaimed if we really needed to, including:
- About half a dozen which were allocated to the US military in the early 1990s, most of which aren't even publicly advertised at all
- 44/8, reserved for amateur radio
- A number of other /8 blocks owned by corporations, which could potentially sell or return chunks of them if properly convinced
Edit: I wish there was an updated version.
That's enough to find out that this particular one is called a Hilbert curve.
This page has similar images from 2012
As for 44/8, there are still those that use it, taking it away would mean having to renumber all of the equipment on that network...
No, trying to reclaim IPv4 addresses by making people go through herculean efforts to renumber their networks is not the way forward and simply delays the inevitable. IPv6 is the way forward, start pushing that, and get more people using it.
Consider subcontractors needing to connect to servers in a particular department.
Ford has 181,000 employees as of 2013 (http://en.wikipedia.org/wiki/Ford_Motor_Company).
That's very roughly 92 publicly routable IP addresses per employee.
I highly doubt they need that many.
It would take years to arrange the return of 100 million addresses compared to the demand for a few billion addresses with even conservative growth.
Well before that, you could recover 18/8, MIT's prefix; how many addresses does a single university actually need, even MIT? Stanford already returned their /8 prefix. Or you could potentially recover a variety of DoD /8s, or start assigning some of the ones that are "reserved for future use" like 240/4.
Of course, an even better use of 240/4 would have been to use it as a backwards-compatible way to move to a larger address space. IPv6 should have been specified with IPv4 compatibility via NAT from the beginning, so that it could be a gradual migration. I mean, we're moving that way anyhow, but with a much more painful period in the middle in which NAT is necessary but IPv6 isn't ready yet for people who want to end the pain of NAT.
The 240 block is problematic because a huge amount of legacy routing equipment is hard-coded to blackhole it. The best thing for it is probably to reserve it for unspecified local use, which would allow you to use it to NAT IPv6 addresses into locally, or use as additional RFC1918-style address space, or as ORCHID-style address space for IPv4-only applications using the likes of cjdns, etc.
When will it finally be impossible to buy an IPv4 address?
Last time I tried to acquire a new IPv4, the distributor (my VPS host) required a technical reason for the request. If the request wasn't up to par, you would be denied an IPv4 + given an IPv6.
This was not at a particularly expensive provider.
What seems so wasteful is the "3 unusable" out of the 8 that are allocated. I have a vague understanding that those 3 are used for some routing/addressing stuff internally, but it's always felt incredibly wasteful.
This is all very fuzzy and some admins will look at you weird for doing this - but sometimes you've gotta do what you've gotta do.
The third address (router) is actually used by your ISP's router's to reach your subnet.
It is space that has been surrendered to IANA for re-allocation.
LACNIC hit that mark and triggered ICANN's policy to start allocating out of this recovered address space pool. The NRO has an announcement up about this, too:
http://www.nro.net/news/iana-allocates-recovered-ipv4-addres...
Basically, after this recovered pool of IPv4 addresses is allocated by IANA, there aren't any more IPv4 addresses to give out.
Step -1: We started running out of IPv4 addresses. The internet is IPv4-only for all practical purposes. Nobody is doing IPv6 because it's still experimental. Your weird neck-bearded friends are talking about it, that's about it.
Step 0: Inception! IPv6 is now a standard and you can route IPv6 over the tubes. Two networks have connected!
Step 1: Dual stack is a thing. Now you can set up both IPv4 and IPv6 on the same network and they co-exist. Some hosts (goole.com, facebook.com) try this and finally turn it on for good in 2012.
Step 2: Dual stack intensifies. This is where we are now. You cannot yet run a full blown IPv6-only network that you want to talk to the Internet and do anything practical with it, but all your cleanly shaven friends are now telling you that you should support IPv6 first, then add IPv4 for compatibility. Google sees as much as 3.5% of their traffic over IPv6.
Step 3: The cost of any single IPv4 address rises dramatically. For an end user it's already roughly $1/month. Buying in bulk is much cheaper, but not free like it used to be. ISP's and other service providers (Amazon, Rackspace, Digital Ocean) are going to start noticing the costs on their bottom lines. Severe restrictions are imposed by IPS's and service providers on anything but the bare minimum of IPv4 usage.
Step 4: The future. The first IPv6-only networks start to pop up. They use special network translation to talk to IPv4-only internet. (You can do this at home now! It's called NAT64: http://www.litech.org/tayga/).
Step 5. The number of IPv6-only networks is growing rapidly. IPv4 is now a legacy protocol. All your friends are telling you that they cannot believe we are still using IPv4 and how much of a pain it is to support it. Sales of T-shirts with "There is no place like 127.0.0.1" drop dramatically.
Step 6. The same people that put together IPv6 World Launch Day put together an IPv4 funeral. Major companies turn off IPv4 presence.
The crucial point here is not that someone demands IPv6 by calling their ISP, etc. It is fun to play with and you should at least get a tunnel set up through Hurricane Electric if you are reading this, but the demand here does not matter. What matters is supply: supply of IPv4 that is. Once that goes to nil, the cost rises and some executive at every ISP and service provider has a bright idea to save the company millions by switching everyone to IPv6. That's it. We, the people in the trenches, cannot affect this. We cannot speed it up and we cannot slow it down. The invisible hand of the market will make IPv6 happen all on its own.
Most people still can't actually route IPv6 over their tubes without going through a tunnel broker. At least for home, small office, and companies that aren't tech heavy, it's still firmly in the neckbeard camp.
What we have not quite reached yet is the point where IPv4 addresses are really expensive. You still get one with every VPS you sign up for and with every home connection. Once that can no longer be done, IPv6 will become standard pretty much across the board, starting in Step 3 and 4.
However, just checked last night and discovered that they'd added a new feature that would tell you when your CMTS was IPv6 ready, and it turns out that they've finally upgraded me. I could finally switch off my tunnel and use a real, routable address. Woo!
The nerdy t-shirt industry experiences a boost in margins, as they can now save ink by printing the much shorter "::1".
In IPv4, you have an entire /8 at your disposal, just for talking to yourself!
It is safe to assume that they won't be allocated in the future. You can easily assign them to your loopback interface. e.g. on linux:
$ ip addr add ::2/128 dev lo
You will then be able to use them over loopback just like ::1, and can populate your /etc/hosts file accordingly. $ ping6 -c 1 ::2
PING ::2(::2) 56 data bytes
64 bytes from ::2: icmp_seq=1 ttl=64 time=0.078 ms
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.078/0.078/0.078/0.000 ms
[1] http://tools.ietf.org/html/rfc4291#section-4EDIT: formatting.
FTFY.
http://en.wikipedia.org/wiki/List_of_assigned_/8_IPv4_addres...
Rapidly-developing Asia already has about as many people as there are IP addresses by itself.
Where are you going to find enough /8s, how are you going to recover them fast enough to do any good, and who's going to pay the massive legal bills from the ensuing litigation?
It also makes it hard for websites to block users based on IP without also blocking lots of legitimate users sharing that IP. I think this is a good thing to keep the internet more equal and anonymous.
I figure the subsequent avalanche of user pressure on isps will solve the problem in a week or so. Added bonus: during that week productivity will be at an all time high.
I cant get ipv6 to work with this router, tho if i connect laptop directly to the wan cable i get an ipv6 address without issues and can use google via ipv6 etc
If a slightly unshaven geek like me cant get ipv6 to work easily what hope is there for rest of the world :(
Am on phone so not read 100%