Are you on IPv4 or IPv6 (Poll)

2»

Comments

  • edited April 2024

    @somik said:

    That's almost fulll IPv6 adoption for your country. Weird how Indonesia and India are leading IPv6 adoption!

    Actually it's not.
    The countries that are "getting online" in the last decades or so does not have the enormous burden of the ip4 legacy, since they have to build from scratch they use ipv6 as their main protocol. Nobody in their right mind will build a new infrastructure today and base it on ip4, that would be insane.
    Also, India have an enormous population, if everyone in India needed an ip4 they alone would use ~30% of the total ip4 space.

  • @somik said: If IPv6 connects all devices over the internet, is there a need to setup wireguard to connect the devices to one another?

    A mesh VPN is beyond the scope of solving my issues, if that's what you mean. A simple Wireguard VPN is enough.
    Sadly all my ISPs (home & mobile) are IPv4 only.

  • @somik said:

    @shell said:
    location, indonesia

    home 1, ftth as7713 : native ipv6 + ipv4
    home 2, ftth as7713 : native ipv6 + ipv4
    home 3, ftth local isp : ipv4 only
    work , ftth as17451 : native ipv6 + ipv4
    mobile 1, xl axiata : native ipv6 + ipv4
    mobile 2, indosat ooredoo : native ipv6 + ipv4

    That's almost fulll IPv6 adoption for your country. Weird how Indonesia and India are leading IPv6 adoption!

    @rcy026 said:

    @somik said:

    Damn, so it's like 1234:5678:9abc:de01:: is just 1 IP while anything expanded from there is the sub IP/routes under that one ip...

    So basically instead of using NAT, all devices in one client are put on the internet through that one block of /64 IP while each device gets a /128 part of that IP block?

    Technically that should work (as long as you get the arp stuff right) but if you are to be true to the rfc's, no, that's not how you should do it. Each customer should actually get a /48 or /56. :smile:

    The correct way would be that the ISP assigns a /48 or /56 to the customers router. The customers router then splits this into /64's. The reason for this is that SLAAC, the automatic assigning of ipv6 addresses, only works in /64 networks so if the devices on the "inside" should be able to use SLAAC they need to be in a /64 network.
    SLAAC is a multiple step process but basically it boils down to the clients on the network using their own mac-adress combined with the network prefix to calculate their own ipv6 adress. There is no server that assigns addresses like in dhcp, the clients simply figures out their ip and gateway on their own.

    Google SLAAC and EUI-64 if you want to read up on it, ipv6 gets really fun once you start to understand it. :smile:
    https://www.networkacademy.io/ccna/ipv6/stateless-address-autoconfiguration-slaac is a good start.

    Ya, my routers get /64 IP from the network provider. Since I got 3 lines, I got 3 blocks of /64 IPv6, one for each of my routers. Bookmarked the url. Will go through it tomorrow.

    @AuroraZero said:
    I am on Crack v10

    It is not good to be on crack...

    @mfs said:
    IPv6 adoption here is inane, I setup a Wireguard VPN on all my devices in order to have IPv6 connectivity.

    If IPv6 connects all devices over the internet, is there a need to setup wireguard to connect the devices to one another?

    Should be okay it is just butt crack

    The Yeti has left the building.

  • @terrorgen said:

    @DataRecovery said:

    @somik said: why are people still using it

    Because we can afford premium, IPv4-only connectivity.

    • IPv6 is soy milk, IPv4 is rich full cream milk;
    • IPv6 is margarine, IPv4 is dairy butter;
    • IPv6 is instant noodles, IPv4 is pasta Bolognaise;
    • IPv6 is roasted cockroaches, IPv4 is Wagyu steak.

    premium only exists in your mind.

  • somiksomik OG Hostbusters

    @rcy026 said:

    @somik said:

    That's almost fulll IPv6 adoption for your country. Weird how Indonesia and India are leading IPv6 adoption!

    Actually it's not.
    The countries that are "getting online" in the last decades or so does not have the enormous burden of the ip4 legacy, since they have to build from scratch they use ipv6 as their main protocol. Nobody in their right mind will build a new infrastructure today and base it on ip4, that would be insane.
    Also, India have an enormous population, if everyone in India needed an ip4 they alone would use ~30% of the total ip4 space.

    True. If you need to buy hardware, might as well get the ones that support IPv6 since it'll be cheaper to run it in the long term. Moreover, new ISP would rarely buy used hardware. Since most new hardware supports IPv6 I guess that's what they are getting.

    @mfs said:

    @somik said: If IPv6 connects all devices over the internet, is there a need to setup wireguard to connect the devices to one another?

    A mesh VPN is beyond the scope of solving my issues, if that's what you mean. A simple Wireguard VPN is enough.
    Sadly all my ISPs (home & mobile) are IPv4 only.

    Oh, so only the servers are IPv6 but the home are still IPv4. That's weird!

    @AuroraZero said:
    Should be okay it is just butt crack

    Only if you are a plumber. Mario, is that you? :lol:

    I speak fluent sarcasm and broken logic. | I would agree with you, but thæn we’d both be wrong.

  • edited April 2024

    @somik said:

    @shell said:
    location, indonesia

    home 1, ftth as7713 : native ipv6 + ipv4
    home 2, ftth as7713 : native ipv6 + ipv4
    home 3, ftth local isp : ipv4 only
    work , ftth as17451 : native ipv6 + ipv4
    mobile 1, xl axiata : native ipv6 + ipv4
    mobile 2, indosat ooredoo : native ipv6 + ipv4

    That's almost fulll IPv6 adoption for your country. Weird how Indonesia and India are leading IPv6 adoption!

    I'm just lucky to live in a place that is covered by a big ISP, there is plenty (more than hundred) small ISP that not offering ipv6.

    fyi, indonesia have more than 1000+ licenced ISP and 8000++ island.

  • somiksomik OG Hostbusters

    @shell said:

    @somik said:

    @shell said:
    location, indonesia

    home 1, ftth as7713 : native ipv6 + ipv4
    home 2, ftth as7713 : native ipv6 + ipv4
    home 3, ftth local isp : ipv4 only
    work , ftth as17451 : native ipv6 + ipv4
    mobile 1, xl axiata : native ipv6 + ipv4
    mobile 2, indosat ooredoo : native ipv6 + ipv4

    That's almost fulll IPv6 adoption for your country. Weird how Indonesia and India are leading IPv6 adoption!

    I'm just lucky to live in a place that is covered by a big ISP, there is plenty (more than hundred) small ISP that not offering ipv6.

    fyi, indonesia have more than 1000+ licenced ISP and 8000++ island.

    Indonesia has 17,508 islands officially; of which, only around 6,000 have people living on them. Given that most islands don't even have electricity, I doubt they want IPv6 (or any internet connectivity) there. The major islands where there is connectivity, there is good internet connectivity. Unfortunaly, bigger ISPs do not want to move to support smaller islands, and smaller ISPs do not want to buy new infra and buys and makes due with second hand infra without IPv6 support? Who knows...

    I speak fluent sarcasm and broken logic. | I would agree with you, but thæn we’d both be wrong.

  • @shell said:

    @somik said:

    @shell said:
    location, indonesia

    home 1, ftth as7713 : native ipv6 + ipv4
    home 2, ftth as7713 : native ipv6 + ipv4
    home 3, ftth local isp : ipv4 only
    work , ftth as17451 : native ipv6 + ipv4
    mobile 1, xl axiata : native ipv6 + ipv4
    mobile 2, indosat ooredoo : native ipv6 + ipv4

    That's almost fulll IPv6 adoption for your country. Weird how Indonesia and India are leading IPv6 adoption!

    I'm just lucky to live in a place that is covered by a big ISP, there is plenty (more than hundred) small ISP that not offering ipv6.

    fyi, indonesia have more than 1000+ licenced ISP and 8000++ island.

    I'm using as7713, still using ipv4 only. I know i can enable ipv6 via ONT and passthrought ipv6 to my router, but i had problem. If using passthrough method, ipv6 doesn't live more than 1-2 hour and then vanish. If i using route mode. My router software doesn't support it, maybe because the address not /64 (ONT then router). If using bridge mode (ONT -> router), ISP doesn't allow it, they thought bridge = bandwidth reselling, lol.

  • @somik said:

    True. If you need to buy hardware, might as well get the ones that support IPv6 since it'll be cheaper to run it in the long term.

    I seriously don't think you have a choice, I don't think you can find a router that does not support ipv6.
    People have to start grasping the fact that ipv6 has been a standard for 25 years, it is not something new.

  • somiksomik OG Hostbusters
    edited April 2024

    @rcy026 said:

    @somik said:

    True. If you need to buy hardware, might as well get the ones that support IPv6 since it'll be cheaper to run it in the long term.

    I seriously don't think you have a choice, I don't think you can find a router that does not support ipv6.
    People have to start grasping the fact that ipv6 has been a standard for 25 years, it is not something new.

    As per: https://www.internetsociety.org/deploy360/ipv6/faq/

    The core specification for the IPv6 protocol was first published in 1995 as RFC 1883, and has seen a number of enhancements and updates since then. It formally became a full standard (as opposed to a draft standard) in 2017 with the publication of RFC 8200, although IPv6 had already been deployed for many years.

    And here as well: https://en.wikipedia.org/wiki/IPv6

    In December 1998, IPv6 became a Draft Standard for the IETF,[2] which subsequently ratified it as an Internet Standard on 14 July 2017.

    So IPv6 was only a full "standard" for 7 years, not 25.

    Anyway, what I need now is a good firewall solution for my devices that are now exposed to the internet. I was previously using the router's firewall + NAT to block most ports from the internet and was only accessing them over home network. Now that everything is open to the internet I need to change all the passwords, block root access and remove "unsafe" servers I was running as test...

    I speak fluent sarcasm and broken logic. | I would agree with you, but thæn we’d both be wrong.

  • @somik said:

    @rcy026 said:

    @somik said:

    True. If you need to buy hardware, might as well get the ones that support IPv6 since it'll be cheaper to run it in the long term.

    I seriously don't think you have a choice, I don't think you can find a router that does not support ipv6.
    People have to start grasping the fact that ipv6 has been a standard for 25 years, it is not something new.

    As per: https://www.internetsociety.org/deploy360/ipv6/faq/

    The core specification for the IPv6 protocol was first published in 1995 as RFC 1883, and has seen a number of enhancements and updates since then. It formally became a full standard (as opposed to a draft standard) in 2017 with the publication of RFC 8200, although IPv6 had already been deployed for many years.

    And here as well: https://en.wikipedia.org/wiki/IPv6

    In December 1998, IPv6 became a Draft Standard for the IETF,[2] which subsequently ratified it as an Internet Standard on 14 July 2017.

    So IPv6 was only a full "standard" for 7 years, not 25.

    You would be surprised as to how many standards are actually still classified as drafts. IETF ratifying it as an internet standard is just the next step, it was considered a standard long before that.
    I've been personally running ipv6 for over 20 years so I know it works and have done so for a very long time.

    Anyway, what I need now is a good firewall solution for my devices that are now exposed to the internet. I was previously using the router's firewall + NAT to block most ports from the internet and was only accessing them over home network. Now that everything is open to the internet I need to change all the passwords, block root access and remove "unsafe" servers I was running as test...

    You should not have everything open on the internet just because you run ipv6, you should run a firewall with default to deny in front of your servers and then open only the ports you want to be open. Exactly as you do with NAT, but without the NAT part.

  • @rcy026 said:

    @somik said:

    @rcy026 said:

    @somik said:

    True. If you need to buy hardware, might as well get the ones that support IPv6 since it'll be cheaper to run it in the long term.

    I seriously don't think you have a choice, I don't think you can find a router that does not support ipv6.
    People have to start grasping the fact that ipv6 has been a standard for 25 years, it is not something new.

    As per: https://www.internetsociety.org/deploy360/ipv6/faq/

    The core specification for the IPv6 protocol was first published in 1995 as RFC 1883, and has seen a number of enhancements and updates since then. It formally became a full standard (as opposed to a draft standard) in 2017 with the publication of RFC 8200, although IPv6 had already been deployed for many years.

    And here as well: https://en.wikipedia.org/wiki/IPv6

    In December 1998, IPv6 became a Draft Standard for the IETF,[2] which subsequently ratified it as an Internet Standard on 14 July 2017.

    So IPv6 was only a full "standard" for 7 years, not 25.

    You would be surprised as to how many standards are actually still classified as drafts. IETF ratifying it as an internet standard is just the next step, it was considered a standard long before that.
    I've been personally running ipv6 for over 20 years so I know it works and have done so for a very long time.

    Anyway, what I need now is a good firewall solution for my devices that are now exposed to the internet. I was previously using the router's firewall + NAT to block most ports from the internet and was only accessing them over home network. Now that everything is open to the internet I need to change all the passwords, block root access and remove "unsafe" servers I was running as test...

    You should not have everything open on the internet just because you run ipv6, you should run a firewall with default to deny in front of your servers and then open only the ports you want to be open. Exactly as you do with NAT, but without the NAT part.

    Your router firewall can still block most traffic

    DM us for private tracker invite.

  • somiksomik OG Hostbusters

    @rcy026 said:

    @somik said:

    @rcy026 said:

    @somik said:

    True. If you need to buy hardware, might as well get the ones that support IPv6 since it'll be cheaper to run it in the long term.

    I seriously don't think you have a choice, I don't think you can find a router that does not support ipv6.
    People have to start grasping the fact that ipv6 has been a standard for 25 years, it is not something new.

    As per: https://www.internetsociety.org/deploy360/ipv6/faq/

    The core specification for the IPv6 protocol was first published in 1995 as RFC 1883, and has seen a number of enhancements and updates since then. It formally became a full standard (as opposed to a draft standard) in 2017 with the publication of RFC 8200, although IPv6 had already been deployed for many years.

    And here as well: https://en.wikipedia.org/wiki/IPv6

    In December 1998, IPv6 became a Draft Standard for the IETF,[2] which subsequently ratified it as an Internet Standard on 14 July 2017.

    So IPv6 was only a full "standard" for 7 years, not 25.

    You would be surprised as to how many standards are actually still classified as drafts. IETF ratifying it as an internet standard is just the next step, it was considered a standard long before that.
    I've been personally running ipv6 for over 20 years so I know it works and have done so for a very long time.

    Well, it was around 2013 that we started getting IPv6 support from our ISPs, which is way before the final standardization. As for servers, I guess IPv6 has been around for a while.

    @rcy026 said:
    You should not have everything open on the internet just because you run ipv6, you should run a firewall with default to deny in front of your servers and then open only the ports you want to be open. Exactly as you do with NAT, but without the NAT part.

    My issue are the test servers I use. The test servers have their firewall disabled (more like never installed/configured) and running insecure applications (non ssl, no logins or any concern for security when the app was created) that were meant to be run only on local network. Since I cannot block the ports, all I can do is disable IPv6 for those servers and work on locking the app behind a password...

    @terrorgen said:

    Your router firewall can still block most traffic

    Yep, you are right. The IPv6 servers are still not accessible from outside my router and I can now see the IPv6 firewall rules on my router's firewall page (bellow the IPv4 firewall rules)! That's good to know! Thank you!

    I speak fluent sarcasm and broken logic. | I would agree with you, but thæn we’d both be wrong.

  • @terrorgen said:

    @rcy026 said:

    @somik said:

    @rcy026 said:

    @somik said:

    True. If you need to buy hardware, might as well get the ones that support IPv6 since it'll be cheaper to run it in the long term.

    I seriously don't think you have a choice, I don't think you can find a router that does not support ipv6.
    People have to start grasping the fact that ipv6 has been a standard for 25 years, it is not something new.

    As per: https://www.internetsociety.org/deploy360/ipv6/faq/

    The core specification for the IPv6 protocol was first published in 1995 as RFC 1883, and has seen a number of enhancements and updates since then. It formally became a full standard (as opposed to a draft standard) in 2017 with the publication of RFC 8200, although IPv6 had already been deployed for many years.

    And here as well: https://en.wikipedia.org/wiki/IPv6

    In December 1998, IPv6 became a Draft Standard for the IETF,[2] which subsequently ratified it as an Internet Standard on 14 July 2017.

    So IPv6 was only a full "standard" for 7 years, not 25.

    You would be surprised as to how many standards are actually still classified as drafts. IETF ratifying it as an internet standard is just the next step, it was considered a standard long before that.
    I've been personally running ipv6 for over 20 years so I know it works and have done so for a very long time.

    Anyway, what I need now is a good firewall solution for my devices that are now exposed to the internet. I was previously using the router's firewall + NAT to block most ports from the internet and was only accessing them over home network. Now that everything is open to the internet I need to change all the passwords, block root access and remove "unsafe" servers I was running as test...

    You should not have everything open on the internet just because you run ipv6, you should run a firewall with default to deny in front of your servers and then open only the ports you want to be open. Exactly as you do with NAT, but without the NAT part.

    Your router firewall can still block most traffic

    I'd be amazed if almost all domestic routers supplied by ISPs don't come pre-configured with their IPv6 firewall set to block by default. Mine certainly was, is that not the norm?

  • somiksomik OG Hostbusters

    @cochon said:

    @terrorgen said:

    @rcy026 said:
    You should not have everything open on the internet just because you run ipv6, you should run a firewall with default to deny in front of your servers and then open only the ports you want to be open. Exactly as you do with NAT, but without the NAT part.

    Your router firewall can still block most traffic

    I'd be amazed if almost all domestic routers supplied by ISPs don't come pre-configured with their IPv6 firewall set to block by default. Mine certainly was, is that not the norm?

    If you are using the ISP supplied router, you are leaving performance on the table. NEVER use their provided routers (unless you got no choice) or you got a very good ISP who do not flash the router with their own firmware... I prefer using my own Asus router but openWRT based routers are good enough as well.

    I speak fluent sarcasm and broken logic. | I would agree with you, but thæn we’d both be wrong.

  • @somik said:
    ... NEVER use their provided routers (unless you got no choice) ...

    Probably a case of suck it and see for most. I actually abandoned the router for a direct connection to a server, but for increased functionality and control not performance.

    I kicked the tyres on the ISP's router when I [finally] got FTTP and it seemed to perform fine, vanilla firmware as far as I could tell, YMMV.

  • somiksomik OG Hostbusters
    edited April 2024

    @cochon said:

    @somik said:
    ... NEVER use their provided routers (unless you got no choice) ...

    Probably a case of suck it and see for most. I actually abandoned the router for a direct connection to a server, but for increased functionality and control not performance.

    I kicked the tyres on the ISP's router when I [finally] got FTTP and it seemed to perform fine, vanilla firmware as far as I could tell, YMMV.

    As long as you can see the "firmware upgrade" option and are able to upgrade it using the firmware available on manufacturer's website, it's ok. The issue is that most "free" routers that the ISP provides are just too cheap to support people who visit these types of forums. Some do not support port forwarding and those which seems ok are too low powered to support 1gbps connection to multiple devices while providing WiFi for the house. It just heats up and crashes, leaving people in the house blaming your server for the internet going down (ask me how i know...).

    As for IPv6, luckily the ISP provided router does support it but there were no instructions on how to get a IPv6 address and the ISP's technician who come and setup the ONT and router leaves IPv6 disabled...

    I speak fluent sarcasm and broken logic. | I would agree with you, but thæn we’d both be wrong.

  • @somik said:

    As long as you can see the "firmware upgrade" option and are able to upgrade it using the firmware available on manufacturer's website, it's ok. The issue is that most "free" routers that the ISP provides are just too cheap to support people who visit these types of forums. Some do not support port forwarding and those which seems ok are too low powered to support 1gbps connection to multiple devices while providing WiFi for the house. It just heats up and crashes, leaving people in the house blaming your server for the internet going down (ask me how i know...).

    As for IPv6, luckily the ISP provided router does support it but there were no instructions on how to get a IPv6 address and the ISP's technician who come and setup the ONT and router leaves IPv6 disabled...

    That's strange, around here most of the ISP's provide pretty good routers that work very well out of the box. No ISP want people calling support since that is expensive so providing a router that works is kind of basic common sense.

  • somiksomik OG Hostbusters

    @rcy026 said:

    @somik said:

    As long as you can see the "firmware upgrade" option and are able to upgrade it using the firmware available on manufacturer's website, it's ok. The issue is that most "free" routers that the ISP provides are just too cheap to support people who visit these types of forums. Some do not support port forwarding and those which seems ok are too low powered to support 1gbps connection to multiple devices while providing WiFi for the house. It just heats up and crashes, leaving people in the house blaming your server for the internet going down (ask me how i know...).

    As for IPv6, luckily the ISP provided router does support it but there were no instructions on how to get a IPv6 address and the ISP's technician who come and setup the ONT and router leaves IPv6 disabled...

    That's strange, around here most of the ISP's provide pretty good routers that work very well out of the box. No ISP want people calling support since that is expensive so providing a router that works is kind of basic common sense.

    Here, they used to provide Aztech routers. Then they "upgrade" to Huawei after 2 years (during re-contract period).

    When I switched internet provider to go with M1 they provided a Asus router (mid range one). Next recontract (2 years down the line) they actually provided with one of the best Asus routers, RT-AX88U which I happily accepted, even though I had to upgrade to the 2x 1Gbps network. Funnily, I only got 1 router for the 2x 1Gbps connection where they clearly stated that I need 2 rotuers to enjoy the dual network. I use one for my servers (since it has fixed IP) and the other one for my home internet.

    Last year, during recontract, they provided the upper mid-range RT-AX56U since they provided us with 2x of these routers along with 1 "free" chinese branded android TV... Well, it's not bad but nothing comapred to the AX88U that they gave the previous time... Was hoping to get one more of those...

    I speak fluent sarcasm and broken logic. | I would agree with you, but thæn we’d both be wrong.

Sign In or Register to comment.