Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #209985 > unrolled thread

Re: IPv4 v IPv6

Started byCurt Howland <Howland@priss.com>
First post2019-06-17 17:50 +0200
Last post2019-06-18 16:10 +0200
Articles 7 — 5 participants

Back to article view | Back to linux.debian.user

This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by below is the oldest one visible, not the original post.


Contents

  Re: IPv4 v IPv6 Curt Howland <Howland@priss.com> - 2019-06-17 17:50 +0200
    Re: IPv4 v IPv6 Gene Heskett <gheskett@shentel.net> - 2019-06-17 19:10 +0200
      Re: IPv4 v IPv6 rhkramer@gmail.com - 2019-06-18 02:10 +0200
        Re: IPv4 v IPv6 Gene Heskett <gheskett@shentel.net> - 2019-06-18 02:40 +0200
          Re: IPv4 v IPv6 rhkramer@gmail.com - 2019-06-18 02:50 +0200
    Re: IPv4 v IPv6 Richard Hector <richard@walnut.gen.nz> - 2019-06-18 11:50 +0200
    Re: IPv4 v IPv6 Pascal Hambourg <pascal@plouf.fr.eu.org> - 2019-06-18 16:10 +0200

#209985 — Re: IPv4 v IPv6

FromCurt Howland <Howland@priss.com>
Date2019-06-17 17:50 +0200
SubjectRe: IPv4 v IPv6
Message-ID<ya23n-1hL-3@gated-at.bofh.it>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

On Monday 17 June 2019, Gene Heskett <gheskett@shentel.net> was heard 
to say:

> How is that resolved, by unroutable address blocks such 
> as 192.168.xx.xx is now?

Yes, IPv6 does have such allocations. The first 64bits is network 
block, then the last 64bits are your local machine.

fc00:: is the non-routed network. RFC1918 equiv.

fe80:: is the link-local address which is not routed at all, it is 
used solely between your device and the router. Personally, I would 
have combined these two, but when IPv6 was being built they didn't 
ask me.

Your device will always have an address built of its MAC address, with 
FF FE in the middle of it, for every network block including link 
local, like this:

# ifconfig
enp1s0: flags=4163<UP,BROADCAST,RUNNING,MULTICAST>  mtu 1500
        inet 192.168.85.86  netmask 255.255.255.0  broadcast 
192.168.85.255
        inet6 fe80::beae:c5ff:fe66:ec70  prefixlen 64  scopeid 
0x20<link>
        inet6 2691:178d:8d80:efd:f92f:91cf:1240:640d  prefixlen 64  
scopeid 0x0<global>
        inet6 2691:178d:8d80:efd:beae:c5ff:fe66:ec70  prefixlen 64  
scopeid 0x0<global>
        ether bc:ae:c5:66:ec:70  txqueuelen 1000  (Ethernet)

These show the three entries which should always exist. The first is 
the link-local address built from the MAC. Second, the allocated 
network from my ISP, with a randomized local address for security 
purposes.

The third entry is the global network address and the local MAC based 
address. Someone realized broadcasting your MAC address is not 
particularly secure, so the randomized interface address has become 
the norm. This third address is what you would put in your hosts 
file.

> how do the other machines on my local net, advertise their presence 
> to the other machines on my local net. So I can still ssh -Y 
> vna.coyote.den for instance, if I can ever make ssh work to a 
> win-10-home edition box.    

You do so by either making a static fc00:: entry, or by knowing your 
global network you can then just splice on the MAC local address 
since the MAC local doesn't change.

Unfortunately, because DHCP6 is really dynamic, and my ISP changes the 
network blocks every once in a while, having the global network 
entries and MAC local addresses in the hosts file has been a complete 
waste of time.

Having fc00::MAC as a non-routed local RFC1918 default would have been 
sooooo much easier, but no, IPv6 was not designed by network 
engineers. It was designed by old AT&T phone engineers who were 
pissed they were being put out of a job by competition, and wanted to 
curse the world with increased complexity where none was needed.






- -- 
You may my glories and my state dispose,
But not my griefs; still am I king of those.
 --- William Shakespeare, "Richard II"

-----BEGIN PGP SIGNATURE-----

iHUEAREIAB0WIQTaYVhJsIalt8scIDa2T1fo1pHhqQUCXQe0IAAKCRC2T1fo1pHh
qTDaAP4oUASTwq45ouAVaxl8umH3f+r+JcAbLLdyXVaWLQZZzgD+KmHUpq5fwv8I
yuOUUo0U5HgRfAiT7cBs1oLDLeqsooE=
=ilf7
-----END PGP SIGNATURE-----

[toc] | [next] | [standalone]


#209991

FromGene Heskett <gheskett@shentel.net>
Date2019-06-17 19:10 +0200
Message-ID<ya3iN-2dK-5@gated-at.bofh.it>
In reply to#209985
On Monday 17 June 2019 11:39:12 am Curt Howland wrote:

> On Monday 17 June 2019, Gene Heskett <gheskett@shentel.net> was heard
>
> to say:
> > How is that resolved, by unroutable address blocks such
> > as 192.168.xx.xx is now?
>
> Yes, IPv6 does have such allocations. The first 64bits is network
> block, then the last 64bits are your local machine.
>
> fc00:: is the non-routed network. RFC1918 equiv.
>
> fe80:: is the link-local address which is not routed at all, it is
> used solely between your device and the router. Personally, I would
> have combined these two, but when IPv6 was being built they didn't
> ask me.

Me neither, but then I've had it amply proved that my oar, in terms of 
steering this ship of state, isn't even the equ of a broken toothpick. 
Sigh...

> Your device will always have an address built of its MAC address, with
> FF FE in the middle of it, for every network block including link
> local, like this:
>
> # ifconfig
> enp1s0: flags=4163<UP,BROADCAST,RUNNING,MULTICAST>  mtu 1500
>         inet 192.168.85.86  netmask 255.255.255.0  broadcast
> 192.168.85.255
>         inet6 fe80::beae:c5ff:fe66:ec70  prefixlen 64  scopeid
> 0x20<link>
>         inet6 2691:178d:8d80:efd:f92f:91cf:1240:640d  prefixlen 64
> scopeid 0x0<global>
>         inet6 2691:178d:8d80:efd:beae:c5ff:fe66:ec70  prefixlen 64
> scopeid 0x0<global>
>         ether bc:ae:c5:66:ec:70  txqueuelen 1000  (Ethernet)
>
> These show the three entries which should always exist. The first is
> the link-local address built from the MAC. Second, the allocated
> network from my ISP, with a randomized local address for security
> purposes.
>
> The third entry is the global network address and the local MAC based
> address. Someone realized broadcasting your MAC address is not
> particularly secure, so the randomized interface address has become
> the norm. This third address is what you would put in your hosts
> file.
>
> > how do the other machines on my local net, advertise their presence
> > to the other machines on my local net. So I can still ssh -Y
> > vna.coyote.den for instance, if I can ever make ssh work to a
> > win-10-home edition box.  
>
> You do so by either making a static fc00:: entry, or by knowing your
> global network you can then just splice on the MAC local address
> since the MAC local doesn't change.
>
> Unfortunately, because DHCP6 is really dynamic, and my ISP changes the
> network blocks every once in a while, having the global network
> entries and MAC local addresses in the hosts file has been a complete
> waste of time.
>
I am lucky, my ISP uses the connecting MAC to translate to a fixed ipv4, 
that has not changed in 6 years. So my web page address in my sig has 
not changed in 6 years even if I swap the router as my standby unit has 
the good ones MAC cloned into it.  So I get a registered STATIC domain 
for almost zip compared to the cost and monkey business associated with 
keeping a dynamic address uptodate globally.

> Having fc00::MAC as a non-routed local RFC1918 default would have been
> sooooo much easier, but no, IPv6 was not designed by network
> engineers. It was designed by old AT&T phone engineers who were
> pissed they were being put out of a job by competition, and wanted to
> curse the world with increased complexity where none was needed.

Chuckle, I subscribe to that theory myself.

Cheers, Gene Heskett
-- 
"There are four boxes to be used in defense of liberty:
 soap, ballot, jury, and ammo. Please use in that order."
-Ed Howdershelt (Author)
If we desire respect for the law, we must first make the law respectable.
 - Louis D. Brandeis
Genes Web page <http://geneslinuxbox.net:6309/gene>

[toc] | [prev] | [next] | [standalone]


#210014

Fromrhkramer@gmail.com
Date2019-06-18 02:10 +0200
Message-ID<ya9Rf-6dO-7@gated-at.bofh.it>
In reply to#209991
On Monday, June 17, 2019 01:05:54 PM Gene Heskett wrote:
> I am lucky, my ISP uses the connecting MAC to translate to a fixed ipv4,
> that has not changed in 6 years. So my web page address in my sig has
> not changed in 6 years even if I swap the router as my standby unit has
> the good ones MAC cloned into it.  So I get a registered STATIC domain
> for almost zip compared to the cost and monkey business associated with
> keeping a dynamic address uptodate globally.

Interesting, and I think I have the same kind of luck.  (When I checked 
several years ago, the ipv4 address from my ISP was the same whenever I 
checked for a fairly long period.  I'm checking again, and hoping to find my 
notes of that address from those years ago.)

But, the main point of this reply is to ask you to provide a little more 
detail of how you set up everything so that you can host your web page that 
way.

I guess I'd have to set up Apache or some similar web server -- I guess I did 
that once upon a time, and should be able to do it again.

How did you get the information about your webserver (host name and IP 
address) into the DNS servers?  Did you have to pay someone to set that up and 
then pay a continuing fee to maintain those entries?

Thanks for any advice you can offer!

[toc] | [prev] | [next] | [standalone]


#210016

FromGene Heskett <gheskett@shentel.net>
Date2019-06-18 02:40 +0200
Message-ID<yaakh-6nf-5@gated-at.bofh.it>
In reply to#210014
On Monday 17 June 2019 07:59:51 pm rhkramer@gmail.com wrote:

> On Monday, June 17, 2019 01:05:54 PM Gene Heskett wrote:
> > I am lucky, my ISP uses the connecting MAC to translate to a fixed
> > ipv4, that has not changed in 6 years. So my web page address in my
> > sig has not changed in 6 years even if I swap the router as my
> > standby unit has the good ones MAC cloned into it.  So I get a
> > registered STATIC domain for almost zip compared to the cost and
> > monkey business associated with keeping a dynamic address uptodate
> > globally.
>
> Interesting, and I think I have the same kind of luck.  (When I
> checked several years ago, the ipv4 address from my ISP was the same
> whenever I checked for a fairly long period.  I'm checking again, and
> hoping to find my notes of that address from those years ago.)
>
> But, the main point of this reply is to ask you to provide a little
> more detail of how you set up everything so that you can host your web
> page that way.
>
> I guess I'd have to set up Apache or some similar web server -- I
> guess I did that once upon a time, and should be able to do it again.
>
> How did you get the information about your webserver (host name and IP
> address) into the DNS servers?  Did you have to pay someone to set
> that up and then pay a continuing fee to maintain those entries?
>
> Thanks for any advice you can offer!

namecheap.com, just a few bucks for a 5 year registration of a fixed 
address, now on another 5 year renewal:
from my sig:
Genes Web page <http://geneslinuxbox.net:6309/gene>
gene@coyote:~$ ping geneslinuxbox.net
PING geneslinuxbox.net (204.111.64.149): 56 data bytes
64 bytes from 204.111.64.149: icmp_seq=0 ttl=64 time=0.274 ms

Now, apache2 is running on port 6309, not on the usual port 80 and dd-wrt 
is set to port-forward that port to this machines internal 192.168.xx.xx 
address at that same port.  You can also port-fwd to port 80 at the same 
address and leave apache2's default at port 80.  Mauchs Nichs as long as 
they match. The 6309 is homeage to a Hitachi cpu that smartens up a 
trs-80 Color computer running what we now call nitros9, used to be os9. 
Its a mini-unix that runs on a 16 bit cpu that has PCR addressing.

Your trivia factoid for today.  Its sort of a secret aas Hitachi had 
permission to clone the moto 6809 in cmos, but were and are precluded 
from mentioning it was an improved clone. It can even do some 32 bit 
math!

Cheers, Gene Heskett
-- 
"There are four boxes to be used in defense of liberty:
 soap, ballot, jury, and ammo. Please use in that order."
-Ed Howdershelt (Author)
If we desire respect for the law, we must first make the law respectable.
 - Louis D. Brandeis
Genes Web page <http://geneslinuxbox.net:6309/gene>

[toc] | [prev] | [next] | [standalone]


#210017

Fromrhkramer@gmail.com
Date2019-06-18 02:50 +0200
Message-ID<yaatX-6qv-3@gated-at.bofh.it>
In reply to#210016
Thanks!

On Monday, June 17, 2019 08:34:01 PM Gene Heskett wrote:
> namecheap.com, just a few bucks for a 5 year registration of a fixed
> address, now on another 5 year renewal:
> from my sig:
> Genes Web page <http://geneslinuxbox.net:6309/gene>
> gene@coyote:~$ ping geneslinuxbox.net
> PING geneslinuxbox.net (204.111.64.149): 56 data bytes
> 64 bytes from 204.111.64.149: icmp_seq=0 ttl=64 time=0.274 ms
> 
> Now, apache2 is running on port 6309, not on the usual port 80 and dd-wrt
> is set to port-forward that port to this machines internal 192.168.xx.xx
> address at that same port.  You can also port-fwd to port 80 at the same
> address and leave apache2's default at port 80.  Mauchs Nichs as long as
> they match. The 6309 is homeage to a Hitachi cpu that smartens up a
> trs-80 Color computer running what we now call nitros9, used to be os9.
> Its a mini-unix that runs on a 16 bit cpu that has PCR addressing.
> 
> Your trivia factoid for today.  Its sort of a secret aas Hitachi had
> permission to clone the moto 6809 in cmos, but were and are precluded
> from mentioning it was an improved clone. It can even do some 32 bit
> math!
> 
> Cheers, Gene Heskett

[toc] | [prev] | [next] | [standalone]


#210028

FromRichard Hector <richard@walnut.gen.nz>
Date2019-06-18 11:50 +0200
Message-ID<yaiUx-37G-1@gated-at.bofh.it>
In reply to#209985

[Multipart message — attachments visible in raw view] — view raw

> On Monday 17 June 2019, Gene Heskett <gheskett@shentel.net> was heard 
> to say:
> 
>> How is that resolved, by unroutable address blocks such 
>> as 192.168.xx.xx is now?
> 
> Yes, IPv6 does have such allocations. The first 64bits is network 
> block, then the last 64bits are your local machine.
> 
> fc00:: is the non-routed network. RFC1918 equiv.

More precisely fc00::/7, of which fc00::/8 is unused, and fd00::/8 is
what you should _randomly_ allocate your local /48 from.

> fe80:: is the link-local address which is not routed at all, it is 
> used solely between your device and the router. Personally, I would 
> have combined these two, but when IPv6 was being built they didn't 
> ask me.

Me neither, but I think the purposes are different enough to keep them
separate.

> Having fc00::MAC as a non-routed local RFC1918 default would have been 
> sooooo much easier, but no, IPv6 was not designed by network 
> engineers. It was designed by old AT&T phone engineers who were 
> pissed they were being put out of a job by competition, and wanted to 
> curse the world with increased complexity where none was needed.

link local addresses are strictly limited to the link, whereas fd00::/7
addresses are for your site, so you can route them around your own
networks as much as you like - I'm linking a few networks and VPSs with
them over openvpn.

https://en.wikipedia.org/wiki/Unique_local_address

Richard


[toc] | [prev] | [next] | [standalone]


#210044

FromPascal Hambourg <pascal@plouf.fr.eu.org>
Date2019-06-18 16:10 +0200
Message-ID<yamY9-5Mh-7@gated-at.bofh.it>
In reply to#209985
Le 17/06/2019 à 17:39, Curt Howland a écrit :
> 
> Yes, IPv6 does have such allocations. The first 64bits is network
> block, then the last 64bits are your local machine.

Unless you want to enable SLAAC which requires 64+64, you can select 
different sizes for the network the host parts. Your network, your rules.

> fc00:: is the non-routed network. RFC1918 equiv.

Unique local addresse can be routed over private links. Just not routed 
on the public internet.

> fe80:: is the link-local address which is not routed at all, it is
> used solely between your device and the router.

Not only between the router and device, but also between devices.

> Personally, I would
> have combined these two, but when IPv6 was being built they didn't
> ask me.

I wouldn't. Link local and ULA have totally different purposes.

> These show the three entries which should always exist. The first is
> the link-local address built from the MAC. Second, the allocated
> network from my ISP, with a randomized local address for security
> purposes.

Rather for privacy concerns.
Be aware that the assignment of a privacy IPv6 address does not mean 
that it is used by default.

> Unfortunately, because DHCP6 is really dynamic, and my ISP changes the
> network blocks every once in a while, having the global network
> entries and MAC local addresses in the hosts file has been a complete
> waste of time.

DHCPv6 is not the problem. It is just a method to dynamically assign a 
prefix, it does not mean that the prefix has to be variable. The problem 
is that your ISP changes the assigned prefix without notice. My ISP has 
changed my prefix once in more than a decade for technical reasons, and 
noticed me before.

> Having fc00::MAC as a non-routed local RFC1918 default

What do you mean by "fc00::MAC" ?

> IPv6 was not designed by network engineers.
The fc00::/7 prefix was assigned for ULA long after IPv6 was designed, 
when the site local prefix was deprecated.

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web