[HN Gopher] Your First IPv6 Request
___________________________________________________________________
Your First IPv6 Request
Author : tosh
Score : 54 points
Date : 2022-10-31 10:27 UTC (12 hours ago)
(HTM) web link (www.arin.net)
(TXT) w3m dump (www.arin.net)
| roody15 wrote:
| I work at medium size school district with 7 building locations
| and just over 300 employees. I was denied an IPv6 block as I was
| deemed too small. Continued to be annoyed at the IPv6 rollout. I
| have 26 static IPv4 addresses that have worked great and continue
| to do so.
| jabart wrote:
| I think all of ARIN requests require that you be multi-homed to
| more than one upstream internet provider. If you are not, then
| you can ask your ISP for a IPv6 block. Assumption here since
| you don't have a /24 range. This was part of one of our
| requests when asking for IPv4 addresses was which networks we
| would peer with and we had to list more than 1.
| ikiris wrote:
| Then you did it wrong, because that's not how that works.
|
| You can get ip space with trivial need and multihoming.
| IgorPartola wrote:
| My understanding is that as a single user I cannot get an
| allocation for a home lab or a small set of VPSs. The (very
| reasonable) requirements are that you need to be multi homes, or
| need lots of networks for e.g. employees or have 13+ different
| offices for the smallest allocation. This is very good info but
| isn't for a hobbyist.
| zauguin wrote:
| I don't know about ARIN, but I got an PI assignment from RIPE
| for my home lab without issues.
| sleepydog wrote:
| Who do you peer with? How do you make your prefix publicly
| routable? Or do you only use it privately?
| zauguin wrote:
| I currently peer (via tunnels through my IPv4 connection)
| with securebit (aka tunnelbroker.ch), freetransit.ch and
| route48.org (but the list varies a bit over time), The
| original motivation was my frustration about my ISP not
| offering native IPv6 and general interest in internet
| routing.
| sigio wrote:
| Any LIR can get a /29 (or /32), and probably anyone that can
| find a sponsoring LIR can get a /48 no questions asked.
| IgorPartola wrote:
| What is a LIR?
| hampereddustbin wrote:
| Wikipedia says it is
|
| >A local Internet registry (LIR) is an organization that
| has been allocated a block of IP addresses by a RIR, and
| that assigns most parts of this block to its own
| customers
|
| RIR being Regional Internet Registry
|
| https://en.wikipedia.org/wiki/Regional_Internet_registry
| ipython wrote:
| You can get small free ipv6 allocations from hurricane
| electric's tunnel broker (tunnelbroker.net) Of course those
| aren't "portable" assignments but it's great for experimenting
| and such.
| IgorPartola wrote:
| That's not really an allocation. I use it currently but it's
| by no means ideal.
| yakcyll wrote:
| One thing that struck me was the sizes of blocks assigned. I get
| a dynamic /64 prefix from my ISP at home, which would be large
| even if it were assigned to my work office; why is the maximum
| prefix length /48 for a single site and /32 for 3k sites? Aside
| from the obvious argument of wastefulness, aren't we just priming
| the same issue we have with IPv4 now to occur thirty, forty years
| down the line?
| hampereddustbin wrote:
| Doesen't /64 mean that you can't create additional subnets
| within your ISP given range? I thought /56 was the smallest
| allocation an ISP could make for a residential allocation.
|
| I think it's great that the smallest subnet size is designed to
| be as large as to never run out of addresses in any conceivable
| application, no more wasting precious time manually assigning
| addresses and thinking about subnet economics
| tsimionescu wrote:
| In previous threads, there were even people saying their ISPs
| provide them a single IPv6 address, so essentially a /128.
| staringback wrote:
| They may be misunderstanding how their ISP provides IPv6
| address space. For example my Comcast connection assigns a
| single /128 to the router, then a bunch of /64s to each
| subnet I have set up.
| jeroenhd wrote:
| /56 is the smallest they're supposed to allocate for
| customers, but I've read stories about ISPs providing people
| with /128s on their CPEs...
|
| A /64 can actually cause problems if you're chaining routers
| together. In IPv4 that'd give you double NAT which is
| obviously terrible and not recommended, but in IPv6 that's a
| fine use case that shouldn't cause any trouble as long as you
| have the ability to create sufficient subnets. With a /64,
| you're stuck doing weird stuff with DHCPv6 to get the subnets
| to work regardless.
| aidenn0 wrote:
| You don't need double-NAT with ipv4 to chain routers
| together, just route between different private-allocation
| subnets. I was running a setup like that to get ethernet
| access to a part of the house via wifi. Changed it for ipv6
| though because my isp only gives me a /64
| aaronax wrote:
| > Doesen't /64 mean that you can't create additional subnets
| within your ISP given range?
|
| Effectively yes.
|
| > I thought /56 was the smallest allocation an ISP could make
| for a residential allocation.
|
| They can and often do make /64 allocations. There is an RFC
| (I think, might just be RIPE guidance or something) that
| recommends that ISPs issue larger to each customer. Many
| don't (as it is just a recommendation). Ideally they would
| allow a customer's router to request a larger allocation like
| /60 or /56 via a prefix delegation message.
| jeroenhd wrote:
| ISPs handing out /64 are quite stingy, /56 is the recommended
| range to hand out to clients. It used to be /48 but people got
| worried about address range exhaustion so they changed it.
|
| The reason for these larger blocks isn't that you need several
| hundred billion IP addresses per se, but that IPv6 can't create
| subnets (without terrible tooling issues) smaller than /64. In
| a way, getting a /64 from your ISP is like being forced to use
| a router that's stuck in the 192.168.0.x space for DHCP. A /56
| will give you 255 subnets, a /48 will give you 65k in total.
| More than enough I'd say.
|
| A /32 will give you as many subnets are there are IPv4
| addresses out there today, I don't see why you'd need that.
| It's nice of them to offer it (for a significant price, of
| course) but I don't think businesses really need address space
| that huge.
|
| IPv6 has a ridiculous amount of address space, we may as well
| use it.
| GoblinSlayer wrote:
| I believe all ip4 lans I saw survived with just one subnet.
| What's the need for more?
| [deleted]
| lokedhs wrote:
| My ISP gives me a static /48. I'm currently using 5 subnets,
| so I could probably have survived with a /56. I'm glad I have
| a full /48 though.
|
| I switched from my previous ISP because they only have me a
| /64. It was quite honestly useless for me, since I couldn't
| even split it into two subnets. They did it because they
| clearly had old network equipment and were using 6rd to
| provide IPv6.
| philjohn wrote:
| I'm with Zen in the UK and they give out /48's which is nice,
| and makes subnet management much easier.
| HyperSane wrote:
| The last 64 bits of an IPv6 address are the host bits. I think
| it is stupid also, it should have been 16 or at most 24 bits
| for the hosts.
| aaronax wrote:
| /64 is not large--it is only enough to run one network /
| broadcast domain. It is fine for 90%+ of homes, unless they
| want to do anything like run a separate guest or IOT network.
| Hopefully they would be able to obtain larger prefix
| delegations by simply requesting one with their router.
|
| A /48 for a site allows a decent number of subdivisions along
| the easily human-readable nibble (16 bit) boundaries. Four
| characters each can be 0 through f.
|
| A very small portion of addresses have been allocated so far.
| "According to the IPv6 Global Unicast Address Assignments list
| from IANA (last updated in Nov 2019), there have been 33
| allocations made to the five Regional Internet Registries in
| total so far. This is equivalent to about 7,396,864 IPv6 /32
| subnets which is approximately 0.172% of the total available
| IPv6 space." https://www.cidr.eu/en/ipv6
| throw0101a wrote:
| > _A /48 for a site allows a decent number of subdivisions
| along the easily human-readable nibble (16 bit) boundaries.
| Four characters each can be 0 through f._
|
| To put it in IPv4 terms:
|
| * an IPv6 /64 subnet is equivalent to 'typical' IPv4 /24
| (though you can fit _much_ more than ~250 hosts in it)
|
| * if assigned a /48, this gives you 16 bits to play with
|
| * if you start with a typical IPv4 /24, and would be assigned
| 16 bits to use, that would bring you up to a /8
|
| So the 'bog standard' IPv6 /48 is the equivalent of an entire
| IPv4 Class A address.
|
| Some folks who have Class As assigned to them: AT&T, Apple,
| Cogent, Comcast, multiple assignments to US military.
|
| * https://en.wikipedia.org/wiki/List_of_assigned_/8_IPv4_addr
| e...
|
| And none of those IPv6 addresses have to be NATed to be
| accessible to the Internet if you wish to provide public
| services: just change the config of your firewall from
| default-deny to allowing whatever portions of the network you
| wish to host service in.
| VLM wrote:
| /56 aren't as generous as you'd think as companies "often" use
| VLANs and people selling network gear have always pushed for
| microsegmentation (rather than having a VLAN for the entire 3rd
| floor which would technically fit, have a distributed VLAN just
| for the three accounting people and their eight servers).
|
| In theory you could have 10 bits just of VLANs without doing
| microsegmentation and strange virtualization games which
| everyone is encouraged to do, so smaller than a /54 for a
| corporate ISP account seems very questionable; may as well
| round each site to /48.
|
| There is a high human labor cost to customization even with
| computer assistance for IPAM. Life is faster, simpler, and more
| reliable if "every generic ISP connection gets a /48"
|
| At some point, for "IoT" and "security" reasons the concept of
| one broadcast domain per residential home will go away,
| hopefully soon. I don't want my soon to be exploited smart TV
| to have any access to my "real" VLAN, for example. My "home"
| and "home-guest" wifi networks should be on separate VLANs on
| separate /64 address blocks.
| throw0101a wrote:
| > _I get a dynamic /64 prefix from my ISP at home, which would
| be large even if it were assigned to my work office; why is the
| maximum prefix length /48 for a single site and /32 for 3k
| sites?_
|
| The default subnet size for IPv6 is /64, and a single "site" is
| /48. There are 16 bits between those.
|
| Comparing with IPv4, where a 'typical' subnet is /24, if you
| were given 16 of space to play with as you see fit, you'd be
| assigned a /8--i.e., an entire Class A. (Which is what most
| companies use now anyhow--i.e. 10/8--and then have to futz
| around with NAT.)
|
| So a 'typical' IPv6 allocation is as many IP addresses as what
| some of the largest corporations have. Plus all of those
| addresses are available for use on the public Internet is you
| wish: just change your firewall from default-deny to allow
| certain segments.
|
| > _Aside from the obvious argument of wastefulness, aren 't we
| just priming the same issue we have with IPv4 now to occur
| thirty, forty years down the line?_
|
| No. The numbers involved with IPv6 are literally astronomical:
|
| * Stars in the Milky Way: 400 Billion
|
| * Galaxies in the universe: 2 Trillion
|
| So _(4x10^11 )x(2x10^12 )=8x10^23_ stars in the universe.
|
| * Size of IPv6 address space: 3.4x10^38
|
| Find the ratio between addresses and stars:
|
| * 3.4x10^38 / 8x10^23
|
| IPv6 offers about 430 trillion times more addresses than
| estimated stars in the universe. From Tom Coffee's presentation
| "An Enterprise IPv6 Address Planning Case-Study"
|
| * https://www.youtube.com/watch?v=7Tnh4upTOC4
|
| Another way of looking at it:
|
| * math property: x^y = x^(a+b) = (x^a )x(x^b )
|
| * IPv4 addresses are 32 bits (2^32 )
|
| * 2^32 ~ 4.3 billion
|
| * So the IPv4 Internet has ~4.3B devices on it
|
| * IPv6 subnets are 64 bits, /64 (2^64 )
|
| So, a IPv6 2^64 subnet is the same as (2^32 )x(2^32 ), which
| means (4.3B)x(IPv4 Internet). I.e., a _single_ IPv6 subnet can
| hold the equivalent of _four billion_ (IPv4) Internets.
|
| A third way:
|
| * On the surface of the Earth (land+water), there are 8.4 IPv4
| addresses per km^2. Not counting the oceans, that would be 28
| IPv4 addresses per km^2 land.
|
| * IPv6 gives 10^17 addresses per mm^2 (yes, square millimeter).
|
| In terms of volume, 10^8 IPv6 addresses per mm^3 throughout the
| Earth.
|
| * Via:
| https://news.ycombinator.com/item?id=28326806#unv_28331245
| ikiris wrote:
| No, because math.
| tialaramex wrote:
| > aren't we just priming the same issue we have with IPv4 now
| to occur thirty, forty years down the line?
|
| Why? Do the arithmetic.
| ninkendo wrote:
| 2^128 is an enormous number. 128 is not.
|
| If you start assigning semantic meaning to the bits in an
| address (the trailing 64 are the devices, the leading 0-31
| are the ISP customer, 32-63 are the subnet) then things
| really do start to exhaust if you have a use case where the
| lines blur (a multitenant datacenter for instance, where it's
| not clear who the "ISP customer" is and different tenants
| want their own subnet ranges, etc.)
|
| There's a lot of IP's, but it's easy to paint yourself into a
| corner if you make the wrong assumptions about what bits
| should mean what.
| iso1631 wrote:
| Certainly giving a /32 to anyone who wants one is a problem
|
| Giving a /56 or a /48 isn't.
|
| There are 281 trillion /48s
|
| If you gave everyone who has ever lived and gave everyone a
| /48, you'd have 281 trillion left
| ninkendo wrote:
| > If you gave everyone who has ever lived and gave
| everyone a /48, you'd have 281 trillion left
|
| What if I got a /48 and my customer wants a bunch of
| /48's? Better ask my upstream for a /40 so that I can
| give it to them. What if my provider already has a bunch
| of people that want /40's? They'll probably want a /32.
| What if their provider has a lot of customers that want
| /32's? (and so on.)
|
| I'm not saying any of the above make any sense (you don't
| typically have that many layers of "providers"), but I've
| seen it happen in really huge corporations that have this
| kind of logic:
|
| "It'd be nice to know where a packet comes from using
| only its address, let's give a /64 to each server, a /56
| to each rack, a /48 to each aisle, a /40 to each server
| room", etc... but suddenly your needs change and your
| servers themselves need to have multiple /64's, or you
| start needing to add regions to the list of stuff packed
| into an address. Suddenly you're asking for a /32 in
| order to keep your inventory management simple, even
| though you're barely using any of the addresses.
|
| I'm not saying the above is a good idea, just that if you
| do dumb stuff with your address space, you can end up
| running out of addresses even though you have many many
| orders of magnitude more addresses than you actually use.
| bauruine wrote:
| As a LIR you get a /32 by default, no questions asked. If
| you need more you need justification and from my
| experience with RIPE and PI space they can be a pain in
| the ass regarding that. AFAIK the biggest one they ever
| give a LIR is a /28 with the note that they never ever
| want to hear from you again. There are 268'435'456 /28
| available. I don't think i will still life when we reach
| the only 200 Million /28 left mark.
| Arnavion wrote:
| Also all the current allocation standards are for
| 2000::/3. If it turns out we have some unforeseen issue
| with the current policy of handing out blocks we can come
| up with something else for the five other /3's that are
| completely unused.
| ninkendo wrote:
| Giving a /32 to anyone who wants one without any
| questions asked is probably a good example of why "aren't
| we making the same mistake as ipv4?" isn't an entirely
| meritless question.
|
| I mean it's probably crazy to imagine a scenario where we
| have more than 4 billion "local internet registries" in
| the universe, but it's not so crazy to imagine a scenario
| where the ability to ask for a /32 maybe needs to get
| constrained a little more.
|
| In the end, I think the idea of making all subnets /64's
| may have been a mistake. It's cool that you can put MAC
| addresses right in the address and thus don't need DHCP
| any more, but carving out room for
| 18,446,744,073,709,551,616 devices per broadcast domain
| is a bit crazy on the face of it. Plus you need all the
| privacy addresses to hide your MAC address from trackers
| anyway, which is way more complexity than we really
| needed. IMO DHCP isn't so bad, it's boring/predictable
| technology at this point, and I'd be perfectly
| comfortable with shifting the "provider vs customer"
| boundary many bits to the right in an address, so that a
| typical subnet is more like a /104 and ISP's give out
| /96's, etc. That would give us a lot more headroom than
| the system we have now where anyone can grab a /32.
| iso1631 wrote:
| > In the end, I think the idea of making all subnets
| /64's may have been a mistake.
|
| True, but just imagine the subnets are only 64k hosts,
| with ipv6's address space as a /80.
|
| My own ipv4 routed network (which is currently routed
| across 5 continents) is based on a space in the 172.16/12
| range comprising 5 /16s. A lot of the subnets I use are
| chopped down to /27, /28 and /29 (and of course /30 and
| /31s for links and /32s for loopbacks).
|
| That said it's a bit of a squeeze at the moment.
|
| To implement that in an ipv6 world, I'd make every subnet
| currently sizing between /29 and /25 into a /64. At most
| it's 8 subnets per /24 at the moment, so call it 16.
|
| As such every /24 I currently allocate would be a /60.
|
| and I have 1280 of those /24s, so 11 bits, which means I
| need a /49.
|
| Add some expansion space (which I'm currently looking at)
| and that seems quite neat as a /48.
|
| That's a fairly big network. At some point in the future
| I could see justifying a second /48.
|
| My company as a whole certainly has more requirement than
| that, but we have a /32 allocated (we also have a /16 and
| /19 in ipv4 land and 2 ASes). That /32 could allocate
| 65,000 of my continent spanning networks. I think we have
| about 8, and only a couple are really large. The main one
| is based on the 10/8 network range, which would probably
| fit into a single /48, but certainly in a handful of
| them.
|
| > where anyone can grab a /32.
|
| If the requirement to grab a single /32 is an ability to
| fill in a form asking for it, we aren't going to be
| running into any issues any time in the next 100 years.
| bauruine wrote:
| Everyone that is willing to pay an initial 2400.- and
| yearly 1400.- to RIPE.
|
| Yes we may have to constrain this a little more sometimes
| but we have plenty of IP space and therefore time before
| we have to consider this.
| sigio wrote:
| Just see it as a 64-bit address-space, as one /64 will be for 1
| home/location/lan.
|
| Then we still have 32^32 times the amount of address-space we
| have in v4.
| greyface- wrote:
| Beware: https://www.arin.net/resources/fees/fee_schedule/#rsp-
| servic...
| zerotolerance wrote:
| Neat note at the bottom, "* There is a temporary IPv6 fee
| waiver for organizations in the 3X-Small service category. A
| 3X-Small organization may receive registry services for up to a
| /36 of total IPv6 space and remain in the 3X-Small service
| category. This waiver will expire 31 December 2026."
___________________________________________________________________
(page generated 2022-10-31 23:02 UTC)