[HN Gopher] Your First IPv6 Request
       ___________________________________________________________________
        
       Your First IPv6 Request
        
       Author : tosh
       Score  : 54 points
       Date   : 2022-10-31 10:27 UTC (12 hours ago)
        
 (HTM) web link (www.arin.net)
 (TXT) w3m dump (www.arin.net)
        
       | roody15 wrote:
       | I work at medium size school district with 7 building locations
       | and just over 300 employees. I was denied an IPv6 block as I was
       | deemed too small. Continued to be annoyed at the IPv6 rollout. I
       | have 26 static IPv4 addresses that have worked great and continue
       | to do so.
        
         | jabart wrote:
         | I think all of ARIN requests require that you be multi-homed to
         | more than one upstream internet provider. If you are not, then
         | you can ask your ISP for a IPv6 block. Assumption here since
         | you don't have a /24 range. This was part of one of our
         | requests when asking for IPv4 addresses was which networks we
         | would peer with and we had to list more than 1.
        
         | ikiris wrote:
         | Then you did it wrong, because that's not how that works.
         | 
         | You can get ip space with trivial need and multihoming.
        
       | IgorPartola wrote:
       | My understanding is that as a single user I cannot get an
       | allocation for a home lab or a small set of VPSs. The (very
       | reasonable) requirements are that you need to be multi homes, or
       | need lots of networks for e.g. employees or have 13+ different
       | offices for the smallest allocation. This is very good info but
       | isn't for a hobbyist.
        
         | zauguin wrote:
         | I don't know about ARIN, but I got an PI assignment from RIPE
         | for my home lab without issues.
        
           | sleepydog wrote:
           | Who do you peer with? How do you make your prefix publicly
           | routable? Or do you only use it privately?
        
             | zauguin wrote:
             | I currently peer (via tunnels through my IPv4 connection)
             | with securebit (aka tunnelbroker.ch), freetransit.ch and
             | route48.org (but the list varies a bit over time), The
             | original motivation was my frustration about my ISP not
             | offering native IPv6 and general interest in internet
             | routing.
        
           | sigio wrote:
           | Any LIR can get a /29 (or /32), and probably anyone that can
           | find a sponsoring LIR can get a /48 no questions asked.
        
             | IgorPartola wrote:
             | What is a LIR?
        
               | hampereddustbin wrote:
               | Wikipedia says it is
               | 
               | >A local Internet registry (LIR) is an organization that
               | has been allocated a block of IP addresses by a RIR, and
               | that assigns most parts of this block to its own
               | customers
               | 
               | RIR being Regional Internet Registry
               | 
               | https://en.wikipedia.org/wiki/Regional_Internet_registry
        
         | ipython wrote:
         | You can get small free ipv6 allocations from hurricane
         | electric's tunnel broker (tunnelbroker.net) Of course those
         | aren't "portable" assignments but it's great for experimenting
         | and such.
        
           | IgorPartola wrote:
           | That's not really an allocation. I use it currently but it's
           | by no means ideal.
        
       | yakcyll wrote:
       | One thing that struck me was the sizes of blocks assigned. I get
       | a dynamic /64 prefix from my ISP at home, which would be large
       | even if it were assigned to my work office; why is the maximum
       | prefix length /48 for a single site and /32 for 3k sites? Aside
       | from the obvious argument of wastefulness, aren't we just priming
       | the same issue we have with IPv4 now to occur thirty, forty years
       | down the line?
        
         | hampereddustbin wrote:
         | Doesen't /64 mean that you can't create additional subnets
         | within your ISP given range? I thought /56 was the smallest
         | allocation an ISP could make for a residential allocation.
         | 
         | I think it's great that the smallest subnet size is designed to
         | be as large as to never run out of addresses in any conceivable
         | application, no more wasting precious time manually assigning
         | addresses and thinking about subnet economics
        
           | tsimionescu wrote:
           | In previous threads, there were even people saying their ISPs
           | provide them a single IPv6 address, so essentially a /128.
        
             | staringback wrote:
             | They may be misunderstanding how their ISP provides IPv6
             | address space. For example my Comcast connection assigns a
             | single /128 to the router, then a bunch of /64s to each
             | subnet I have set up.
        
           | jeroenhd wrote:
           | /56 is the smallest they're supposed to allocate for
           | customers, but I've read stories about ISPs providing people
           | with /128s on their CPEs...
           | 
           | A /64 can actually cause problems if you're chaining routers
           | together. In IPv4 that'd give you double NAT which is
           | obviously terrible and not recommended, but in IPv6 that's a
           | fine use case that shouldn't cause any trouble as long as you
           | have the ability to create sufficient subnets. With a /64,
           | you're stuck doing weird stuff with DHCPv6 to get the subnets
           | to work regardless.
        
             | aidenn0 wrote:
             | You don't need double-NAT with ipv4 to chain routers
             | together, just route between different private-allocation
             | subnets. I was running a setup like that to get ethernet
             | access to a part of the house via wifi. Changed it for ipv6
             | though because my isp only gives me a /64
        
           | aaronax wrote:
           | > Doesen't /64 mean that you can't create additional subnets
           | within your ISP given range?
           | 
           | Effectively yes.
           | 
           | > I thought /56 was the smallest allocation an ISP could make
           | for a residential allocation.
           | 
           | They can and often do make /64 allocations. There is an RFC
           | (I think, might just be RIPE guidance or something) that
           | recommends that ISPs issue larger to each customer. Many
           | don't (as it is just a recommendation). Ideally they would
           | allow a customer's router to request a larger allocation like
           | /60 or /56 via a prefix delegation message.
        
         | jeroenhd wrote:
         | ISPs handing out /64 are quite stingy, /56 is the recommended
         | range to hand out to clients. It used to be /48 but people got
         | worried about address range exhaustion so they changed it.
         | 
         | The reason for these larger blocks isn't that you need several
         | hundred billion IP addresses per se, but that IPv6 can't create
         | subnets (without terrible tooling issues) smaller than /64. In
         | a way, getting a /64 from your ISP is like being forced to use
         | a router that's stuck in the 192.168.0.x space for DHCP. A /56
         | will give you 255 subnets, a /48 will give you 65k in total.
         | More than enough I'd say.
         | 
         | A /32 will give you as many subnets are there are IPv4
         | addresses out there today, I don't see why you'd need that.
         | It's nice of them to offer it (for a significant price, of
         | course) but I don't think businesses really need address space
         | that huge.
         | 
         | IPv6 has a ridiculous amount of address space, we may as well
         | use it.
        
           | GoblinSlayer wrote:
           | I believe all ip4 lans I saw survived with just one subnet.
           | What's the need for more?
        
             | [deleted]
        
           | lokedhs wrote:
           | My ISP gives me a static /48. I'm currently using 5 subnets,
           | so I could probably have survived with a /56. I'm glad I have
           | a full /48 though.
           | 
           | I switched from my previous ISP because they only have me a
           | /64. It was quite honestly useless for me, since I couldn't
           | even split it into two subnets. They did it because they
           | clearly had old network equipment and were using 6rd to
           | provide IPv6.
        
           | philjohn wrote:
           | I'm with Zen in the UK and they give out /48's which is nice,
           | and makes subnet management much easier.
        
         | HyperSane wrote:
         | The last 64 bits of an IPv6 address are the host bits. I think
         | it is stupid also, it should have been 16 or at most 24 bits
         | for the hosts.
        
         | aaronax wrote:
         | /64 is not large--it is only enough to run one network /
         | broadcast domain. It is fine for 90%+ of homes, unless they
         | want to do anything like run a separate guest or IOT network.
         | Hopefully they would be able to obtain larger prefix
         | delegations by simply requesting one with their router.
         | 
         | A /48 for a site allows a decent number of subdivisions along
         | the easily human-readable nibble (16 bit) boundaries. Four
         | characters each can be 0 through f.
         | 
         | A very small portion of addresses have been allocated so far.
         | "According to the IPv6 Global Unicast Address Assignments list
         | from IANA (last updated in Nov 2019), there have been 33
         | allocations made to the five Regional Internet Registries in
         | total so far. This is equivalent to about 7,396,864 IPv6 /32
         | subnets which is approximately 0.172% of the total available
         | IPv6 space." https://www.cidr.eu/en/ipv6
        
           | throw0101a wrote:
           | > _A /48 for a site allows a decent number of subdivisions
           | along the easily human-readable nibble (16 bit) boundaries.
           | Four characters each can be 0 through f._
           | 
           | To put it in IPv4 terms:
           | 
           | * an IPv6 /64 subnet is equivalent to 'typical' IPv4 /24
           | (though you can fit _much_ more than ~250 hosts in it)
           | 
           | * if assigned a /48, this gives you 16 bits to play with
           | 
           | * if you start with a typical IPv4 /24, and would be assigned
           | 16 bits to use, that would bring you up to a /8
           | 
           | So the 'bog standard' IPv6 /48 is the equivalent of an entire
           | IPv4 Class A address.
           | 
           | Some folks who have Class As assigned to them: AT&T, Apple,
           | Cogent, Comcast, multiple assignments to US military.
           | 
           | * https://en.wikipedia.org/wiki/List_of_assigned_/8_IPv4_addr
           | e...
           | 
           | And none of those IPv6 addresses have to be NATed to be
           | accessible to the Internet if you wish to provide public
           | services: just change the config of your firewall from
           | default-deny to allowing whatever portions of the network you
           | wish to host service in.
        
         | VLM wrote:
         | /56 aren't as generous as you'd think as companies "often" use
         | VLANs and people selling network gear have always pushed for
         | microsegmentation (rather than having a VLAN for the entire 3rd
         | floor which would technically fit, have a distributed VLAN just
         | for the three accounting people and their eight servers).
         | 
         | In theory you could have 10 bits just of VLANs without doing
         | microsegmentation and strange virtualization games which
         | everyone is encouraged to do, so smaller than a /54 for a
         | corporate ISP account seems very questionable; may as well
         | round each site to /48.
         | 
         | There is a high human labor cost to customization even with
         | computer assistance for IPAM. Life is faster, simpler, and more
         | reliable if "every generic ISP connection gets a /48"
         | 
         | At some point, for "IoT" and "security" reasons the concept of
         | one broadcast domain per residential home will go away,
         | hopefully soon. I don't want my soon to be exploited smart TV
         | to have any access to my "real" VLAN, for example. My "home"
         | and "home-guest" wifi networks should be on separate VLANs on
         | separate /64 address blocks.
        
         | throw0101a wrote:
         | > _I get a dynamic /64 prefix from my ISP at home, which would
         | be large even if it were assigned to my work office; why is the
         | maximum prefix length /48 for a single site and /32 for 3k
         | sites?_
         | 
         | The default subnet size for IPv6 is /64, and a single "site" is
         | /48. There are 16 bits between those.
         | 
         | Comparing with IPv4, where a 'typical' subnet is /24, if you
         | were given 16 of space to play with as you see fit, you'd be
         | assigned a /8--i.e., an entire Class A. (Which is what most
         | companies use now anyhow--i.e. 10/8--and then have to futz
         | around with NAT.)
         | 
         | So a 'typical' IPv6 allocation is as many IP addresses as what
         | some of the largest corporations have. Plus all of those
         | addresses are available for use on the public Internet is you
         | wish: just change your firewall from default-deny to allow
         | certain segments.
         | 
         | > _Aside from the obvious argument of wastefulness, aren 't we
         | just priming the same issue we have with IPv4 now to occur
         | thirty, forty years down the line?_
         | 
         | No. The numbers involved with IPv6 are literally astronomical:
         | 
         | * Stars in the Milky Way: 400 Billion
         | 
         | * Galaxies in the universe: 2 Trillion
         | 
         | So _(4x10^11 )x(2x10^12 )=8x10^23_ stars in the universe.
         | 
         | * Size of IPv6 address space: 3.4x10^38
         | 
         | Find the ratio between addresses and stars:
         | 
         | * 3.4x10^38 / 8x10^23
         | 
         | IPv6 offers about 430 trillion times more addresses than
         | estimated stars in the universe. From Tom Coffee's presentation
         | "An Enterprise IPv6 Address Planning Case-Study"
         | 
         | * https://www.youtube.com/watch?v=7Tnh4upTOC4
         | 
         | Another way of looking at it:
         | 
         | * math property: x^y = x^(a+b) = (x^a )x(x^b )
         | 
         | * IPv4 addresses are 32 bits (2^32 )
         | 
         | * 2^32 ~ 4.3 billion
         | 
         | * So the IPv4 Internet has ~4.3B devices on it
         | 
         | * IPv6 subnets are 64 bits, /64 (2^64 )
         | 
         | So, a IPv6 2^64 subnet is the same as (2^32 )x(2^32 ), which
         | means (4.3B)x(IPv4 Internet). I.e., a _single_ IPv6 subnet can
         | hold the equivalent of _four billion_ (IPv4) Internets.
         | 
         | A third way:
         | 
         | * On the surface of the Earth (land+water), there are 8.4 IPv4
         | addresses per km^2. Not counting the oceans, that would be 28
         | IPv4 addresses per km^2 land.
         | 
         | * IPv6 gives 10^17 addresses per mm^2 (yes, square millimeter).
         | 
         | In terms of volume, 10^8 IPv6 addresses per mm^3 throughout the
         | Earth.
         | 
         | * Via:
         | https://news.ycombinator.com/item?id=28326806#unv_28331245
        
         | ikiris wrote:
         | No, because math.
        
         | tialaramex wrote:
         | > aren't we just priming the same issue we have with IPv4 now
         | to occur thirty, forty years down the line?
         | 
         | Why? Do the arithmetic.
        
           | ninkendo wrote:
           | 2^128 is an enormous number. 128 is not.
           | 
           | If you start assigning semantic meaning to the bits in an
           | address (the trailing 64 are the devices, the leading 0-31
           | are the ISP customer, 32-63 are the subnet) then things
           | really do start to exhaust if you have a use case where the
           | lines blur (a multitenant datacenter for instance, where it's
           | not clear who the "ISP customer" is and different tenants
           | want their own subnet ranges, etc.)
           | 
           | There's a lot of IP's, but it's easy to paint yourself into a
           | corner if you make the wrong assumptions about what bits
           | should mean what.
        
             | iso1631 wrote:
             | Certainly giving a /32 to anyone who wants one is a problem
             | 
             | Giving a /56 or a /48 isn't.
             | 
             | There are 281 trillion /48s
             | 
             | If you gave everyone who has ever lived and gave everyone a
             | /48, you'd have 281 trillion left
        
               | ninkendo wrote:
               | > If you gave everyone who has ever lived and gave
               | everyone a /48, you'd have 281 trillion left
               | 
               | What if I got a /48 and my customer wants a bunch of
               | /48's? Better ask my upstream for a /40 so that I can
               | give it to them. What if my provider already has a bunch
               | of people that want /40's? They'll probably want a /32.
               | What if their provider has a lot of customers that want
               | /32's? (and so on.)
               | 
               | I'm not saying any of the above make any sense (you don't
               | typically have that many layers of "providers"), but I've
               | seen it happen in really huge corporations that have this
               | kind of logic:
               | 
               | "It'd be nice to know where a packet comes from using
               | only its address, let's give a /64 to each server, a /56
               | to each rack, a /48 to each aisle, a /40 to each server
               | room", etc... but suddenly your needs change and your
               | servers themselves need to have multiple /64's, or you
               | start needing to add regions to the list of stuff packed
               | into an address. Suddenly you're asking for a /32 in
               | order to keep your inventory management simple, even
               | though you're barely using any of the addresses.
               | 
               | I'm not saying the above is a good idea, just that if you
               | do dumb stuff with your address space, you can end up
               | running out of addresses even though you have many many
               | orders of magnitude more addresses than you actually use.
        
               | bauruine wrote:
               | As a LIR you get a /32 by default, no questions asked. If
               | you need more you need justification and from my
               | experience with RIPE and PI space they can be a pain in
               | the ass regarding that. AFAIK the biggest one they ever
               | give a LIR is a /28 with the note that they never ever
               | want to hear from you again. There are 268'435'456 /28
               | available. I don't think i will still life when we reach
               | the only 200 Million /28 left mark.
        
               | Arnavion wrote:
               | Also all the current allocation standards are for
               | 2000::/3. If it turns out we have some unforeseen issue
               | with the current policy of handing out blocks we can come
               | up with something else for the five other /3's that are
               | completely unused.
        
               | ninkendo wrote:
               | Giving a /32 to anyone who wants one without any
               | questions asked is probably a good example of why "aren't
               | we making the same mistake as ipv4?" isn't an entirely
               | meritless question.
               | 
               | I mean it's probably crazy to imagine a scenario where we
               | have more than 4 billion "local internet registries" in
               | the universe, but it's not so crazy to imagine a scenario
               | where the ability to ask for a /32 maybe needs to get
               | constrained a little more.
               | 
               | In the end, I think the idea of making all subnets /64's
               | may have been a mistake. It's cool that you can put MAC
               | addresses right in the address and thus don't need DHCP
               | any more, but carving out room for
               | 18,446,744,073,709,551,616 devices per broadcast domain
               | is a bit crazy on the face of it. Plus you need all the
               | privacy addresses to hide your MAC address from trackers
               | anyway, which is way more complexity than we really
               | needed. IMO DHCP isn't so bad, it's boring/predictable
               | technology at this point, and I'd be perfectly
               | comfortable with shifting the "provider vs customer"
               | boundary many bits to the right in an address, so that a
               | typical subnet is more like a /104 and ISP's give out
               | /96's, etc. That would give us a lot more headroom than
               | the system we have now where anyone can grab a /32.
        
               | iso1631 wrote:
               | > In the end, I think the idea of making all subnets
               | /64's may have been a mistake.
               | 
               | True, but just imagine the subnets are only 64k hosts,
               | with ipv6's address space as a /80.
               | 
               | My own ipv4 routed network (which is currently routed
               | across 5 continents) is based on a space in the 172.16/12
               | range comprising 5 /16s. A lot of the subnets I use are
               | chopped down to /27, /28 and /29 (and of course /30 and
               | /31s for links and /32s for loopbacks).
               | 
               | That said it's a bit of a squeeze at the moment.
               | 
               | To implement that in an ipv6 world, I'd make every subnet
               | currently sizing between /29 and /25 into a /64. At most
               | it's 8 subnets per /24 at the moment, so call it 16.
               | 
               | As such every /24 I currently allocate would be a /60.
               | 
               | and I have 1280 of those /24s, so 11 bits, which means I
               | need a /49.
               | 
               | Add some expansion space (which I'm currently looking at)
               | and that seems quite neat as a /48.
               | 
               | That's a fairly big network. At some point in the future
               | I could see justifying a second /48.
               | 
               | My company as a whole certainly has more requirement than
               | that, but we have a /32 allocated (we also have a /16 and
               | /19 in ipv4 land and 2 ASes). That /32 could allocate
               | 65,000 of my continent spanning networks. I think we have
               | about 8, and only a couple are really large. The main one
               | is based on the 10/8 network range, which would probably
               | fit into a single /48, but certainly in a handful of
               | them.
               | 
               | > where anyone can grab a /32.
               | 
               | If the requirement to grab a single /32 is an ability to
               | fill in a form asking for it, we aren't going to be
               | running into any issues any time in the next 100 years.
        
               | bauruine wrote:
               | Everyone that is willing to pay an initial 2400.- and
               | yearly 1400.- to RIPE.
               | 
               | Yes we may have to constrain this a little more sometimes
               | but we have plenty of IP space and therefore time before
               | we have to consider this.
        
         | sigio wrote:
         | Just see it as a 64-bit address-space, as one /64 will be for 1
         | home/location/lan.
         | 
         | Then we still have 32^32 times the amount of address-space we
         | have in v4.
        
       | greyface- wrote:
       | Beware: https://www.arin.net/resources/fees/fee_schedule/#rsp-
       | servic...
        
         | zerotolerance wrote:
         | Neat note at the bottom, "* There is a temporary IPv6 fee
         | waiver for organizations in the 3X-Small service category. A
         | 3X-Small organization may receive registry services for up to a
         | /36 of total IPv6 space and remain in the 3X-Small service
         | category. This waiver will expire 31 December 2026."
        
       ___________________________________________________________________
       (page generated 2022-10-31 23:02 UTC)