6 ms·
What about the benefit of there being enough addresses?
by eulenteufel 9mo ago
What about the benefit of there being enough addresses?
- the_mitsuhiko 9mo agoThe widespread deployment of NAT and VPNs has counter acted the market forces that were assumed to make IPv6 appealing.
- NewJazz 9mo agoIPv4 addresses are still expensive. NAT is a value add for a lot of cloud platforms. IPv6 has arguably done more to counteract market forces related to IPv4 address exhaustion.
- coredog64 9mo agoIt's my dream that one day I'll be able to run an AWS VPC that only has IPv6 for the private subnets and then I'll never have to worry about managing the address space or how many IP addresses each ALB consumes.
- throw0101a 9mo ago> The widespread deployment of NAT and VPNs has counter acted the market forces that were assumed to make IPv6 appealing. Tell that to everyone who is behind CG-NAT and has issues with (e.g.) video games. Or all the (small(er)) ISPs that have to layout CapEx for translation boxes.
- rao-v 9mo agoHonestly the games issue might be out of day. Game devs have access to great services to punch through NAT at this point. Tech finds a way…
- coryrc 9mo agoWhich has led to every game needing a central server running, forcing centralization where p2p used to work great. Also how Skype was able to scale on a budget, something now blocked, forcing you to raise money for more ideas than before. Running a matrix(?) node should be as simple as clicking install and it's just there, next time you're with your friends, nfc tap or whatever and your servers talk to each other directly forever going forward. But nope, there always is a gatekeeper now and they need money and that poisons everything.
- everforward 9mo agoI don’t think VOIP was a major factor in game centralization. The big one was selling cosmetics (easily unlock able server-side in community servers), and to some extent being able to police voice chat more. Major game publishers didn’t want to be in the news about the game with the most slurs or child grooming or what not.
- chongli 9mo agoCentral servers are useful for more than just NAT hole-punching. They’re also great as a centralized database of records and statistics as well as a host for anti-cheating services and community standards enforcement. Peer to Peer games with no central authority would be so rife with cheating that you’d only ever want to play with friends, not strangers. That sucks!
- throw0101a 9mo ago> Peer to Peer games with no central authority would be so rife with cheating that you’d only ever want to play with friends, not strangers. That sucks! Back in the the day RtCW had a server anyone could run and you could give out the address: * https://en.wikipedia.org/wiki/Return_to_Castle_Wolfenstein https://en.wikipedia.org/wiki/Return_to_Castle_Wolfenstein There was a server that a ISP / cable company in the southern US ran that I participate in and it was a great community with many regulars. P2P can be awesome with the right peers.
- chongli 9mo ago
- reincarnate0x14 9mo agoSo we acknowledge v4 and CG-NAT are a problem but don't want to use the already available solution because game developers took it upon themselves to DEFEAT NAT :) That just reminded me of a peer protocol I worked on a long time ago that used other hosts to try to figure out which hosts were getting translated. Kind of like a reverse TOR. If that was detected, the better peering hosts would send them each other's local and public addresses so they could start sending UDP packets to each other, because the NAT devices wouldn't expect the TCP handshake first and so while the first few rounds didn't make it through, it caused the NAT device(s) to create the table entries for itself. Was it Hamachi that was the old IPX-over-IP tunneling? I'm fairly sure it used similar tricks. IPX-over-IP is also done on DOSBOX, which incidentally made it possible to play Master of Orion 2 with friends in other continents.
- pix128 9mo agoI can spin up a NAT puncher today without having to depend on anybody. Can't say the same for IPv6.
- lmz 9mo ago> That just reminded me of a peer protocol I worked on a long time ago that used other hosts to try to figure out which hosts were getting translated. Kind of like a reverse TOR. If that was detected, the better peering hosts would send them each other's local and public addresses so they could start sending UDP packets to each other, Sounds similar to STUN, really.
- reincarnate0x14 9mo agoIf that's the VOIP thing, yes, lots of people came to similar methods. That particular thing was for exchanging state, not VOIP or tunneling, so as long as participant groups overlapped it didn't really need a fixed server to be the middle which was handy for our purposes, although long network interruptions could make reconvergence take a while. Does make me chuckle that so many people had to be working around NAT for so long and then people are like "NAT is way better than the thing that makes us not have to deal with the problem at all." Just had a bit of NAT PTSD remembering an unrelated, but livid argument between some network teams about how a tool defeating their NAT policies was malware. They had overlapping 10.x.y.z blocks, because of course they did :)
- viraptor 9mo agoNat hole punching works... most of the time. There are many edge cases and weird/broken networks which you just can't work around in standard ways. You get to see all kinds of broken setups if you work at VoIP providers. That's why everyone will use a central proxy server as the last resource - you'll mostly notice it only because of a higher ping.
- AtlasBarfed 9mo agoIsn't CGnat due to IPv6 use on the mobiles? You could quit and say that's an IPv6 problem that didn't get solved in the IPv6 engineering
- nulbyte 9mo agoWhy would CGNAT be deployed as a response to IPv6 on mobile? I don't understand the logic there. CGNAT is deployed due to a shortage of publicly routable IPv4 addresses. IPv6 was introduced due to having much larger publicly routable space.
- AtlasBarfed 9mo agoBecause the internet as a whole is ipv4. The mobiles are IPv6. The ipv4 internet does not care about any server running on any mobile device. Thus, CG Nat was invented so that IPv6 could talk to IPv4 and get the information from it.
- aragilar 9mo agoNo, CGNAT (Carrier-Grade NAT - https://en.wikipedia.org/wiki/Carrier-grade_NAT https://en.wikipedia.org/wiki/Carrier-grade_NAT) is an IPv4 only thing. https://www.rfc-editor.org/rfc/rfc6598 https://www.rfc-editor.org/rfc/rfc6598 specifies they should use 100.64.0.0/10 for it, to avoid conflicting with the pre-existing private-use ranges. IPv6 removes the need for using CGNAT, as each home router is allocated a public IP (rather than a CGNAT IP) on its public link.
- AtlasBarfed 8mo agoOh so cgnat exists for ipv4 addresses to talk to IPv6 servers? Is that what you are telling me? Because all of the www is in IPv6, and cgnat actually excuses for ipv4 cable users to use the bedrock internet servers and services? Bullshit. Cgnat is a hack for ipv6 to talk to the ipv4 universe. Because if there were magically enough iov4 addresses for mobiles, would cgnat exist? No, it wouldn't.
- jpdb 9mo agoThat particular benefit has no value if you still need to support v4. It's almost a self-inflicted tragedy of the commons or reverse network-effect. Adopting IPv6 doesn't alleviate the pain of IPv4 exhaustion if you still need to support dual-stack.
- craftkiller 9mo agoIt still helps. I have a 1U in a colo which gives me a /64 for ipv6 and ~5 addresses for ipv4. I just set up a dual stack kubernetes cluster on 6 virtual machines. When I want to ssh into one of the machines, my options are either: 1. Use IPv6 which works and goes directly to the virtual machine because each virtual machine grabs its own address from one of my 18446744073709551616 addresses. 2. Use IPv4 and either have to do a jumphost or do port forwarding, giving each virtual machine its own port which forwards to port 22 on the virtual machine. 3. Use a VPN. I have all 3 working, but #1 was significantly less setup and works the best. Also being able to generate unique ULA subnets is super nice.
- wolvoleo 9mo agoReally using port 22 is very ill advised anyway because you will get constant nuisance brute force attacks (accomplishing nothing because you're using keys or certificates I hope) but still eating up cycles for the crypto handshake.
- Dagger2 9mo agoReally? I get somewhere in the region of none to barely any, depending on the server. I mean, yes, you'll get a constant stream of them on IPv4, but why would you run a server on v4 unless you absolutely needed to? The address space is so small you can scan every IP in 5 minutes per port, and if you have my v4 address you can enumerate every single server I'm running just by scanning 65k ports. Meanwhile, on v6, even the latter of those takes a thousand years. How would people even find the server?
- craftkiller 9mo agoBy that same logic, using IPv4 is ill-advised because I could easily give the ssh endpoints their own IPv6 addresses, avoiding the need to hide behind non-standard ports. Scanning through 18446744073709551616 addresses is going to be a lot slower than scanning through 65536 ports.
- Spooky23 9mo agoThere’s zero benefit to you because the carrier is NATing you for other purposes. They get better network management.
- cortesoft 9mo agoThat is a collective problem, though, not an individual one. I have always been able to get enough v4 addresses for all my needs.
- adolph 9mo agoYep, iot would be a tremendously worse security problem if everyone wasn't actually operating a household subnet without knowing it. When your washing machine, fridge, etc all come with ipv6 5g modems is when your house becomes part of the future IT battlescape between lots of different entities that do not wish you well.
- abujazar 9mo agoNo, because sensibly configured routers would still block incoming traffic regardless of NAT.
- chongli 9mo agoIf your dishwasher has a 5G antenna + modem built-in and connects to the manufacturer’s own wireless account then your router doesn’t enter the picture. The dishwasher can happily serve you ads and conduct routine surveillance all day long and the only thing you can do is cut power to the device (until they start including a battery backup for that stuff).
- abujazar 9mo agoTrue, but the dishwasher should have its own firewall regardless, and assuming it'll be on IPv4 behind a firewalled NAT is by itself an implementation error.
- chongli 9mo agoMy point is that you don't control what network the dishwasher is on, the manufacturer does. The dishwasher connects to its own cellular network so that you cannot block any of its ads or prevent it from spying on you.
- _moof 9mo agoEnough addresses for what? Nobody needs or even wants all of their devices to have globally routable addresses.
- crote 9mo agoEnough addresses for proper P2P connectivity, which is kinda useful for newfangled things like video chat?
- easterncalculus 9mo agoWe’re supposedly mere years away from superintelligence, but it’s still literally impossible to just send a file between two clients without configuring intermediate network hardware or performing some hack to get around NAT (which can still fail and then require an intermediate server) if both clients are behind CGNAT. It’s genuinely disheartening to see so many people here not even begin to try to understand how much we’re missing by not having effortless end-to-end connectivity, in favor of expensive cloud services. This literally used to be what the “Internet” is - we’re definitionally not on one without this.
- throw0101a 9mo ago> Enough addresses for what? Nobody needs or even wants all of their devices to have globally routable addresses. They do if they have applications, such as Xbox/PS gaming applications, broken VoIP in gaming lobbies, failure of SIP client to punch through etc. And if an ISP does not have, or cannot afford, to get enough IPv4 to hand each of their customers at least one to assign to the CPE's WAN port, you're now talking about CG-NAT, which a whole other level of breakage.
- djha-skin 9mo agoEveryone who says this is obviously a web developer.