Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #209975 > unrolled thread
| Started by | mick crane <mick.crane@gmail.com> |
|---|---|
| First post | 2019-06-17 11:10 +0200 |
| Last post | 2019-07-02 11:10 +0200 |
| Articles | 20 on this page of 60 — 21 participants |
Back to article view | Back to linux.debian.user
IPv4 v IPv6 mick crane <mick.crane@gmail.com> - 2019-06-17 11:10 +0200
Re: IPv4 v IPv6 <tomas@tuxteam.de> - 2019-06-17 11:20 +0200
Re: IPv4 v IPv6 Aidan Gauland <aidalgol@fastmail.net> - 2019-06-17 12:30 +0200
Re: IPv4 v IPv6 Rob van der Putten <rob@sput.nl> - 2019-06-18 09:30 +0200
Re: IPv4 v IPv6 Jonathan Dowland <jmtd@debian.org> - 2019-06-17 12:10 +0200
Re: IPv4 v IPv6 Gene Heskett <gheskett@shentel.net> - 2019-06-17 16:40 +0200
Re: IPv4 v IPv6 Dan Ritter <dsr@randomstring.org> - 2019-06-17 17:00 +0200
Re: IPv4 v IPv6 Gene Heskett <gheskett@shentel.net> - 2019-06-17 18:30 +0200
Re: IPv4 v IPv6 Gene Heskett <gheskett@shentel.net> - 2019-06-17 19:00 +0200
Re: IPv4 v IPv6 Greg Wooledge <wooledg@eeg.ccf.org> - 2019-06-17 19:10 +0200
Re: SOLVED was IPv4 v IPv6 discussion that went off the rails. Gene Heskett <gheskett@shentel.net> - 2019-06-18 02:10 +0200
Re: IPv4 v IPv6 Dan Ritter <dsr@randomstring.org> - 2019-06-17 19:10 +0200
Re: IPv4 v IPv6 Gene Heskett <gheskett@shentel.net> - 2019-06-17 19:40 +0200
Re: IPv4 v IPv6 Dan Ritter <dsr@randomstring.org> - 2019-06-17 20:00 +0200
Re: IPv4 v IPv6 Gene Heskett <gheskett@shentel.net> - 2019-06-17 20:00 +0200
Re: IPv4 v IPv6 Pascal Hambourg <pascal@plouf.fr.eu.org> - 2019-06-18 14:50 +0200
Re: IPv4 v IPv6 Greg Wooledge <wooledg@eeg.ccf.org> - 2019-06-18 14:50 +0200
Re: IPv4 v IPv6 Pascal Hambourg <pascal@plouf.fr.eu.org> - 2019-06-18 15:10 +0200
Re: IPv4 v IPv6 Dennis Wicks <wix@mgssub.com> - 2019-06-27 22:40 +0200
Re: IPv4 v IPv6 Gene Heskett <gheskett@shentel.net> - 2019-06-27 23:30 +0200
Re: IPv4 v IPv6 John Hasler <jhasler@newsguy.com> - 2019-06-17 20:30 +0200
Re: IPv4 v IPv6 Dan Ritter <dsr@randomstring.org> - 2019-06-17 22:10 +0200
Re: IPv4 v IPv6 Robin Hammond <rdhdroid@gmail.com> - 2019-06-17 22:20 +0200
Re: IPv4 v IPv6 Andy Smith <andy@strugglers.net> - 2019-06-18 00:50 +0200
Re: IPv4 v IPv6 John Hasler <jhasler@newsguy.com> - 2019-06-18 04:10 +0200
Re: IPv4 v IPv6 Gene Heskett <gheskett@shentel.net> - 2019-06-18 02:20 +0200
Re: IPv4 v IPv6 Reco <recoverym4n@enotuniq.net> - 2019-06-17 17:40 +0200
Re: IPv4 v IPv6 Richard Hector <richard@walnut.gen.nz> - 2019-06-18 12:00 +0200
Re: IPv4 v IPv6 Reco <recoverym4n@enotuniq.net> - 2019-06-18 12:40 +0200
Re: IPv4 v IPv6 Richard Hector <richard@walnut.gen.nz> - 2019-06-18 13:50 +0200
Re: IPv4 v IPv6 Reco <recoverym4n@enotuniq.net> - 2019-06-18 16:20 +0200
Re: IPv4 v IPv6 Pascal Hambourg <pascal@plouf.fr.eu.org> - 2019-06-18 16:50 +0200
Re: IPv4 v IPv6 Reco <recoverym4n@enotuniq.net> - 2019-06-18 18:20 +0200
Re: IPv4 v IPv6 Linux Dave <mckisicd@gmail.com> - 2019-06-20 20:40 +0200
Re: IPv4 v IPv6 Pascal Hambourg <pascal@plouf.fr.eu.org> - 2019-06-20 20:40 +0200
Re: IPv4 v IPv6 Erwan David <erwan@rail.eu.org> - 2019-06-20 20:50 +0200
Re: IPv4 v IPv6 Nicholas Geovanis <nickgeovanis@gmail.com> - 2019-06-20 21:00 +0200
Re: IPv4 v IPv6 Reco <recoverym4n@enotuniq.net> - 2019-06-20 21:10 +0200
Re: IPv4 v IPv6 Nicholas Geovanis <nickgeovanis@gmail.com> - 2019-06-18 17:40 +0200
Re: IPv4 v IPv6 Reco <recoverym4n@enotuniq.net> - 2019-06-18 18:30 +0200
Re: IPv4 v IPv6 Richard Hector <richard@walnut.gen.nz> - 2019-06-18 18:20 +0200
Re: IPv4 v IPv6 Reco <recoverym4n@enotuniq.net> - 2019-06-18 18:30 +0200
Re: IPv4 v IPv6 David Wright <deblis@lionunicorn.co.uk> - 2019-06-18 18:20 +0200
Re: IPv4 v IPv6 Richard Hector <richard@walnut.gen.nz> - 2019-06-18 18:30 +0200
Re: IPv4 v IPv6 Nicholas Geovanis <nickgeovanis@gmail.com> - 2019-06-18 18:40 +0200
Re: IPv4 v IPv6 David Wright <deblis@lionunicorn.co.uk> - 2019-06-22 05:10 +0200
Re: IPv4 v IPv6 Richard Hector <richard@walnut.gen.nz> - 2019-06-22 10:50 +0200
Re: IPv4 v IPv6 David Wright <deblis@lionunicorn.co.uk> - 2019-06-24 20:20 +0200
Re: IPv4 v IPv6 Andy Smith <andy@strugglers.net> - 2019-06-22 21:40 +0200
Re: IPv4 v IPv6 Gene Heskett <gheskett@shentel.net> - 2019-06-22 22:50 +0200
Re: IPv4 v IPv6 John Hasler <jhasler@newsguy.com> - 2019-06-22 23:40 +0200
Re: IPv4 v IPv6 Gene Heskett <gheskett@shentel.net> - 2019-06-23 02:30 +0200
Re: IPv4 v IPv6 John Hasler <jhasler@newsguy.com> - 2019-06-23 05:00 +0200
Re: IPv4 v IPv6 Gene Heskett <gheskett@shentel.net> - 2019-06-23 08:30 +0200
Re: IPv4 v IPv6 Pascal Hambourg <pascal@plouf.fr.eu.org> - 2019-06-23 11:20 +0200
Re: IPv4 v IPv6 Andy Smith <andy@strugglers.net> - 2019-06-26 20:40 +0200
Re: IPv4 v IPv6 Michael Stone <mstone@debian.org> - 2019-06-26 21:00 +0200
Re: IPv4 v IPv6 Richard Hector <richard@walnut.gen.nz> - 2019-06-18 11:50 +0200
Re: IPv4 v IPv6 Jonathan Dowland <jmtd@debian.org> - 2019-06-21 17:30 +0200
Re: IPv4 v IPv6 andreimpopescu@gmail.com - 2019-07-02 11:10 +0200
Page 3 of 3 — ← Prev page 1 2 [3]
| From | Richard Hector <richard@walnut.gen.nz> |
|---|---|
| Date | 2019-06-18 18:20 +0200 |
| Message-ID | <yaoZY-6YN-9@gated-at.bofh.it> |
| In reply to | #210045 |
[Multipart message — attachments visible in raw view] — view raw
On 19/06/19 2:11 AM, Reco wrote: > Hi. > > On Tue, Jun 18, 2019 at 11:47:08PM +1200, Richard Hector wrote: >> On 18/06/19 10:32 PM, Reco wrote: >> >> Custom routes? When routing between 2 networks using the same range, >> either with a VPN or some kind of direct connection? It's going to need >> some evil double NAT sorcery, especially if the same actual addresses >> are in use on both. > > As long as: > > a) It's L3 VPN, so ARP is not a concern. > b) There are no duplicate IPs on both sites combined. > > The problem can be 'solved' by announcing specific IP routes to each and > every host on both sites. Yes, it's gross. Eww. And people who have chosen 'obvious' blocks (like 192.168.1.0/24) are probably going to start numbering at the bottom, too. So duplicates are almost inevitable. I think we agree here. > >>>> There are online random ULA generators - but I'm not convinced one of >>>> them didn't give me the same block twice, or whether it was my own error. >>> >>> Never used one. IPv6 /8 block consists of 2^56 unique /64 subnets. >>> Surely it's possible to choose several unique /64 subnets by using, say, >>> ipv6calc. >> >> Yes, but there is a recommendation to use random ones, and even a >> suggestion of how to do it, in RFC 4193. > > But this RFC's "random" cannot mean "I start each day with selecting > new, custom /64 IPv6 ULA prefix for my site". ipv6calc fills this > nicely, try it some day. Every day? Of course not. Just when you set up a new network. I made the mistake of doing it for every subnet, which is unnecessary; I should have generated one /48 and split that up manually - and probably simplified my (static) routing. I should get round to renumbering one day ... though I now have a real /48 from one of my VPSs to use for some of it. Richard
[toc] | [prev] | [next] | [standalone]
| From | Reco <recoverym4n@enotuniq.net> |
|---|---|
| Date | 2019-06-18 18:30 +0200 |
| Message-ID | <yap9D-725-3@gated-at.bofh.it> |
| In reply to | #210058 |
Hi. On Wed, Jun 19, 2019 at 04:17:55AM +1200, Richard Hector wrote: > On 19/06/19 2:11 AM, Reco wrote: > > On Tue, Jun 18, 2019 at 11:47:08PM +1200, Richard Hector wrote: > >> On 18/06/19 10:32 PM, Reco wrote: > > >> > >> Custom routes? When routing between 2 networks using the same range, > >> either with a VPN or some kind of direct connection? It's going to need > >> some evil double NAT sorcery, especially if the same actual addresses > >> are in use on both. > > > > As long as: > > > > a) It's L3 VPN, so ARP is not a concern. > > b) There are no duplicate IPs on both sites combined. > > > > The problem can be 'solved' by announcing specific IP routes to each and > > every host on both sites. Yes, it's gross. > > Eww. And people who have chosen 'obvious' blocks (like 192.168.1.0/24) > are probably going to start numbering at the bottom, too. So duplicates > are almost inevitable. > > I think we agree here. Most definitely. Reco
[toc] | [prev] | [next] | [standalone]
| From | David Wright <deblis@lionunicorn.co.uk> |
|---|---|
| Date | 2019-06-18 18:20 +0200 |
| Message-ID | <yaoZX-6YN-1@gated-at.bofh.it> |
| In reply to | #209982 |
On Mon 17 Jun 2019 at 10:38:27 (-0400), Gene Heskett wrote:
> On Monday 17 June 2019 05:59:52 am Jonathan Dowland wrote:
> > On Mon, Jun 17, 2019 at 10:05:11AM +0100, mick crane wrote:
> > >Without knowing anything about it I'm wondering if I should request
> > > an IPv6 range from my ISP to use locally.
> >
> > You don't need a global IPv6 address allocation in order to have local
> > IPv6 addresses. Much like 127.0.0.0/8 (etc.) for IPv4 there are
> > reserved ranges.
> >
> > If you want to have globally-accessible IPv6 addresses for machine(s)
> > in your home, then you would need to request a range from your ISP (if
> > they aren't already assigning you one). But I would start with
> > learning a bit more about it first, and experimenting in the local
> > range if that helps.
> >
> > >A network card have IPv4 and IPv6 addresses that are different, not
> > >the same address in different notation ?
> >
> > That's right.
> >
> > >Then with firewalling do you need to specify both IPv4 and IPv6
> > > ranges ?
> >
> > Yes, generally, anywhere you may have specified an IPv4 address or
> > range you would need to rethink or add IPv6 equivalents.
>
> But that opens yet another container of worms. If I arbitrarily assign
> ipv6 local addresses, and later, ipv6 shows up at my side of the router,
> what if I have an address clash with someone on a satellite circuit in
> Ulan Bator. How is that resolved, by unroutable address blocks such as
> 192.168.xx.xx is now?
Seems a good reason not to bother setting up ipv6 local addresses
until we (you and I) understand it and ever see ipv6 on this side
of the modem. I'm not holding my breath.
> What I've read so far has not addressed this serious security concern. Or
> even mentioned it. If in the future all addressing is by dhcpd6, how do
> the other machines on my local net, advertise their presence to the
> other machines on my local net. So I can still ssh -Y vna.coyote.den for
> instance, if I can ever make ssh work to a win-10-home edition box.
> Thats a rarely used hookup at best. Presently the hosts file duplicated
> on all machines fill's this requirement.
>
> These are the questions I'll need to address if and when ipv6 shows up on
> my side of the router. And the wiki pages I've read, haven't discussed
> it.
Well, ipv6 does show up on the hosts (as seen by $ ip a) even if
there's nothing on the LAN, and I've found it useful enough to
script it, even though I've been ticked off here for doing it.
It makes a useful way of bypassing the router when transferring huge
quantities between wireless devices (typically laptops) that can sit
close to each other: I just connect them with a Cat5 cable, and the
OS does the rest automatically after a short wait. It works with a
wired PC too (though it obviously becomes isolated from the LAN in
the meantime) just by unpluging the LAN cable temporarily.
The trick I use is:
Mywiredifname=$(ip -o link show | sed -e '/^[0-9]\+: [^e]/d;s/[0-9]\+: \([^:]\+\): .*/\1/;')
in .bashrc, which discovers the local wired interface name (assuming
it starts with 'e'), and the bash function:
function wired6 {
ping6 -c 1 -W 1 ff02::1%"$Mywiredifname"
local Neighbour=$(ip -6 -o neighbour | grep -e REACHABLE | sed -e 's/^\([^ ]\+\) .*/\1/;')
if [ -n "$Neighbour" ] ; then
printf '%s\n' "$Neighbour"
else
printf '%s\n' "Unconnected"
return 1
fi
if ! ping6 -c 1 -W 1 "$Neighbour%$Mywiredifname" ; then
printf '%s\n' "Unconnected"
return 1
fi
if [ -z "$1" ] ; then
date && ssh -X "$Neighbour%$Mywiredifname"
else
"$My_clever_scp_function" "$USER@[$Neighbour%$Mywiredifname]" "$@"
fi
}
$ wired6 at one end will login as me to the machine at the other
end, and $ wired6 files … will transfer files to it instead.
$My_clever_scp_function is just a "smart" version of scp.
Apologies to those that don't like using link addresses like that.
Cheers,
David.
[toc] | [prev] | [next] | [standalone]
| From | Richard Hector <richard@walnut.gen.nz> |
|---|---|
| Date | 2019-06-18 18:30 +0200 |
| Message-ID | <yap9D-725-5@gated-at.bofh.it> |
| In reply to | #210054 |
[Multipart message — attachments visible in raw view] — view raw
On 19/06/19 4:12 AM, David Wright wrote: > On Mon 17 Jun 2019 at 10:38:27 (-0400), Gene Heskett wrote: >> But that opens yet another container of worms. If I arbitrarily assign >> ipv6 local addresses, and later, ipv6 shows up at my side of the router, >> what if I have an address clash with someone on a satellite circuit in >> Ulan Bator. How is that resolved, by unroutable address blocks such as >> 192.168.xx.xx is now? > > Seems a good reason not to bother setting up ipv6 local addresses > until we (you and I) understand it and ever see ipv6 on this side > of the modem. I'm not holding my breath. If you never try setting it up, when do you expect to understand it? And I see IPv6 on my side of the modem; I suspect many others do too. I expect you'll get it sooner or later. Richard
[toc] | [prev] | [next] | [standalone]
| From | Nicholas Geovanis <nickgeovanis@gmail.com> |
|---|---|
| Date | 2019-06-18 18:40 +0200 |
| Message-ID | <yapjj-75q-1@gated-at.bofh.it> |
| In reply to | #210062 |
[Multipart message — attachments visible in raw view] — view raw
On Tue, Jun 18, 2019 at 11:23 AM Richard Hector <richard@walnut.gen.nz> wrote: > > If you never try setting it up, when do you expect to understand it? And > I see IPv6 on my side of the modem; I suspect many others do too. I > expect you'll get it sooner or later. > A few weeks ago a took a position in the world's largest data center, a couple kilometers south of downtown Chicago. I've been intentionally ignoring IPV6 with some success for several years. But here it is an absolute necessity. I cannot any longer, I'm in front of it all day and night. Bite the bullet ;-) While they remove that old TCAM slug :-D Bet you never heard of THAT network protocol :-) Richard > >
[toc] | [prev] | [next] | [standalone]
| From | David Wright <deblis@lionunicorn.co.uk> |
|---|---|
| Date | 2019-06-22 05:10 +0200 |
| Message-ID | <ybEzD-4Qb-1@gated-at.bofh.it> |
| In reply to | #210062 |
On Wed 19 Jun 2019 at 04:23:15 (+1200), Richard Hector wrote: > On 19/06/19 4:12 AM, David Wright wrote: > > On Mon 17 Jun 2019 at 10:38:27 (-0400), Gene Heskett wrote: > > >> But that opens yet another container of worms. If I arbitrarily assign > >> ipv6 local addresses, and later, ipv6 shows up at my side of the router, > >> what if I have an address clash with someone on a satellite circuit in > >> Ulan Bator. How is that resolved, by unroutable address blocks such as > >> 192.168.xx.xx is now? > > > > Seems a good reason not to bother setting up ipv6 local addresses > > until we (you and I) understand it and ever see ipv6 on this side > > of the modem. I'm not holding my breath. > > If you never try setting it up, when do you expect to understand it? And > I see IPv6 on my side of the modem; I suspect many others do too. I > expect you'll get it sooner or later. What's more relevant to me is not when IPv6 is made availble to me, but when IPv4 is withdrawn. Until then, I have IPv6 disabled in the router. It really comes down to the cost/benefit ratio. Currently the benefit is almost zero, so any cost makes the ratio almost infinite. Lastly, what do you understand by the word "understand"? I wouldn't claim to understand much of IPv4 as I've no need to. Judging by your https://lists.debian.org/debian-user/2019/06/msg00554.html you're doing far more sophisticated things than I ever expect to do. I trust that by the time I might need IPv4, there'll be plenty of HOWTOs floating around for simple setups. Cheers, David.
[toc] | [prev] | [next] | [standalone]
| From | Richard Hector <richard@walnut.gen.nz> |
|---|---|
| Date | 2019-06-22 10:50 +0200 |
| Message-ID | <ybJSF-7TR-5@gated-at.bofh.it> |
| In reply to | #210219 |
[Multipart message — attachments visible in raw view] — view raw
On 22/06/19 3:01 PM, David Wright wrote: > On Wed 19 Jun 2019 at 04:23:15 (+1200), Richard Hector wrote: >> On 19/06/19 4:12 AM, David Wright wrote: >>> On Mon 17 Jun 2019 at 10:38:27 (-0400), Gene Heskett wrote: >> >>>> But that opens yet another container of worms. If I arbitrarily assign >>>> ipv6 local addresses, and later, ipv6 shows up at my side of the router, >>>> what if I have an address clash with someone on a satellite circuit in >>>> Ulan Bator. How is that resolved, by unroutable address blocks such as >>>> 192.168.xx.xx is now? >>> >>> Seems a good reason not to bother setting up ipv6 local addresses >>> until we (you and I) understand it and ever see ipv6 on this side >>> of the modem. I'm not holding my breath. >> >> If you never try setting it up, when do you expect to understand it? And >> I see IPv6 on my side of the modem; I suspect many others do too. I >> expect you'll get it sooner or later. > > What's more relevant to me is not when IPv6 is made availble to me, but > when IPv4 is withdrawn. Until then, I have IPv6 disabled in the router. Hmm. Waiting till IPv4 is turned off globally is way too long. You want to be ready for the first IPv6-only site that you want to communicate with, or which wants to communicate with you. It may be very soon, or possibly have already happened - I don't know if people trying to send me mail have failed due to my mail server not yet supporting IPv6. If you're exclusively doing client-side stuff, then I guess at least you'll be the first to know when something doesn't work :-) Is that when you want to be turning it on and figuring out any issues? > It really comes down to the cost/benefit ratio. Currently the benefit > is almost zero, so any cost makes the ratio almost infinite. > > Lastly, what do you understand by the word "understand"? I wouldn't > claim to understand much of IPv4 as I've no need to. Judging by your > https://lists.debian.org/debian-user/2019/06/msg00554.html > you're doing far more sophisticated things than I ever expect to do. > I trust that by the time I might need IPv4, there'll be plenty of > HOWTOs floating around for simple setups. Fair enough. Maybe :-) I don't claim to understand all of either IPv4 or IPv6 either. And most of my learning has been due to some requirement. But it's been a long time since I deliberately turned IPv6 off (IIRC); if something doesn't work, that's something to learn about, not to disable, if I can help it. Richard
[toc] | [prev] | [next] | [standalone]
| From | David Wright <deblis@lionunicorn.co.uk> |
|---|---|
| Date | 2019-06-24 20:20 +0200 |
| Message-ID | <ycBJn-6Ol-3@gated-at.bofh.it> |
| In reply to | #210226 |
On Sat 22 Jun 2019 at 20:45:59 (+1200), Richard Hector wrote: > On 22/06/19 3:01 PM, David Wright wrote: > > On Wed 19 Jun 2019 at 04:23:15 (+1200), Richard Hector wrote: > >> On 19/06/19 4:12 AM, David Wright wrote: > >>> On Mon 17 Jun 2019 at 10:38:27 (-0400), Gene Heskett wrote: > >> > >>>> But that opens yet another container of worms. If I arbitrarily assign > >>>> ipv6 local addresses, and later, ipv6 shows up at my side of the router, > >>>> what if I have an address clash with someone on a satellite circuit in > >>>> Ulan Bator. How is that resolved, by unroutable address blocks such as > >>>> 192.168.xx.xx is now? > >>> > >>> Seems a good reason not to bother setting up ipv6 local addresses > >>> until we (you and I) understand it and ever see ipv6 on this side > >>> of the modem. I'm not holding my breath. > >> > >> If you never try setting it up, when do you expect to understand it? And > >> I see IPv6 on my side of the modem; I suspect many others do too. I > >> expect you'll get it sooner or later. > > > > What's more relevant to me is not when IPv6 is made availble to me, but > > when IPv4 is withdrawn. Until then, I have IPv6 disabled in the router. > > Hmm. Waiting till IPv4 is turned off globally is way too long. That's not quite the same thing; I'm not waiting for the last person to turn off the lights. Personally, I'm not bother with running two stacks on the network if I can avoid it. In my case, the withdrawal that's critical is that of Roku, because we have three devices here. (The Samsung "smart" TV is unimportant—I don't recall when we last used its "tuner" section.) > You want > to be ready for the first IPv6-only site that you want to communicate > with, or which wants to communicate with you. It may be very soon, or > possibly have already happened - I don't know if people trying to send > me mail have failed due to my mail server not yet supporting IPv6. My (external) mail server can handle both, as can my ISP. So any problems would be beyond my reach. > If > you're exclusively doing client-side stuff, then I guess at least you'll > be the first to know when something doesn't work :-) Is that when you > want to be turning it on and figuring out any issues? I am, and obviously that would depend on what I'm being deprived of. I can't speak for Gene. > > It really comes down to the cost/benefit ratio. Currently the benefit > > is almost zero, so any cost makes the ratio almost infinite. > > > > Lastly, what do you understand by the word "understand"? I wouldn't > > claim to understand much of IPv4 as I've no need to. Judging by your > > https://lists.debian.org/debian-user/2019/06/msg00554.html > > you're doing far more sophisticated things than I ever expect to do. > > I trust that by the time I might need IPv4, there'll be plenty of > > HOWTOs floating around for simple setups. > > Fair enough. Maybe :-) > > I don't claim to understand all of either IPv4 or IPv6 either. And most > of my learning has been due to some requirement. But it's been a long > time since I deliberately turned IPv6 off (IIRC); if something doesn't > work, that's something to learn about, not to disable, if I can help it. Nothing doesn't work, so I'm currently sticking to the principle "Never touch a running system," and waiting for perceptible effects. Cheers, David.
[toc] | [prev] | [next] | [standalone]
| From | Andy Smith <andy@strugglers.net> |
|---|---|
| Date | 2019-06-22 21:40 +0200 |
| Message-ID | <ybU1H-5BL-13@gated-at.bofh.it> |
| In reply to | #210219 |
On Fri, Jun 21, 2019 at 10:01:47PM -0500, David Wright wrote:
> On Wed 19 Jun 2019 at 04:23:15 (+1200), Richard Hector wrote:
> > On 19/06/19 4:12 AM, David Wright wrote:
> > > On Mon 17 Jun 2019 at 10:38:27 (-0400), Gene Heskett wrote:
> >
> > >> But that opens yet another container of worms. If I arbitrarily assign
> > >> ipv6 local addresses, and later, ipv6 shows up at my side of the router,
> > >> what if I have an address clash with someone on a satellite circuit in
> > >> Ulan Bator. How is that resolved, by unroutable address blocks such as
> > >> 192.168.xx.xx is now?
> > >
> > > Seems a good reason not to bother setting up ipv6 local addresses
> > > until we (you and I) understand it and ever see ipv6 on this side
> > > of the modem. I'm not holding my breath.
> >
> > If you never try setting it up, when do you expect to understand it? And
> > I see IPv6 on my side of the modem; I suspect many others do too. I
> > expect you'll get it sooner or later.
>
> What's more relevant to me is not when IPv6 is made availble to me, but
> when IPv4 is withdrawn. Until then, I have IPv6 disabled in the router.
This is not quite the case. Here is why:
IPv4 is almost entirely exhausted. In some regions it is already
exhausted. New businesses entering the marketplace who want to
advertise services on the Internet will need to either buy IPv4 on
the auction market or else live behind something called "Carrier
Grade NAT" (CGNAT).
CGNAT can be in a couple of different configurations but the most
common are as follows:
- NAT444
Three networks of IPv4:
a) Customer's own private (RFC1918) IPv4 network.
b) Provider's own public IPv4 network, but a much smaller number
than the sum of customer networks.
c) The public IPv4 Internet.
- DS-Lite
Two networks of IPv4 with an IPv6 core:
a) Customer's own private (RFC1918) IPv4 network.
b) Provider's IPv6 core.
c) The public IPv4 Internet.
Now probably if you aren't already behind a NAT444 you're not going
to be put behind one, but it could happen to anyone at this point if
they switch ISPs.
So let's say you are an IPv4 hold-out who visits a small business's
site who can't afford to buy highly valuable IPv4 addresses of their
own¹. They are very possibly going to be behind a NAT444.
If you also are behind a NAT444 then that's 6 layers of NAT that
every packet traverses!
CGNAT devices are really expensive and not a great solution. They
have to hold a lot of state and any protocol that uses lots of ports
can run them out of their per-IP state limits. As the end users
either side don't have administrative control of the NAT in the
middle, it is not possible without provider assistance to set up
permanent mappings i.e. to set up servers that permanently hold an
IP;port pair.
NAT hampers the ability of end-to-end communication on the Internet.
The good news is that there is a very easy fix. Just start using
IPv6. There is no shortage of IPv6, so no reason why the newcomer
sites can't serve on v6 immediately, and if you view on v6 then you
side-step this entire CGNAT apparatus.
Now, in the North American and European market, outside of cellular
networks, it is still rare to end up behind a CGNAT. In the Asian
markets a lot of people are behind CGNAT because they ran out of v4
a long time ago. It's coming to us in Europe and North America too.
That is why the stance that, "I have IPv4 so I don't need to do
anything" is not completely correct: it's not urgent for much of the
world at present, but we will get into a situation where either one
or both sides of a given IP conversation are behind multiple layers
of NAT that they don't control, and that's bad.
It is essential though that ISPs turn on v6 and end users use it
without even knowing. That's the only way this gets done.
So I would say that most of the onus is on your ISP, but if they're
doing their bit and providing IPv6 and your side isn't just working
with it without you doing anything then that is a problem that
should be looked into.
If they aren't doing their bit and not providing v6 then I
personally would be asking why and looking around for another
provider, but it is the case that a lot of people are in a
near-monopoly without real choice of ISP.
Eventually the cost of CGNAT will force even those tardy ISPs to
push out v6 to their subscribers, because there comes a point where
that's cheaper than scaling the CGNAT.
Cheers,
Andy
¹ To give you some idea of how valuable, I looked up what IPv4
addresses are selling for today, and it's about $40k per /21. That
means that my business's most valuable asset as of today is its
IPv4 addresses. How will new businesses cope? I didn't have $40k
when I started my business.
--
https://bitfolk.com/ -- No-nonsense VPS hosting
[toc] | [prev] | [next] | [standalone]
| From | Gene Heskett <gheskett@shentel.net> |
|---|---|
| Date | 2019-06-22 22:50 +0200 |
| Message-ID | <ybV7r-6ec-5@gated-at.bofh.it> |
| In reply to | #210261 |
On Saturday 22 June 2019 15:34:52 Andy Smith wrote: > On Fri, Jun 21, 2019 at 10:01:47PM -0500, David Wright wrote: > > On Wed 19 Jun 2019 at 04:23:15 (+1200), Richard Hector wrote: > > > On 19/06/19 4:12 AM, David Wright wrote: > > > > On Mon 17 Jun 2019 at 10:38:27 (-0400), Gene Heskett wrote: > > > >> But that opens yet another container of worms. If I arbitrarily > > > >> assign ipv6 local addresses, and later, ipv6 shows up at my > > > >> side of the router, what if I have an address clash with > > > >> someone on a satellite circuit in Ulan Bator. How is that > > > >> resolved, by unroutable address blocks such as 192.168.xx.xx is > > > >> now? > > > > > > > > Seems a good reason not to bother setting up ipv6 local > > > > addresses until we (you and I) understand it and ever see ipv6 > > > > on this side of the modem. I'm not holding my breath. > > > > > > If you never try setting it up, when do you expect to understand > > > it? And I see IPv6 on my side of the modem; I suspect many others > > > do too. I expect you'll get it sooner or later. > > > > What's more relevant to me is not when IPv6 is made availble to me, > > but when IPv4 is withdrawn. Until then, I have IPv6 disabled in the > > router. > > This is not quite the case. Here is why: > > IPv4 is almost entirely exhausted. In some regions it is already > exhausted. New businesses entering the marketplace who want to > advertise services on the Internet will need to either buy IPv4 on > the auction market or else live behind something called "Carrier > Grade NAT" (CGNAT). > > CGNAT can be in a couple of different configurations but the most > common are as follows: > > - NAT444 > > Three networks of IPv4: > > a) Customer's own private (RFC1918) IPv4 network. > > b) Provider's own public IPv4 network, but a much smaller number > than the sum of customer networks. > > c) The public IPv4 Internet. > > - DS-Lite > > Two networks of IPv4 with an IPv6 core: > > a) Customer's own private (RFC1918) IPv4 network. > > b) Provider's IPv6 core. > > c) The public IPv4 Internet. > > Now probably if you aren't already behind a NAT444 you're not going > to be put behind one, but it could happen to anyone at this point if > they switch ISPs. > > So let's say you are an IPv4 hold-out who visits a small business's > site who can't afford to buy highly valuable IPv4 addresses of their > own¹. They are very possibly going to be behind a NAT444. > > If you also are behind a NAT444 then that's 6 layers of NAT that > every packet traverses! > > CGNAT devices are really expensive and not a great solution. They > have to hold a lot of state and any protocol that uses lots of ports > can run them out of their per-IP state limits. As the end users > either side don't have administrative control of the NAT in the > middle, it is not possible without provider assistance to set up > permanent mappings i.e. to set up servers that permanently hold an > IP;port pair. > > NAT hampers the ability of end-to-end communication on the Internet. > > The good news is that there is a very easy fix. Just start using > IPv6. There is no shortage of IPv6, so no reason why the newcomer > sites can't serve on v6 immediately, and if you view on v6 then you > side-step this entire CGNAT apparatus. > > Now, in the North American and European market, outside of cellular > networks, it is still rare to end up behind a CGNAT. In the Asian > markets a lot of people are behind CGNAT because they ran out of v4 > a long time ago. It's coming to us in Europe and North America too. > > That is why the stance that, "I have IPv4 so I don't need to do > anything" is not completely correct: it's not urgent for much of the > world at present, but we will get into a situation where either one > or both sides of a given IP conversation are behind multiple layers > of NAT that they don't control, and that's bad. > > It is essential though that ISPs turn on v6 and end users use it > without even knowing. That's the only way this gets done. > > So I would say that most of the onus is on your ISP, but if they're > doing their bit and providing IPv6 and your side isn't just working > with it without you doing anything then that is a problem that > should be looked into. > > If they aren't doing their bit and not providing v6 then I > personally would be asking why and looking around for another > provider, but it is the case that a lot of people are in a > near-monopoly without real choice of ISP. > > Eventually the cost of CGNAT will force even those tardy ISPs to > push out v6 to their subscribers, because there comes a point where > that's cheaper than scaling the CGNAT. > > Cheers, > Andy > This is likely true too. But as just a small town residential cable customer, on a 10 Mb circuit, how can I apply pressure to my isp that would speed up this deployment of ipv6? He no doubt has to buy the block of ipv6 addresses before his dhcpd v6 can pass them out. Further proving the TANSTAAFL principle. Lets say my local isp has 2k customers in this town of about 7k. Whats a good guess at his cost on a per customer basis to make it happen? > ¹ To give you some idea of how valuable, I looked up what IPv4 > addresses are selling for today, and it's about $40k per /21. That > means that my business's most valuable asset as of today is its > IPv4 addresses. How will new businesses cope? I didn't have $40k > when I started my business. Cheers, Gene Heskett -- "There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order." -Ed Howdershelt (Author) If we desire respect for the law, we must first make the law respectable. - Louis D. Brandeis Genes Web page <http://geneslinuxbox.net:6309/gene>
[toc] | [prev] | [next] | [standalone]
| From | John Hasler <jhasler@newsguy.com> |
|---|---|
| Date | 2019-06-22 23:40 +0200 |
| Message-ID | <ybVTP-6JS-9@gated-at.bofh.it> |
| In reply to | #210264 |
Gene writes: > He no doubt has to buy the block of ipv6 addresses before his dhcpd v6 > can pass them out. No one buys IPv6 addresses. There is no competition for them. They are allocated, and your ISP almost certainly already has an allocation even if they haven't registered it yet. https://www.ripe.net/publications/docs/ripe-699 -- John Hasler jhasler@newsguy.com Elmwood, WI USA
[toc] | [prev] | [next] | [standalone]
| From | Gene Heskett <gheskett@shentel.net> |
|---|---|
| Date | 2019-06-23 02:30 +0200 |
| Message-ID | <ybYyl-8nk-1@gated-at.bofh.it> |
| In reply to | #210266 |
On Saturday 22 June 2019 17:32:54 John Hasler wrote: > Gene writes: > > He no doubt has to buy the block of ipv6 addresses before his dhcpd > > v6 can pass them out. > > No one buys IPv6 addresses. There is no competition for them. They > are allocated, and your ISP almost certainly already has an allocation > even if they haven't registered it yet. > > > https://www.ripe.net/publications/docs/ripe-699 Well, I'd expect there is a registration fee, particularly since it may take a whole cluster of servers to cover locally, the whole ipv6 address space. Cheers, Gene Heskett -- "There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order." -Ed Howdershelt (Author) If we desire respect for the law, we must first make the law respectable. - Louis D. Brandeis Genes Web page <http://geneslinuxbox.net:6309/gene>
[toc] | [prev] | [next] | [standalone]
| From | John Hasler <jhasler@newsguy.com> |
|---|---|
| Date | 2019-06-23 05:00 +0200 |
| Message-ID | <yc0Tv-1hZ-1@gated-at.bofh.it> |
| In reply to | #210272 |
Gene writes:
> Well, I'd expect there is a registration fee...
>From https://www.arin.net/resources/fees/fee_schedule/
Internet Service Providers (ISPs)
Internet Service Providers (ISPs) are allocated IP addresses for
distribution to the users of their Internet services. The fee
schedule continues to encourage IPv6 adoption by providing approved
IPv6 requests up to the organization’s existing IPv4 service
category at no additional charge.
Thus an ISP that starts offering IPv6 incurs no additional fees.
> ...particularly since it may take a whole cluster of servers to cover
> locally, the whole ipv6 address space.
I don't know what you mean by that. The number of servers does not
depend on the size of the address space.
--
John Hasler
jhasler@newsguy.com
Elmwood, WI USA
[toc] | [prev] | [next] | [standalone]
| From | Gene Heskett <gheskett@shentel.net> |
|---|---|
| Date | 2019-06-23 08:30 +0200 |
| Message-ID | <yc4aJ-3n6-1@gated-at.bofh.it> |
| In reply to | #210278 |
On Saturday 22 June 2019 22:49:36 John Hasler wrote: > Gene writes: > > Well, I'd expect there is a registration fee... > > From https://www.arin.net/resources/fees/fee_schedule/ > > Internet Service Providers (ISPs) > > Internet Service Providers (ISPs) are allocated IP addresses for > distribution to the users of their Internet services. The fee > schedule continues to encourage IPv6 adoption by providing > approved IPv6 requests up to the organization’s existing IPv4 service > category at no additional charge. > > Thus an ISP that starts offering IPv6 incurs no additional fees. > > > ...particularly since it may take a whole cluster of servers to > > cover locally, the whole ipv6 address space. > > I don't know what you mean by that. The number of servers does not > depend on the size of the address space. That doesn't compute John, unless a 30+ second dns lookup time would be tolerable. That would have customers carrying pitchforks storming the offices. Cheers, Gene Heskett -- "There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order." -Ed Howdershelt (Author) If we desire respect for the law, we must first make the law respectable. - Louis D. Brandeis Genes Web page <http://geneslinuxbox.net:6309/gene>
[toc] | [prev] | [next] | [standalone]
| From | Pascal Hambourg <pascal@plouf.fr.eu.org> |
|---|---|
| Date | 2019-06-23 11:20 +0200 |
| Message-ID | <yc6Pf-4Xd-5@gated-at.bofh.it> |
| In reply to | #210281 |
Le 23/06/2019 à 08:27, Gene Heskett a écrit : > On Saturday 22 June 2019 22:49:36 John Hasler wrote: > >> Gene writes: >>> Well, I'd expect there is a registration fee... >>> ...particularly since it may take a whole cluster of servers to >>> cover locally, the whole ipv6 address space. >> >> I don't know what you mean by that. The number of servers does not >> depend on the size of the address space. > > That doesn't compute John, unless a 30+ second dns lookup time would be > tolerable. Why would a DNS lookup take 30 seconds ? Anyway, this is irrelevant. Registries who assign address blocks do not manage DNS lookups. They just manage delegations to the organizations which manage reverse DNS zones. Besides, a reverse DNS zone does not have to serve PTR records for all IP addresses in the block.
[toc] | [prev] | [next] | [standalone]
| From | Andy Smith <andy@strugglers.net> |
|---|---|
| Date | 2019-06-26 20:40 +0200 |
| Message-ID | <ydkZP-b7-5@gated-at.bofh.it> |
| In reply to | #210261 |
On Sat, Jun 22, 2019 at 07:34:52PM +0000, Andy Smith wrote:
> That is why the stance that, "I have IPv4 so I don't need to do
> anything" is not completely correct: it's not urgent for much of the
> world at present, but we will get into a situation where either one
> or both sides of a given IP conversation are behind multiple layers
> of NAT that they don't control, and that's bad.
I recently came across a couple of articles that indicate that due
to the issues I mentioned in this email, IPv6 is already faster than
IPv4:
https://www.retevia.net/fast/
…and that this has some interesting effects on the economics for
carriers (ISPs) and content providers (e.g. web hosts and large
retailers) of v6 vs v4:
https://www.retevia.net/prisoner/
Cheers,
Andy
--
https://bitfolk.com/ -- No-nonsense VPS hosting
[toc] | [prev] | [next] | [standalone]
| From | Michael Stone <mstone@debian.org> |
|---|---|
| Date | 2019-06-26 21:00 +0200 |
| Message-ID | <ydljb-hH-3@gated-at.bofh.it> |
| In reply to | #210421 |
On Wed, Jun 26, 2019 at 06:37:25PM +0000, Andy Smith wrote: >On Sat, Jun 22, 2019 at 07:34:52PM +0000, Andy Smith wrote: >> That is why the stance that, "I have IPv4 so I don't need to do >> anything" is not completely correct: it's not urgent for much of the >> world at present, but we will get into a situation where either one >> or both sides of a given IP conversation are behind multiple layers >> of NAT that they don't control, and that's bad. > >I recently came across a couple of articles that indicate that due >to the issues I mentioned in this email, IPv6 is already faster than >IPv4: Yup. In my area all the bandwidth-intensive stuff from mobile devices is already going over a nice IPv6 route; it's unfortunate that the wired providers have dragged their feet so much.
[toc] | [prev] | [next] | [standalone]
| From | Richard Hector <richard@walnut.gen.nz> |
|---|---|
| Date | 2019-06-18 11:50 +0200 |
| Message-ID | <yaiUx-37G-5@gated-at.bofh.it> |
| In reply to | #209977 |
[Multipart message — attachments visible in raw view] — view raw
On 17/06/19 9:59 PM, Jonathan Dowland wrote: > On Mon, Jun 17, 2019 at 10:05:11AM +0100, mick crane wrote: >> Without knowing anything about it I'm wondering if I should request an >> IPv6 range from my ISP to use locally. > > You don't need a global IPv6 address allocation in order to have local > IPv6 addresses. Much like 127.0.0.0/8 (etc.) for IPv4 there are reserved > ranges. 127.0.0.0/8 is for loopback addresses; ::1 is the IPv6 equivalent. Reserved ranges for local use are the RFC1918 ranges (192.168.0.0/16, 172.16.0.0/12 and 10.0.0.0/8), and more closely replaced by ULAs (fd00::/8) in IPv6. Richard
[toc] | [prev] | [next] | [standalone]
| From | Jonathan Dowland <jmtd@debian.org> |
|---|---|
| Date | 2019-06-21 17:30 +0200 |
| Message-ID | <ybtEe-6pK-7@gated-at.bofh.it> |
| In reply to | #210029 |
On Tue, Jun 18, 2019 at 09:49:10PM +1200, Richard Hector wrote: >127.0.0.0/8 is for loopback addresses; ::1 is the IPv6 equivalent. >Reserved ranges for local use are the RFC1918 ranges (192.168.0.0/16, >172.16.0.0/12 and 10.0.0.0/8), and more closely replaced by ULAs >(fd00::/8) in IPv6. Yes sorry, 127.0.0.0/8 is a typo here (I intended to type 192.168.0.0/16) -- Jonathan Dowland
[toc] | [prev] | [next] | [standalone]
| From | andreimpopescu@gmail.com |
|---|---|
| Date | 2019-07-02 11:10 +0200 |
| Message-ID | <yfmXv-789-3@gated-at.bofh.it> |
| In reply to | #209975 |
[Multipart message — attachments visible in raw view] — view raw
On Lu, 17 iun 19, 10:05:11, mick crane wrote: > hello, > I know nothing about IPv6. Then you don't have any prejudices ;) (no, IPv6 doesn't break your network). > Can somebody point to a good explanation ? > Without knowing anything about it I'm wondering if I should request an IPv6 > range from my ISP to use locally. If it's free (cost) and you have the time to set it up properly. > A network card have IPv4 and IPv6 addresses that are different, not the same > address in different notation ? > Then with firewalling do you need to specify both IPv4 and IPv6 ranges ? Yes, as others have pointed out. What I didn't see mentioned in this thread is that IPv6 does not need/use NAT. Some users rely on NAT in IPv4 as some sort of protection (it is not, you still need a firewall). When properly configured[1] with IPv6 all devices on your home network supporting it will be directly accessible from the internet (by design). Your firewall rules may need to be adjusted to account for this. [1] depending on your ISP and/or modem you might not need to do anything at all with most recent OSes in their default configuration. Kind regards, Andrei -- http://wiki.debian.org/FAQsFromDebianUser
[toc] | [prev] | [standalone]
Page 3 of 3 — ← Prev page 1 2 [3]
Back to top | Article view | linux.debian.user
csiph-web