Masthash

#ipv6

waldstepper
4 hours ago
matdevdug
7 hours ago

Boss: why is this service using IPv6?
Me: I just wanted to use IPv6 once in my career for a production service. Seems sad people did all that work for nothing.
Boss: 😑
#networking #ipv6 #infrastructure

awlnx
9 hours ago

@flameeyes Don't get me wrong I am all for #IPv6 adoption. But it has soo many issues, right now. Let alone the stability for networks like Vodafone, Tata and the like.

Also if your application doesn't support happy-eyeballs it's a big mess.

One example:
https://github.com/npm/cli/issues/4163#issuecomment-1084601306

Falk Stern
16 hours ago

XC# netstat -lnup | grep snmp
udp 0 0 0.0.0.0:161 0.0.0.0:* 22967/tinysnmpd

Danke für nix, Ubiquiti. #IPv6

Jeremiah Lee
1 day ago

Another example: If I go to create a new GCE instance in the GCP console, the Terraform it generates does not include any of the IPv6 configuration. It's included in the command line and REST equivalent code, but not the Terraform. Whhyyy??

#GCP #IPv6 #Terraform #rant

Jeremiah Lee
2 days ago

Why does it feel like all the people who *should* care about IPv6 don’t care about it (eg GCP and one of the largest home ISPs in Sverige)?

#IPv6

Jeremiah Lee
2 days ago

If you want to be able to reserve IPv6 addresses on GCP with Terraform, please gimme a 👍.

https://github.com/hashicorp/terraform-provider-google/issues/14748

#GCP #Terraform #IPv6

IT News
2 days ago

Where Exactly Did That Network Packet Come From? - Have you ever noticed that some websites can figure out, at least roughly, where y... - https://hackaday.com/2023/05/26/where-exactly-did-that-network-packet-come-from/ #ipgeolocation #networkhacks #ipv4 #ipv6

Karl Auerbach
2 days ago

Supernatantmotherliquor with a rotten cherry on top!!!!!!!

Today I wanted to fire up a web browser and point it at an IPv6 link local address (with the interface/zone specifier). I know the convention with square brackets & the way to express the interface. I.e. I wanted to have my browser connect to:

http://[fe80::20d:b9ff:fe40:2f9e%en0]/

But no. Browser makers now treat the "address bar" as a search bar: Safari, Chrome, Firefox all treated the above as a search expression.

I can use the address above to make a perfectly usable SSH connection:

ssh fe80::20d:b9ff:fe40:2f9e%en0

Browsers used to do this IPv6 address thing correctly, but the race to monetize the address bar to pre-capture search queries has rotted the browsers.

I began working on the future for IPv4 back in the very early 1990s. It is sad how badly IPv6 has muddled in the years since.

GD&*@!#! Not everything on the net is a search query!!!!! Browsers should easily allow raw IPv6 addresses without sending them to a search site

#ipv6

Nick Buraglio
2 days ago

Am I really in a 2023 where
RedHat RHEL subscription manager cannot happen on an IPv6-only network? I really hope I am wrong....if not, that's a significant issue for USG systems. https://access.redhat.com/solutions/465613
Come on, folks. #IPv6

Stanford
2 days ago

Hello cyberpolice :ablobcatwave:​

My IP is looking like "2a10:cc45:121:acab:acab:acab:acab:acab" by pure accident.
There is no deeper meaning behind it :ageblobcat:​

#cyber #police #ipv6

Martin
2 days ago
sedrubal
3 days ago

Wat, #duckduckgo kann kein #ipv6?!

@jonatan @noipv6

On Macs, I've noticed that using #pfSense with #Ventura in Assisted mode, #macOS will acquire SLAAC addresses but never receives a #DHCP6 address. Macs are the only devices like this on my local LAN.

There's nothing wrong with stateless addresses, of course, but since the ISP can change the delegation at will, for full #IPv6 on your local network, you want #DHCP6 to conveniently enable DNS names.

I can't tell if this is a pfSense thing or an #Apple thing. But it ain't good.

INFURIATINGLY insulting comment during the Q/A section that was basically "you're late to #IPv6 and you suck".

I had to jump up to the mic and had to correct the commenter, that while "yes" the best time to deploy IPv6 was 20 years ago, but the second best time is now. Also, insulting people for being (so called) late is super counter-productive.

Don't punish the behaviour you wish to see, c'mon!

#RIPE86

Jonatan Steuernagel
4 days ago

Me: Wants to switch Wireguard tunnels to use #IPv6
Also me: Wants to use link-local addresses to route my traffic and immediatly finds a Bug with the Wireguard package for Ubiquiti 🤦‍♂️

https://github.com/WireGuard/wireguard-vyatta-ubnt/issues/148

Interesting, an ISP decided while they will deploy #CGNAT to their users. Since the main cost center for ISPs is support costs, they did some checking for "port forwarding" on the CPE and checking for "dmz" in searches, and excluded those users from CGNAT.

They also allow users to opt-out via the customer support portal.

Info about why not other technologies are in the presentation, check it out! https://ripe86.ripe.net/programme/meeting-plan/ipv6-wg/

#RIPE86 #IPv6 WG

⬆️ Ceci est un toot purement #IPv6

chrbre
4 days ago

https://ripe86.ripe.net/wp-content/uploads/presentations/67-RPE86-IPv6-deployment-journey.pdf_1.2.pdf #ipv6
THE BUSINESS CASE OF CGNAT PART 2
Slide 5 / 12
▪ Support calls can kill the case, be aware for the “5%”
• Exclude users that do DMZ/Port forwarding (Give them public V4)
• Easy opt-out users from CGNAT via portal/app
• Test, test ,test....
▪ Lowering CGNAT traffic, improves business case
• Bypass CGNAT for internal services (mail/dns)
• Directly route Google/Netflix traffic from Local Caches.
Finally a business case for IPv6!

panda :verified:
5 days ago

Networking is weird. I setup a gif tunnel to he.net, but it doesn't really come up for some reason.

The weird thing is the setup looks fine on my side. #ipv6 traffic leaves opnsense as expected.

I can see it in tcpdump. Both on the gif interface and the wan interface.

It seems like the he.net server ignores my packets.

I really don't know any further at this point and I'm super tired of german isps not properly supporting ipv6.

John-Mark Gurney
5 days ago

Well, FreeBSD's #IPv6 mirror state is pretty poor. Right now download.freebsd.org is sending me to Tokoyo, which has a RTT of around 140ms.

Yet IPv4 has me go to ISC in the Bay Area w/ an RTT of 10ms.

Looks like part of the problem is that isc's IPv6 address is the Tokoyo address.

Jonatan Steuernagel
5 days ago

Me, once again noticing how old #IPv6 is already and how it is still so badly supported in many cases…

For Real What GIF by SWR3

Someone slightly facepalming
Jonatan Steuernagel
5 days ago

Uuh, maybe I should also play around with Tayga and doing some #NAT64 for #IPv6 myself.
Maybe an #IPv6 only homelab network could actually be in my future, even without the rest of the world getting their shit together 😶

Jonatan Steuernagel
5 days ago

I‘ve started configuring my first #BGP connection over #Wireguard and automatically chose 2 IPv4 adresses for the transit network. In the end that really doesn’t matter but somehow I have the urge to change it over to #IPv6 addresses, just to normalize the usage of IPv6 as the default.
Though I‘ve learned that I‘d loose 20 MTU by doing that, not that that would make any measurable difference here.

Stanford
5 days ago

Can someone explain the duration value for #RFC8925 / IPv6-Only Preferred?

I'm pretty sure I'm being stupid right now, but I don't understand why I would want to have a time limit.

#IPv6

lopta
5 days ago

Overheard #NewITGuy telling someone that #IPv6 was faster than IPv4. It's a bigger number, see...

Patchday für #mikrotik RouterOS 7.10beta7, 7.9.1, 6.49.8, 6.48.7 gegen CVE-2023-32154.

https://blog.mikrotik.com/security/cve-2023-32154.html

"You are only affected if one of the below settings is applied:

ipv6/settings/ set accept-router-advertisements=yes

or

ipv6/settings/set forward=no accept-router-advertisements=yes-if-forwarding-disabled"

#ipv6

Christopher M0YNG
6 days ago

thanks for the replies. I have the basics working as far as I can tell, with my laptop, phone, and mini-server all having #IPv6 addresses and talking to v6 servers.

Now I need to work out how to get #piHole running in docker to talk v6, but maybe that's a tomorrow job.

Hacker News 50
6 days ago
Christopher M0YNG
6 days ago

I got #IPv6 enabled on my home broadband connection!

What do I need to think about doing before I enable it?

How best to configure it for a bunch of computers that have been assuming no one can directly access them outside the local network (and I'd like to keep it that way)?

I'm using unifi networking equipment

Adrian Offerman
1 week ago

op SIDN.nl: Toepassing moderne internetstandaarden bij Nederlandse bedrijven groeit -- Interessante verschillen per standaard tussen bedrijfsgrootten en bedrijfstakken
https://www.sidn.nl/nieuws-en-blogs/toepassing-moderne-internetstandaarden-bij-nederlandse-bedrijven-groeit

"De totaalscores bleken te zijn gestegen van 60,3 naar 65,1 procent. Kleine bedrijven en zzp’ers scoren beter op het gebruik van IPv6, terwijl grotere bedrijven betere resultaten halen op de toepassingen van HTTPS."

#IPv6 #DNSSEC #DMARC #DANE
#InternetSecurity
@internet_nl

Thomas Schäfer
1 week ago

@f2k1de

#ipv6 Roaming in Niederlande ging, statt v6ony habe ich jetzt dualstack

Rod Van Meter
1 week ago

Care about #IPv6, #SRv6, and how to build great networks? Recent paper from our lab:
https://www.jstage.jst.go.jp/article/transinf/E106.D/5/E106.D_2022NTP0003/_article

Thomas Schäfer
1 week ago

@_holger

And ping is very old...
(in other os ping and ping6 are merged already)

#ipv6

Nick Buraglio
1 week ago

Spent the last few days exercising DHCP option 108 (RFC8925 - #ipv6 mostly) across different platforms. I must say, it is quite seamless. The only wrinkle I have found so far is very, very old Android devices. Moved a legacy v4 enclave to it and so far it's working perfectly.

Andreas Scherbaum
1 week ago

OH: "Meine Meisen kann ich wunderbar in v6 angucken!"

#TabsVonGesternNacht #TvgN #IPv6

Stanford
1 week ago

Controversial opinion: There are legit use cases for #IPv6 NAT

Major Hayden
1 week ago

If you're looking for a bit more privacy in your IPv6 SLAAC address on Linux, these steps may help.

#networking #ipv6 #privacy #linux #networkmanager

https://major.io/2016/04/17/enable-ipv6-privacy-networkmanager/

MarcinGondek
2 weeks ago

I’m little lost. How to setup on Windows that it won’t get any additional IPv6 addresses from RA and so on once I’ve setup manual IPv6 address and proper gateway? #ipv6 #windows. Whatever I’ve tried it’s still get additional addresses even all is set manually. Any hints?

@dolari whereas even for #Windows-Fans there are simple tools like #netplan ( https://netplan.io/ ) that just allow ome.to simply setup a failover-#bond between #Wifi and #Ethernet and assign it one #IPv4 (and even #IPv6)...

And it just works...
https://driveinsaturday.org/@dolari/110381477500668703

Note: #netplan does not run on Windows, because Windows is trash!

Slides and talks from the UK IPv6 Council's "Enterprise & #IPv6 Workshop" are now available: https://www.ipv6.org.uk/2023/02/03/enterprise-ipv6-workshop/ (including a good summary on IPv6 status in Kubernetes)

Ce toot vous a été envoyé grâce au protocole IPv6® 😎

Et vous ? Vous êtes en #IPv6 aussi ? Le luxe de l'Internet

Vue de mon plugin sur Firefox "IPvFoo" qui m'indique si ma connexion à un site web, respectivement tooting.ch est faite en IPv6, en IPv4 ou les deux. Ici l'adresse IPv6 de tooting est affichée 2a0a:db40:1::35
Hambone Fakenamington
2 weeks ago

Major router manufacturer where the VoIP ATA in the router stops working (even over IPv4!) if you set IPv6 DNS or IP manually:
"We've had a definitive answer [..] and it is not good news I'm afraid. [..]
[Vendor] does not support VoIP6 in [platform] today, it is not a model specific issue.
There are no immediate plans to implement VoIP6, therefore no schedule."
Add that to the pile of problems we have with the CPE vendor :( #VoIP #SIP #IPv6 #CPE

Stanford
2 weeks ago

#GitHub being IPv4 only is so annoying and sad.. :blobcatverysad:

#IPv6

René ♾️
2 weeks ago

Weshalb ist mein #Heimnetzwerk mit deaktivierten #ipv6 gefühlt schneller? Ist da was falsch konfiguriert oder ist das generell so? Es merken besonders die Kids auf ihren Windows Büchsen beim Spielen. Aber auch die Streamingdienste sind irgendwie flüssiger wenn nur #ipv4 aktiv ist.

Hey, #fediverse: I’m experimenting with #IPv6 on residential #FiOS to #pfSense with hosts like @air11.social behind #HAProxy. (whew)

#DNS on Google Domains is giving me fits. It’s too long to detail in a toot so if you’re interested in helping me with a question, please checkout this #Reddit post:

https://www.reddit.com/r/PFSENSE/comments/13f7l2o/dynamic_dns_entries_for_both_a_and_aaaa_records/?utm_source=share&utm_medium=ios_app&utm_name=ioscss&utm_content=1&utm_term=1

@tschaefer

And thank you for pointing out to me that I had more work to do.

I learned a lot about #IPv6, thanks to your feedback.

Here's a quickie #PowerShell function I use to get my current #IPv6 GUA and IPv4 address on the console.

function Get-MyIpAddress
{
$ipv4 = (Invoke-WebRequest http://ip4only.me/api/).content
$ipv6 = (Invoke-WebRequest http://ip6only.me/api/).content
$output = "Protocol:$($ipv6.Split(",")[0])`tAddress:$($ipv6.Split(",")[1])`nProtocol:$($ipv4.Split(",")[0])`tAddress:$($ipv4.Split(",")[1]) "
Write-Host -ForegroundColor Yellow -Object $output
}

So, after I posted how cool #IPv6 was, I got a nice reply from a visitor that in fact this instance was NOT available via IPv6.

I think I’ve licked that issue now though I haven’t completely solved DNS updates.

But I’d appreciate hearing from folks who attempt to access @air11.social via IPv6.

John-Mark Gurney
3 weeks ago

One of the issues w/ #IPv6 is that it isn't monitored/maintained nearly as well as IPv4.

I've been having connectivity issues the last few days, and pretty sure it's down to spotty IPv6.

Of course people are going to disable IPv6 if the quality of their internet is worse than on IPv4 only.

Main host I've having issues w/ right now is docs.python.org, but others as well.

Jeremiah Lee
3 weeks ago

Update: I am giving up on getting an #IPv6 Mastodon instance setup on #GCP for now. There is no happy path, only broken documentation examples or load balancer termination (which doesn't work because of outbound requests).

@SGgrc @leo

You’ve talked for years about protection value of NAT in consumer routers.

#FiOS here is rolling out #IPv6 (in a quirky way, as only #Verizon can). I’ve been experimenting with it using #pfSense and “losing” NAT to IPv6 GUAs is the first big head-slapper.

Would love to hear what you think of the lack of NAT in IPv6 and consumer connectivity on an upcoming #SecurityNow.

Nick Buraglio
3 weeks ago

New Blog Post: Quick and dirty Mikrotik CG-NAT using NETMAP and hardware offload NAT.
https://forwardingplane.net/2023/05/09/mikrotik-cg-nat-using-netmap-and-hardware-offload-nat/

#blog #ipv6 #mikrotik #cgnat

Jeremiah Lee
3 weeks ago

Why in the year of 2023 is IPv6 not enabled by default on GCP? Why? WHY?? And why is it 18 steps to enable?

#IPv6 #GCP

Stanford
3 weeks ago

@mozilla How about adding #IPv6 support?

And maybe not host your stuff @google?

Thomas :damnified:
1 month ago

ipv6.google.com is only accessible via IPv6. Great for testing dualstack networks for working IPv6. :)

#ipv6

@jwildeboer @EU_Commission doesn't change the fact tho that your criticisms are totally valid anyway and that there's no excuse for ISPs to bot even assign a /64 #IPv6 statically free of charge...(

@jwildeboer @EU_Commission @torproject Even tho #Vodafone Business Germany is even more absurd since they'll assign me an entire /29 of #IPv4's at no extra cost but won't offer me even a /64 #IPv6 for no reason but being dicks...

@jwildeboer @EU_Commission that being said, I fully agree and think everyone should have a free, provider-independent #IPv6 /64 assignment and shit like #CGNAT, espechally those violating standards and using #RFC1918 adress spaces (like #mobile networks routinely do) should be abolished and forcibly disconnecting limes each 24 hours as well as trying to restrict peoples' use should be abolished.
https://social.wildeboer.net/@jwildeboer/110250521163940486

Jan Wildeboer 😷
1 month ago

#IPv6 is the present and the future. But boy, identifying IPv6 addresses in log files with a regex is, well, a bit more work ;) Source: https://gist.github.com/khanzf/27996c1660317a4a2988

egrep "(([0-9a-fA-F]{1,4}:){7,7}[0-9a-fA-F]{1,4}|([0-9a-fA-F]{1,4}:){1,7}:|([0-9a-fA-F]{1,4}:){1,6}:[0-9a-fA-F]{1,4}|([0-9a-fA-F]{1,4}:){1,5}(:[0-9a-fA-F]{1,4}){1,2}|([0-9a-fA-F]{1,4}:){1,4}(:[0-9a-fA-F]{1,4}){1,3}|([0-9a-fA-F]{1,4}:){1,3}(:[0-9a-fA-F]{1,4}){1,4}|([0-9a-fA-F]{1,4}:){1,2}(:[0-9a-fA-F]{1,4}){1,5}|[0-9a-fA-F]{1,4}:((:[0-9a-fA-F]{1,4}){1,6})|:((:[0-9a-fA-F]{1,4}){1,7}|:)|fe80:(:[0-9a-fA-F]{0,4}){0,4}%[0-9a-zA-Z]{1,}|::(ffff(:0{1,4}){0,1}:){0,1}((25[0-5]|(2[0-4]|1{0,1}[0-9]){0,1}[0-9])\.){3,3}(25[0-5]|(2[0-4]|1{0,1}[0-9]){0,1}[0-9])|([0-9a-fA-F]{1,4}:){1,4}:((25[0-5]|(2[0-4]|1{0,1}[0-9]){0,1}[0-9])\.){3,3}(25[0-5]|(2[0-4]|1{0,1}[0-9]){0,1}[0-9]))(\/((1(1[0-9]|2[0-8]))|([0-9][0-9])|([0-9])))?"
NLnet Labs
2 months ago

Did we mention #IPv6 support? #RPKI

Michael Gebis
2 months ago

If I were an evil threat actor, I'd be learning as much about #ipv6 as possible right now. I'm convinced that many companies that say they "aren't using" IPv6 are in reality just ignoring IPv6, and it would be easy to set up a "shadow network" consisting of IPv6 traffic where you could get away with murder. Nobody at the company is logging IPv6 traffic and events, none of the tools are configured to monitor it, and a large majority of the staff knows nothing about it.

I added an IPv6 address to berthub.eu - the non-bot traffic quickly jumped to >45% #IPv6. Quite impressive!

hnapel
2 months ago

@bert_hubert

Looks good!

#IPV6

Screenshot of the berthub.eu website showing its IPV6 address via the IPvFoo Firefox addon.
Timo Geusch
2 months ago

@stefano a few years ago we moved to a place where the local quasi-monopoly ISP offers properly configured and working #IPv6. I’ve been experimenting with it ever since and must say I really like using it - dual stack of course because I still see a lot of IPv4 traffic.

A lot of it turned out to be easier than I thought, once I had figured out the firewall settings. Oh, and the correct incantation to have the ISP at least cough up a /60 instead of a /64.

Hambone Fakenamington
2 months ago

ARGH... I'm on my second attempt at finding a suitable #VPS host who is low cost, supports #IPv6 and isn't utterly scummy... this one looked perfect.. then I tried pinging an IPv6 server I have off HE.net... I can't believe this #Cogent to he.net IPv6 issue is STILL a thing. (also, sucks that this VPS provider has Cogent only).

Raito Bezarius
2 months ago

Some toots ago, I spoke about doing this neat PROXY protocol thing for many hosts at the same time based on what @beasts does.

I finally wrote an article on how to achieve it: https://ryan.lahfa.xyz/en/one-trick-to-build-a-tls-enabled-ipv6-only-empire-with-only-one-legacy-ip.html

It is running in production on this very server with success! (and many others!!)

#nixos #ipv6 #sni

Stanford
2 months ago

It's all fake! They are still using IPv4 :blobcatopenmouth:​

#ipv6 #ipv6forum

Screenshot of the website ipv6enabled.org showing the error message "SQLSTATE[HY000] [2003] Can't connect to MySQL server on '39.104.228.93' (4)"

If the headers on this latest spam are to be believed (who knows), someone is passing email around between servers using 2002:: prefix #IPv6 for #IPv4 RFC1918 10.x.x.x addresses.

I am a tad sceptical of the headers, but that is a new one on me. Really rather "special" to say the least.

P.S. The spam was entirely some right to left script in a language for which I have no clue. The headers were the only interesting bit 🙂

Received: by 2002:a17:903:138f:b0:19c:a86d:b340 with SMTP id
 jx15-20020a170903138f00b0019ca86db340ls2423244plb.9.-pod-prod-gmail; Thu, 16
 Mar 2023 09:35:59 -0700 (PDT)
Aral Balkan
3 months ago

My bad, I accidentally ran npm config set registry http:// registry.npmjs.org --global instead of *https* while troubleshooting. 🤦‍♂️

All good now :)

#npm #ipv6 #stuck #workaround

Alex Haydock
3 months ago

A Native American tribal ISP seems to be handing out AppleTVs to users in exchange for their Roku devices after discovering that 71% of their IPv4 traffic was Roku-related, and deciding that this would actually be the cheaper solution.

https://community.roku.com/t5/Features-settings-updates/It-s-2022-and-still-no-IPv6/td-p/759420/page/2

#ipv6