Boss: why is this service using IPv6?
Me: I just wanted to use IPv6 once in my career for a production service. Seems sad people did all that work for nothing.
#networking #ipv6 #infrastructure

@flameeyes Don't get me wrong I am all for #IPv6 adoption. But it has soo many issues, right now. Let alone the stability for networks like Vodafone, Tata and the like.

Also if your application doesn't support happy-eyeballs it's a big mess.

One example:

Falk Stern
XC# netstat -lnup | grep snmp
udp 0 0* 22967/tinysnmpd

Danke für nix, Ubiquiti. #IPv6

Jeremiah Lee
Another example: If I go to create a new GCE instance in the GCP console, the Terraform it generates does not include any of the IPv6 configuration. It's included in the command line and REST equivalent code, but not the Terraform. Whhyyy??

Jeremiah Lee
Why does it feel like all the people who *should* care about IPv6 don’t care about it (eg GCP and one of the largest home ISPs in Sverige)?


Jeremiah Lee
If you want to be able to reserve IPv6 addresses on GCP with Terraform, please gimme a 👍.

IT News
Where Exactly Did That Network Packet Come From? - Have you ever noticed that some websites can figure out, at least roughly, where y... - #ipgeolocation #networkhacks #ipv4 #ipv6

Karl Auerbach
Supernatantmotherliquor with a rotten cherry on top!!!!!!!

Today I wanted to fire up a web browser and point it at an IPv6 link local address (with the interface/zone specifier). I know the convention with square brackets & the way to express the interface. I.e. I wanted to have my browser connect to:


But no. Browser makers now treat the "address bar" as a search bar: Safari, Chrome, Firefox all treated the above as a search expression.

I can use the address above to make a perfectly usable SSH connection:

ssh fe80::20d:b9ff:fe40:2f9e%en0

Browsers used to do this IPv6 address thing correctly, but the race to monetize the address bar to pre-capture search queries has rotted the browsers.

I began working on the future for IPv4 back in the very early 1990s. It is sad how badly IPv6 has muddled in the years since.

GD&*@!#! Not everything on the net is a search query!!!!! Browsers should easily allow raw IPv6 addresses without sending them to a search site


Nick Buraglio
Am I really in a 2023 where
RedHat RHEL subscription manager cannot happen on an IPv6-only network? I really hope I am wrong....if not, that's a significant issue for USG systems.
Hello cyberpolice :ablobcatwave:​

My IP is looking like "2a10:cc45:121:acab:acab:acab:acab:acab" by pure accident.
There is no deeper meaning behind it :ageblobcat:​

Wat, #duckduckgo kann kein #ipv6?!

@jonatan @noipv6

On Macs, I've noticed that using #pfSense with #Ventura in Assisted mode, #macOS will acquire SLAAC addresses but never receives a #DHCP6 address. Macs are the only devices like this on my local LAN.

There's nothing wrong with stateless addresses, of course, but since the ISP can change the delegation at will, for full #IPv6 on your local network, you want #DHCP6 to conveniently enable DNS names.

I can't tell if this is a pfSense thing or an #Apple thing. But it ain't good.

INFURIATINGLY insulting comment during the Q/A section that was basically "you're late to #IPv6 and you suck".

I had to jump up to the mic and had to correct the commenter, that while "yes" the best time to deploy IPv6 was 20 years ago, but the second best time is now. Also, insulting people for being (so called) late is super counter-productive.

Don't punish the behaviour you wish to see, c'mon!


Jonatan Steuernagel
Me: Wants to switch Wireguard tunnels to use #IPv6
Also me: Wants to use link-local addresses to route my traffic and immediatly finds a Bug with the Wireguard package for Ubiquiti 🤦‍♂️

Interesting, an ISP decided while they will deploy #CGNAT to their users. Since the main cost center for ISPs is support costs, they did some checking for "port forwarding" on the CPE and checking for "dmz" in searches, and excluded those users from CGNAT.

They also allow users to opt-out via the customer support portal.

Info about why not other technologies are in the presentation, check it out!

⬆️ Ceci est un toot purement #IPv6

Slide 5 / 12
▪ Support calls can kill the case, be aware for the “5%”
• Exclude users that do DMZ/Port forwarding (Give them public V4)
• Easy opt-out users from CGNAT via portal/app
• Test, test ,test....
▪ Lowering CGNAT traffic, improves business case
• Bypass CGNAT for internal services (mail/dns)
• Directly route Google/Netflix traffic from Local Caches.
Finally a business case for IPv6!

panda :verified:
Networking is weird. I setup a gif tunnel to, but it doesn't really come up for some reason.

The weird thing is the setup looks fine on my side. #ipv6 traffic leaves opnsense as expected.

I can see it in tcpdump. Both on the gif interface and the wan interface.

It seems like the server ignores my packets.

I really don't know any further at this point and I'm super tired of german isps not properly supporting ipv6.

John-Mark Gurney
Well, FreeBSD's #IPv6 mirror state is pretty poor. Right now is sending me to Tokoyo, which has a RTT of around 140ms.

Yet IPv4 has me go to ISC in the Bay Area w/ an RTT of 10ms.

Looks like part of the problem is that isc's IPv6 address is the Tokoyo address.

Jonatan Steuernagel
Me, once again noticing how old #IPv6 is already and how it is still so badly supported in many cases…

For Real What GIF by SWR3

Someone slightly facepalming
Jonatan Steuernagel
Uuh, maybe I should also play around with Tayga and doing some #NAT64 for #IPv6 myself.
Maybe an #IPv6 only homelab network could actually be in my future, even without the rest of the world getting their shit together 😶

Jonatan Steuernagel
I‘ve started configuring my first #BGP connection over #Wireguard and automatically chose 2 IPv4 adresses for the transit network. In the end that really doesn’t matter but somehow I have the urge to change it over to #IPv6 addresses, just to normalize the usage of IPv6 as the default.
Though I‘ve learned that I‘d loose 20 MTU by doing that, not that that would make any measurable difference here.

Can someone explain the duration value for #RFC8925 / IPv6-Only Preferred?

I'm pretty sure I'm being stupid right now, but I don't understand why I would want to have a time limit.


Overheard #NewITGuy telling someone that #IPv6 was faster than IPv4. It's a bigger number, see...

Patchday für #mikrotik RouterOS 7.10beta7, 7.9.1, 6.49.8, 6.48.7 gegen CVE-2023-32154.

"You are only affected if one of the below settings is applied:

ipv6/settings/ set accept-router-advertisements=yes


ipv6/settings/set forward=no accept-router-advertisements=yes-if-forwarding-disabled"


Christopher M0YNG
thanks for the replies. I have the basics working as far as I can tell, with my laptop, phone, and mini-server all having #IPv6 addresses and talking to v6 servers.

Now I need to work out how to get #piHole running in docker to talk v6, but maybe that's a tomorrow job.

Hacker News 50
Christopher M0YNG
I got #IPv6 enabled on my home broadband connection!

What do I need to think about doing before I enable it?

How best to configure it for a bunch of computers that have been assuming no one can directly access them outside the local network (and I'd like to keep it that way)?

I'm using unifi networking equipment

Adrian Offerman
op Toepassing moderne internetstandaarden bij Nederlandse bedrijven groeit -- Interessante verschillen per standaard tussen bedrijfsgrootten en bedrijfstakken

"De totaalscores bleken te zijn gestegen van 60,3 naar 65,1 procent. Kleine bedrijven en zzp’ers scoren beter op het gebruik van IPv6, terwijl grotere bedrijven betere resultaten halen op de toepassingen van HTTPS."


Thomas Schäfer
1 week ago


#ipv6 Roaming in Niederlande ging, statt v6ony habe ich jetzt dualstack

Rod Van Meter
Care about #IPv6, #SRv6, and how to build great networks? Recent paper from our lab:

Thomas Schäfer
And ping is very old...
(in other os ping and ping6 are merged already)


Nick Buraglio
Spent the last few days exercising DHCP option 108 (RFC8925 - #ipv6 mostly) across different platforms. I must say, it is quite seamless. The only wrinkle I have found so far is very, very old Android devices. Moved a legacy v4 enclave to it and so far it's working perfectly.

Andreas Scherbaum
OH: "Meine Meisen kann ich wunderbar in v6 angucken!"

Controversial opinion: There are legit use cases for #IPv6 NAT

Major Hayden
If you're looking for a bit more privacy in your IPv6 SLAAC address on Linux, these steps may help.

I’m little lost. How to setup on Windows that it won’t get any additional IPv6 addresses from RA and so on once I’ve setup manual IPv6 address and proper gateway? #ipv6 #windows. Whatever I’ve tried it’s still get additional addresses even all is set manually. Any hints?

@dolari whereas even for #Windows-Fans there are simple tools like #netplan ( ) that just allow simply setup a failover-#bond between #Wifi and #Ethernet and assign it one #IPv4 (and even #IPv6)...

And it just works...

Note: #netplan does not run on Windows, because Windows is trash!

Slides and talks from the UK IPv6 Council's "Enterprise & #IPv6 Workshop" are now available: (including a good summary on IPv6 status in Kubernetes)

Ce toot vous a été envoyé grâce au protocole IPv6® 😎

Et vous ? Vous êtes en #IPv6 aussi ? Le luxe de l'Internet

Vue de mon plugin sur Firefox "IPvFoo" qui m'indique si ma connexion à un site web, respectivement est faite en IPv6, en IPv4 ou les deux. Ici l'adresse IPv6 de tooting est affichée 2a0a:db40:1::35
Hambone Fakenamington
Major router manufacturer where the VoIP ATA in the router stops working (even over IPv4!) if you set IPv6 DNS or IP manually:
"We've had a definitive answer [..] and it is not good news I'm afraid. [..]
[Vendor] does not support VoIP6 in [platform] today, it is not a model specific issue.
There are no immediate plans to implement VoIP6, therefore no schedule."
Add that to the pile of problems we have with the CPE vendor :( #VoIP #SIP #IPv6 #CPE

#GitHub being IPv4 only is so annoying and sad.. :blobcatverysad:


René ♾️
Weshalb ist mein #Heimnetzwerk mit deaktivierten #ipv6 gefühlt schneller? Ist da was falsch konfiguriert oder ist das generell so? Es merken besonders die Kids auf ihren Windows Büchsen beim Spielen. Aber auch die Streamingdienste sind irgendwie flüssiger wenn nur #ipv4 aktiv ist.

Hey, #fediverse: I’m experimenting with #IPv6 on residential #FiOS to #pfSense with hosts like behind #HAProxy. (whew)

#DNS on Google Domains is giving me fits. It’s too long to detail in a toot so if you’re interested in helping me with a question, please checkout this #Reddit post:


And thank you for pointing out to me that I had more work to do.

I learned a lot about #IPv6, thanks to your feedback.

Here's a quickie #PowerShell function I use to get my current #IPv6 GUA and IPv4 address on the console.

function Get-MyIpAddress
$ipv4 = (Invoke-WebRequest
$ipv6 = (Invoke-WebRequest
$output = "Protocol:$($ipv6.Split(",")[0])`tAddress:$($ipv6.Split(",")[1])`nProtocol:$($ipv4.Split(",")[0])`tAddress:$($ipv4.Split(",")[1]) "
Write-Host -ForegroundColor Yellow -Object $output

So, after I posted how cool #IPv6 was, I got a nice reply from a visitor that in fact this instance was NOT available via IPv6.

I think I’ve licked that issue now though I haven’t completely solved DNS updates.

But I’d appreciate hearing from folks who attempt to access via IPv6.

John-Mark Gurney
One of the issues w/ #IPv6 is that it isn't monitored/maintained nearly as well as IPv4.

I've been having connectivity issues the last few days, and pretty sure it's down to spotty IPv6.

Of course people are going to disable IPv6 if the quality of their internet is worse than on IPv4 only.

Main host I've having issues w/ right now is, but others as well.

Jeremiah Lee
Update: I am giving up on getting an #IPv6 Mastodon instance setup on #GCP for now. There is no happy path, only broken documentation examples or load balancer termination (which doesn't work because of outbound requests).

@SGgrc @leo

You’ve talked for years about protection value of NAT in consumer routers.

#FiOS here is rolling out #IPv6 (in a quirky way, as only #Verizon can). I’ve been experimenting with it using #pfSense and “losing” NAT to IPv6 GUAs is the first big head-slapper.

Would love to hear what you think of the lack of NAT in IPv6 and consumer connectivity on an upcoming #SecurityNow.

Nick Buraglio
New Blog Post: Quick and dirty Mikrotik CG-NAT using NETMAP and hardware offload NAT.

Jeremiah Lee
Why in the year of 2023 is IPv6 not enabled by default on GCP? Why? WHY?? And why is it 18 steps to enable?

@mozilla How about adding #IPv6 support?

And maybe not host your stuff @google?

Thomas :damnified:
1 month ago is only accessible via IPv6. Great for testing dualstack networks for working IPv6. :)


@jwildeboer @EU_Commission doesn't change the fact tho that your criticisms are totally valid anyway and that there's no excuse for ISPs to bot even assign a /64 #IPv6 statically free of charge...(

@jwildeboer @EU_Commission @torproject Even tho #Vodafone Business Germany is even more absurd since they'll assign me an entire /29 of #IPv4's at no extra cost but won't offer me even a /64 #IPv6 for no reason but being dicks...

@jwildeboer @EU_Commission that being said, I fully agree and think everyone should have a free, provider-independent #IPv6 /64 assignment and shit like #CGNAT, espechally those violating standards and using #RFC1918 adress spaces (like #mobile networks routinely do) should be abolished and forcibly disconnecting limes each 24 hours as well as trying to restrict peoples' use should be abolished.

Jan Wildeboer 😷
#IPv6 is the present and the future. But boy, identifying IPv6 addresses in log files with a regex is, well, a bit more work ;) Source:

egrep "(([0-9a-fA-F]{1,4}:){7,7}[0-9a-fA-F]{1,4}|([0-9a-fA-F]{1,4}:){1,7}:|([0-9a-fA-F]{1,4}:){1,6}:[0-9a-fA-F]{1,4}|([0-9a-fA-F]{1,4}:){1,5}(:[0-9a-fA-F]{1,4}){1,2}|([0-9a-fA-F]{1,4}:){1,4}(:[0-9a-fA-F]{1,4}){1,3}|([0-9a-fA-F]{1,4}:){1,3}(:[0-9a-fA-F]{1,4}){1,4}|([0-9a-fA-F]{1,4}:){1,2}(:[0-9a-fA-F]{1,4}){1,5}|[0-9a-fA-F]{1,4}:((:[0-9a-fA-F]{1,4}){1,6})|:((:[0-9a-fA-F]{1,4}){1,7}|:)|fe80:(:[0-9a-fA-F]{0,4}){0,4}%[0-9a-zA-Z]{1,}|::(ffff(:0{1,4}){0,1}:){0,1}((25[0-5]|(2[0-4]|1{0,1}[0-9]){0,1}[0-9])\.){3,3}(25[0-5]|(2[0-4]|1{0,1}[0-9]){0,1}[0-9])|([0-9a-fA-F]{1,4}:){1,4}:((25[0-5]|(2[0-4]|1{0,1}[0-9]){0,1}[0-9])\.){3,3}(25[0-5]|(2[0-4]|1{0,1}[0-9]){0,1}[0-9]))(\/((1(1[0-9]|2[0-8]))|([0-9][0-9])|([0-9])))?"
NLnet Labs
Did we mention #IPv6 support? #RPKI

Michael Gebis
If I were an evil threat actor, I'd be learning as much about #ipv6 as possible right now. I'm convinced that many companies that say they "aren't using" IPv6 are in reality just ignoring IPv6, and it would be easy to set up a "shadow network" consisting of IPv6 traffic where you could get away with murder. Nobody at the company is logging IPv6 traffic and events, none of the tools are configured to monitor it, and a large majority of the staff knows nothing about it.

I added an IPv6 address to - the non-bot traffic quickly jumped to >45% #IPv6. Quite impressive!

Looks good!


Screenshot of the website showing its IPV6 address via the IPvFoo Firefox addon.
Timo Geusch
@stefano a few years ago we moved to a place where the local quasi-monopoly ISP offers properly configured and working #IPv6. I’ve been experimenting with it ever since and must say I really like using it - dual stack of course because I still see a lot of IPv4 traffic.

A lot of it turned out to be easier than I thought, once I had figured out the firewall settings. Oh, and the correct incantation to have the ISP at least cough up a /60 instead of a /64.

Hambone Fakenamington
ARGH... I'm on my second attempt at finding a suitable #VPS host who is low cost, supports #IPv6 and isn't utterly scummy... this one looked perfect.. then I tried pinging an IPv6 server I have off I can't believe this #Cogent to IPv6 issue is STILL a thing. (also, sucks that this VPS provider has Cogent only).

Raito Bezarius
Some toots ago, I spoke about doing this neat PROXY protocol thing for many hosts at the same time based on what @beasts does.

I finally wrote an article on how to achieve it:

It is running in production on this very server with success! (and many others!!)

It's all fake! They are still using IPv4 :blobcatopenmouth:​

Screenshot of the website showing the error message "SQLSTATE[HY000] [2003] Can't connect to MySQL server on '' (4)"

If the headers on this latest spam are to be believed (who knows), someone is passing email around between servers using 2002:: prefix #IPv6 for #IPv4 RFC1918 10.x.x.x addresses.

I am a tad sceptical of the headers, but that is a new one on me. Really rather "special" to say the least.

P.S. The spam was entirely some right to left script in a language for which I have no clue. The headers were the only interesting bit 🙂

Received: by 2002:a17:903:138f:b0:19c:a86d:b340 with SMTP id
 jx15-20020a170903138f00b0019ca86db340ls2423244plb.9.-pod-prod-gmail; Thu, 16
 Mar 2023 09:35:59 -0700 (PDT)
Aral Balkan
My bad, I accidentally ran npm config set registry http:// --global instead of *https* while troubleshooting. 🤦‍♂️

All good now :)

Alex Haydock
A Native American tribal ISP seems to be handing out AppleTVs to users in exchange for their Roku devices after discovering that 71% of their IPv4 traffic was Roku-related, and deciding that this would actually be the cheaper solution.