7 ms·
A brief history of IPv4 address space exhaustion
- rst 9y agoCorrections: CIDR stands for Classless Inter Domain Routing (because it superseded the Class A/Class B/Class C arrangement, which allowed only three particular allocation block sizes).
- metalliqaz 9y agoI now receive a block of IPv6 from Comcast. I allow the router to assign them to devices on the network, but I admit that I am somewhat worried that my local PC is no longer isolated from the Internet by a private IP.
- lwhalen 9y agoYou want to set up an 'egress only' v6 gateway for your /64s (or however you carve up your netblock). That is going to be the closest analogue to behind-a-NAT-like behavior.
- metalliqaz 9y agoThanks I'll look into it with pfSense.
- bArray 9y agoI think whilst it's nice to have that barrier, it's prevention rather than cure anyway. There's no substitute for secure devices :)
- 2bitencryption 9y agowhat's more secure than a device you cannot possibly reach? I'll take an insecure device isolated at the bottom of the ocean in a titanium block over a probably-secure device that is publicly addressable any day.
- Spivak 9y agoYour appliance 'router' can (and probably does) run a firewall to give you that kind of control. NAT never really gave you that.
- linkregister 9y agoWhich devices are secure?
- deleted 9y ago[deleted]
- JetSpiegel 9y agoYour router has a firewall, external computers can't just send packets to the internal addresses. NAT is not a firewall.
- mirimir 9y agoSo IPv6 firewall rules are common now for consumer routers?
- Spivak 9y agoFirst, nothing is common for consumer IPv6 routers, they're practically non-existent. Second, you get the same security benefits by having a firewall that denies outbound connections not already established.
- sparewalking 9y agoI bought an IPv6 router 3-4 years ago.
- voltagex_ 9y agoMost people don't buy routers, they are given them by their ISPs. My parents switched ISP at the start of the year and were given a 5 year old modem/router.
- Spivak 9y agoYou're also on Hacker News. They have been available for a long time, but they're firmly a techie/early adopter product.
- Symbiote 9y agoIn many countries the ISP supplies the router. I've had IPv6 capable routers for years and years in Britain, but it's only in the last 2 years or so that the IPv6 address has been assigned by the ISP.
- 9y ago
- mavendependency 9y agoThis is the case for ipv6 on mobile data by default. Would using a usb modem result in getting affected by smb exploits or something of the sort?
- belorn 9y agoBe sure that you are really isolated if relying on it for protection. Its only as secure as the least secure node inside the bubble, and there can be quite a dangerous in large networks like in a company or campus. It would not surprise me if a number of WannaCry victims was behind nat and got infected by a machine on the same local network.
- djsumdog 9y agoI was at a company that made a mistake like this during their IPv6 rollout. The firewalls are different an individual, and initially they only had iptables rules on their BGR and an empty ip6tables set.
- bArray 9y agoWould have been awfully nice to have a reserved bit in hindsight. 7 bit ASCII was an amazing accident. (Maybe it wasn't, time to brush up on my history...)
- DaiPlusPlus 9y agoIf you're advocating for the introduction of variable-length IP addresses then it would have been a nightmare - packet-switching is often done in hardware and that level of complexity would have only added trouble.
- bArray 9y agoAny harder than implementing IPv6 in hardware? I'm talking about an adjustment that would keep older machines talking to older addresses, whilst newer machines could implement extended IPv4, for example. From my potential ignorance, I'm not sure how that would be more difficult? I think it's theoretical of course, I don't believe there is a reserved bit in the IPv4 range.
- dogecoinbase 9y agoWe do/did! Class E space (240.0.0.0/4) exists and is entirely unused. There was a proposal in 2008-ish to try and convert it to regular IP space for allocation, but the agreement was that it would be too much work (many stacks default drop class E packets) and we should focus on transitioning to IPv6.
- bArray 9y agoThanks, I wasn't really aware of this. Class E wouldn't add too much to the IP address space if I understand this correctly? I was thinking more along the lines of a bit being flipped would mean the next 8 bytes are an IP and not four, for example. From my limited understanding, I don't think they reserved a bit in the address space?
- dboreham 9y agoUnfortunately my perception is that IPv6 deployment is stalled (due to inaction by ISPs). In my company we have recently dismantled some of our IPv6 infrastructure because it became apparent that ubiquitous v6 connectivity was not coming any time soon (e.g. we have locations served by Charter/Spectrum, and they have no IPv6 and no plan to deploy it). We've instead deployed a private IPv4 overlay network between our sites and assets using GRE tunnels. Also somewhat exasperating that the "running out of IPv4 addresses" saga has played out across almost my entire career. I remember attending the CIDR meetings at the IETF in around 1992, for example. So one of the first technical problems I encountered in my career remains unsolved nearly 30 years later.
- bpodgursky 9y agoI don't think that perception is accurate. Google's IPv6 tracker shows continual progress: https://www.google.com/intl/en/ipv6/statistics.html https://www.google.com/intl/en/ipv6/statistics.html (with the expected bumps around weekends and holidays) It's not a fast process, but I don't see any evidence it is stalled.
- votepaunchy 9y agoHow much progress is simply due to mobile? Not a bad thing, but legacy ISPs seem to be updating at a glacial pace.
- tomschlick 9y agoComcast is one of the leaders in this space in the US. They are nearing 100% deployment and their X1 platform is supposed to run IPv6 only internally (SetTop Boxes to their content source). Verizon on the other hand hasn't done shit.
- otterley 9y agoMy Verizon Wireless iPhone has a v6 address. Maybe you mean FIOS?
- 9y ago
- exabrial 9y agoWe only use 32 bits of each 48 bit ipv4 address. The problem isn't exhaustion, it's using DNS to do service location rather than IP.
- syncsynchalt 9y agoIf you mean ports, those aren't IP. Those are TCP/UDP.
- porfirium 9y agoI know the author is Spanish; I'd like to point out Orange Spain has been deploying IPv6 addresses to end customers these last weeks using the Dual Stack lite transition system. All the big ISPs have been testing IPv6 for years now and I'm sure it's just a matter of flipping a switch. Now that a new contender is in town (a 4th ISP) and they're having huge problems because they have no IP addresses left to assign to their customers, I suppose the rest of ISPs will stall even more their transition to IPv6 so they can try and "suffocate" the new ISP. Just my two cents...
- FullyFunctional 9y agoI find DJB's take on this interesting: https://cr.yp.to/djbdns/ipv6mess.html https://cr.yp.to/djbdns/ipv6mess.html EDIT: Dan has many excellent points, but I'd like to quote my favorite: The IPv6 designers made a fundamental conceptual mistake: they designed the IPv6 address space as an alternative to the IPv4 address space, rather than an extension to the IPv4 address space. Indeed, what were they thinking! It's certainly an undeniable fact that IPv6 adoption has been a disaster, taking much longer than hoped for. Frankly, I expect to see IPv4 coexist with IPv6 for the next hundred years - not ideal.
- cesarb 9y agoOne thing I never understood in these proposals: how would two computers, one with only an extended address and the other with only an IPv4 address, talk to each other? Or two computers with extended addresses, but with a single router in the middle of their path which doesn't understand extended addresses? All these proposals I've seen appear to assume that extended addresses start being distributed only after every or almost every host and router in the whole world had all of its software upgraded to understand extended addresses. But that's not realistic, since without being able to actually use it, there would be no incentive to modify every single piece of network-facing software and hardware to be able to use extended addresses. It's a Catch-22.
- lisper 9y ago> One thing I never understood in these proposals: how would two computers, one with only an extended address and the other with only an IPv4 address, talk to each other? Via a NAT router that talks v4 on one side and v6 on the other.
- cesarb 9y agoA NAT router is not enough. Suppose the v4 side wants to initiate the communication; to which address would it send the initial packet? Remember, the "v4 side" has no concept of extended addresses at all, for it every address must be 32 bits and nothing more. And it also doesn't solve the "v4 router in the middle of the path" problem.
- gwu78 9y agohttp://www.internetsociety.org/deploy360/blog/2017/05/google-buys-a-12-ipv4-address-block/ http://www.internetsociety.org/deploy360/blog/2017/05/google...
- gens 9y agoIANA sold the blocks. There are still a lot of unused IPv4 addresses. IANA sold the blocks. PS IPv6 sucks.
- jcranmer 9y agoThe IANA blocks were exhausted in January 2011. All of the RIRs save AFRINIC exhausted their internal allocation pools since then: APNIC in April 2011, RIPE September 2012, LACNIC June 2014, and ARIN September 2015 (although note that the definition of "exhaustion" differs from RIR to RIR--ARIN in particularly relied on a truly-bone-dry definition whereas APNIC claimed exhaustion when they had less then a full /8 in their pool). As of right now, ARIN appears to have exactly 0 IPv4 addresses--they can't even give out a block of 256 IPv4 addresses to someone who asks for it. All they can do is put you on a waiting list until someone else agrees to give up their IPv4 address space. Some people have been waiting since July 2015.
- deleted 9y ago[deleted]
- bogomipz 9y agoIf you enjoyed this, this is a great resource current state of prefix utilization in the global routing tables: http://www.cidr-report.org/as2.0/ http://www.cidr-report.org/as2.0/
- redm 9y agoIPv4 is like any commodity. Now that it's not easily to get from ARIN, a market has sprung up around buying and selling it. It's still relatively easy to get IPv4 blocks for a buck or two per IP through auction houses.
- zlynx 9y agoAlthough whatever block you get has to be big enough to convince people to route to it. Too small and it won't matter. No ISP wants to carry the load for millions of tiny IPv4 blocks.
- icedchai 9y agoThe smallest you can get is a /24, and everyone accepts routes for that. In 1997, I remember running 2 T1's w/BGP on a router with a whopping 32 megs of RAM. I think there were 50,000 routes! How things have changed...
- djsumdog 9y agoI've only worked at one company that had full IPv6 support. Even on my current 1GbE fibre setup with a small startup, they still don't have IPv6 rolled out to residents yet. :( I feel like one big hurdle is IPv6 usability. You can write down and easily remember IPv4 addresses. IPv6 netmasks can get really confusing. They make sense if you expand out every block, but in reality, IPv6 requires a lot of tooling to chop up and work with address spaces in an intuitive way.
- Xorbitant 9y agoI think this is the key point. It's too hard to understand, and adds a lot of what I would consider extraneous and over-engineered guff. People will naturally resist it when what they have, works. The only thing that needed fixing was the address space (imo, as far as I can see), but if I need to turn it on, I now have to worry about weird routing, special addresses (IPv4 has some, but IPv6 seems to have taken it to a new level), understanding hexadecimal addresses, translation layers etc. What a mess, just extend the address space.
- deathanatos 9y agoUse DNS. Seriously. We use IPv4 where I work, and we don't use DNS, and it's still a nightmare. There's no good way to refer to a machine, short of an IPv4 address, and that's still painful to speak and hard to memorize. Life is much easier when you can speak of a machine as "2.dev.awesome-service" (.your-company.com) Besides, the machines should be ephemeral, and the new ones will likely get new IPs. (Unless you're doing something like EIPs, but just stop that and use DNS. ;-) )
- rschulman 9y agoI love it when people make this argument. The IPv6 adoption hurdle is NOT the usability of v6 addresses. 99% of the world thinks that IPv4 addresses are a horrorshow and would never bother to memorize one or even write one down. They use DNS because they are human beings. The layout of the address behind the DNS they couldn't care less about.
- vidoc 9y ago
- pololee 9y agoWhen I was at UCLA, I learned this new architecture called NDN https://named-data.net/ https://named-data.net/. It does not rely on addressable device or host. It give addresses to content. Not sure how industry think of this new idea. I watched several talks about NDN. They all have great stories and believe it's the future.
- voltagex_ 9y agohttp://named-data.net/doc/NFD/current/manpages/ndn-autoconfig.html#ndn-hub-discovery-procedure http://named-data.net/doc/NFD/current/manpages/ndn-autoconfi... Still relies on TCP and UDP and thus still needs IP addresses.
- deleted 9y ago[deleted]