News: 1643016605

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

IPv6 is built to be better, but that's not the route to success

(2022/01/24)


Opinion In the World of Tomorrow that's always 10 years away, Linux dominates the desktop, quantum computers control the fusion reactors, and all Android phones receive regular system updates. And the internet runs on IPv6.

This sort of talk irks IPv6 stans, [1]mostly because it's true . They are serious-minded, far-seeing, sober engineering types who are both baffled and angry that IPv4 still rules the world in 2022. This is not how it was supposed to be.

IPv4 was designed by expert prophetic dreamers more than 40 years ago to be future-proof, but the future it actually created outstripped their dreams. IPv6 was the engineers' answer, born from a decade and a half of experience, and solving IPv4's undeniable routing, addressing, security and performance problems at the unprecedented scale it was being asked to support.

[2]

They built IPv6 to be everything the world needed in a 21st century network. The 21st century network was too busy to care. Nearly 25 years on since the protocol's launch, it carries maybe 25 per cent of global network traffic.

[3]

[4]

It has not swept all before it. For those who follow such things, one by-product has been two decades of unhappy articles – the [5]latest heart-rending missive is here , berating the makers of networks for not embracing the scheduled future. "It's as if they don't see the need," is the mournful cry.

Well, they don't. And that's not their fault.

[6]

IPv6 made two very important, interlinked assumptions from the outset: that the world would need more than the four billion addresses IPv4 could support, and that this plus a lot of less important factors justified an incompatible new stack that fixed everything. The first was correct, but irrelevant, and that made the second just plain wrong.

The irrelevance of the first observation came through the clever bodge of NAT, Network Address Translation. It's like a local switchboard for telephone extensions: a company with 10,000 employees can have just the one public telephone number. If you can do that, why rip out the whole phone system to give everyone a personal number? In retrospect, relying on IP address exhaustion to make IPv6 happen was doomed anyway, as it implied a user base far too huge to move. Making IPv6 incompatible with IPv4 just made that mountain higher, with the result that there are now tens of billions of IPv4 devices to convert. Not happening. Not without a really good reason – and more efficient routing tables ain't it.

The race does not always go to the swiftest. Many senior netheads will remember the tech wars of the 1980s and 90s, when wave after wave of superior computer technologies tried and failed to bring down the oafish monolith of the IBM PC architecture. Call it the Amiga Syndrome.

[7]

In the end, not only did innovation fail to overcome inertia, but the crude, neo-brutalist [8]8086 evolved to take over every specialism from video editing workstations to supercomputers. Incompatibility equals obsolescence.

[9]Can Rust save the planet? Why, and why not

[10]It's time to decentralize the internet, again: What was distributed is now centralized by Google, Facebook, etc

[11]APNIC: Big Tech's use of carrier-grade NAT is holding back internet innovation

[12]OK so what's going with these millions of Pentagon-owned IPv4 addresses lighting up all of a sudden?

But IPv6 isn't quite the network Itanium. There is no doubt that an IPv6-only planet would be superior, more efficient, support a bigger variety of services and have better security. The trouble is, until you get there, the opposite is true. If running an IPv4 network implies a certain amount of resources required and a certain threat landscape to manage, then adding a parallel IPv6 network means adding to those costs and liabilities. It doesn't get you much in return.

There are plenty of places where running IPv6 as a core protocol makes sense, especially if you're managing a huge estate where you make the rules, but they get less sensible as you move towards the edge.

It's not impossible, even then: some mobile operators have an [13]IPv6-only network that does IPv4 translation and tunnelling – although it's messy and hardly confers a compelling commercial advantage. You have to dig very deep into your phone settings to find if your carriers' APN is pure IPv4 or not. And do you know which UK ISPs do IPv6, which do not, and which are [14]dragging their feet ? You do not, nor do you care, nor should you.

Until IPv6 confers a palpable advantage to end users, which means compelling services that cannot be replicated on IPv4, it can only hope for a tap-drip of growth as each of a thousand business decisions on cost versus benefit goes its way.

If IPv6 fans want to change that, writing regular letters of unrequited love will do nothing but evince wistful pity among the rest of us.

Instead, they must build the services for which their protocol is the essential motor. Demonstrate what we could have if only we saw the need. Create the world they want – not give us the bricks and say "There you go."

It's harsh, it's unfair. It's reality. ®

Get our [15]Tech Resources



[1] https://www.theregister.com/2021/07/15/ipv6_istilli_510_years_away/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Ye6G1OEIRnYx67bF@nvDYQAAAJA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Ye6G1OEIRnYx67bF@nvDYQAAAJA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Ye6G1OEIRnYx67bF@nvDYQAAAJA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.theregister.com/2022/01/20/ipv4_nats_slow_ipv6_transition/

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Ye6G1OEIRnYx67bF@nvDYQAAAJA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Ye6G1OEIRnYx67bF@nvDYQAAAJA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[8] https://www.theregister.com/2012/12/22/verity_stob_8086_and_all_that_revisited/

[9] https://www.theregister.com/2021/11/30/aws_reinvent_rust/

[10] https://www.theregister.com/2021/08/11/decentralized_internet/

[11] https://www.theregister.com/2022/01/20/ipv4_nats_slow_ipv6_transition/

[12] https://www.theregister.com/2021/04/26/defense_department_ipv6/

[13] https://blog.wirelessmoves.com/2020/02/ipv6-only-in-mobile-networks.html

[14] https://www.ispreview.co.uk/index.php/2021/11/update-on-ipv6-plans-for-virgin-media-talktalk-plusnet-and-vodafone.html

[15] https://whitepapers.theregister.com/



Won't happen in my lifetime

Anonymous Coward

I'm 49.

Re: Won't happen in my lifetime

Jim Willsher

I'm also 49, I've worked in IT for 27 years (developer, networking, now a global CTO) and I agree. The IETF needs to fall on its sword and accept that it has failed.

Look at the failings of IPv4, look at the barriers to adoption of IPv6, and find some middle ground. IPv6 throws the baby out wit the bathwater.

Take NAT for example. Yes, people see it as a challenge. But it's great for having simple firewall rules, where the default is to disallow all inbound traffic.

Take addressing. Anyone in IT can easily remember IP addresses as they walk from one end of the office to the other; IPv6 address blocks are longer, with hex, and are just less memorable.

Take the concept of all devices having a public IP address. Maybe I don't want that?

I'm not posting this as an AC, and I'm happy to be shot down. But I don't think I'm wrong. If IPv6 brought enough advantages, the challenges would be overcome, people would find a way. But there are very few advantages at the "IT department level" and the "end user level", so there's simply no appetite for the effort.

Re: Won't happen in my lifetime

pavel.petrman

I think you've got the point exactly with the IT Department and end user levels. And both may very well be the points where IPv6 will see adoption rate rise later on: end users migrate in their flocs to big everything-as-a-service providers (Google, Apple, Microsoft) and care less and less about the raw infrastructure, as everything to the smallest smart whitch in the closet is set up through an app, not manually. End users are migrating from IPv4 not to IPv6 but to QR codes. Smaller IT departments look much the same, difference being in what's deployed but not how. A willingly implemented NAT solution may become a thing (Internet-facing network port being configured for IPv6 and everything behind it running on IPv4, including the DMZ, with some good old port translation thrown in the mix).

Maybe we are now just waiting for people to stop giving a damn about how the Internet is run and stop taking part in its operations, so that the ten to twenty remainig big guys can do their thing.

Re: Won't happen in my lifetime

Tom7

You should want that. The reason Facebook, Twitter, TikTok and so on have massive amounts of power today is because IPv6 hasn't been adopted, devices don't have a public IP address and peer-to-peer networking is impossible.

Hand me a global internet where every device has a public IP address and tomorrow I'll give you a social network where you actually connect with your friends instead of connecting to Facebook. Until then, any attempt to build it will drown in user complaints that it doesn't work. Or doesn't work on some of their devices. Or doesn't work when they're at work or at their friends' house. Or doesn't work when they roam onto the wrong mobile network. Actually, none of those things; the complaint will be that it just doesn't work because the average consumer has no idea how to figure out that it's related to any of those things and shouldn't have to care.

Re: Won't happen in my lifetime

Muppet Boss

I fully support.

Not only that but the original IPv6 developers did not see the need for enterprise multihoming, until 2009 there simply was no equivalent of IPv4 PI (Provider Independent) address blocks. Combined with how painful public DNS change propagation was back then, IPv6 at the time could not provide network-level disaster recovery and was a huge ISP lock-in. Also, by the time IPV6 was well supported in hardware, exposing the internal network to the Internet was no longer in vogue. So migration to IPv6 was simply not worth the effort.

Nowadays IPv6 is mostly on par with IPv4 feature-wise (if one is good at remembering very long numbers). It also means that running dual-stack in the internal network does not make any sense, while implementing and operating IPv4 is still much more simple. For the Internet-facing services dual-stack is fine to maximize reachability.

One of the main arguments was about IPv6 faster to switch in hardware, well IPv4 is still switched just fine and SDNs are happy to hear that.

Anonymous Coward

Why would networking be the exception? The tech world is full of examples of great solutions failing while terrible ones prosper. Python and Java are great examples, Windows and MacOS too, x86 just won't die, the list goes on. The problem is the people in tech, not the tech. Look at the way cloud architectures have devolved from scalable, self managing beauty to essentially a more expensive on-prem design with firewalls and network appliances to manage.

Let's be honest though, it's not just tech people, it's people. In a global pandemic you still see a majority not washing their hands after using a public toilet. We deserve everything we get.

Rich 2

“… The tech world is full of examples of great solutions failing while terrible ones prosper. Python and Java are great examples”

Sorry - between Python and Java, I’m struggling to see which one is “great” :-)

re: In a global pandemic

Anonymous Coward

almost two years in and people have still not worked out that a face mask is supposed to cover the mouth AND the nose. Sigh. I guess it is too late now. Many of those who refused are probably no longer with us.

Re: re: In a global pandemic

TRT

And there we have the dual-stack conundrum.

NAT is telling us something important

steelpillow

NAT is not just the darling of mobile telco gateways. Clouds love it too, for example Microsoft has begun peddling Vnet NAT for Azure because it "simplifies outbound Internet connectivity for virtual networks". This appears to be telling us that NAT is fulfilling some important additional network function that we cannot live without.

So why not roll NAT up into the IP standard? There was a time when I could phone a colleague by dialling their full ISDN phone number followed by their extension, all in a single frenzy of button-pushing, and then wait for the connection to worm its way through. The system was left to worry about which numbers were to be processed by which switches. Do the same with IP/NAT. Call it CIP (cascading IP) or XNAT (eXtensible NAT) or something like that, or just IPv10.

IPv6 is actually there in the home user worls

Milliped

Looking at the anonymous edits at Wikipedia, more than half comes from IPv6 addresses, see here https://en.wikipedia.org/wiki/Special:RecentChanges?userExpLevel=unregistered&hidebots=1&hidecategorization=1&hideWikibase=1&limit=500&days=7&urlversion=2

IPv6

Crypto Monad

"solving IPv4's undeniable routing, addressing, security and performance problems at the unprecedented scale it was being asked to support."

That's a tired and incorrect statement. IPv6 did none of that, apart from the longer addresses.

Routing? There was an original hare-brained idea to allocate addresses for "tier 1" and "tier 2" ISPs in a way that would reduce the number of core routes. It was never going to work because it did not acknowledge the commercial realities of how networks interconnect and the financial relationships between them, and hence it was binned early on.

Security? IPv6 mandated that devices must be "IPSEC capable". This doesn't change the fact that (a) IPv4 devices can be "IPSEC capable" too, and (b) without a keying infrastructure, it's never used.

Performance? The removal of IP fragmentation is the only thing I can see that might possibly go in that direction, but IPv4 stacks all implement PMTU these days anyway. Otherwise, the larger headers of IPv6 give a small (~2%) performance degradation in normal use, compared to IPv4.

IPv6 didn't solve any of the IPv4 problems that needed fixing, like multi-homing: every BGP multi-homed network still appears as a separate route in the global routing tables.

IPv6 also needlessly changed a bunch of things that didn't need changing. Replacing ARP with NDP? Replacing DHCP with SLAAC? These were ideas from academics. They didn't realise the privacy implications of SLAAC, so then had to invent randomly-changing privacy addresses. In the real world, there are good reasons why networks need DHCP, and so DHCPv6 came along, meaning we now have two different ways of assigning addresses (except Android [1]still doesn't implement DHCPv6 ).

But the biggest problem is the lack of interoperability. If you can't build an IPv6 network and see the whole world of IPv4 content, this means you have to build an IPv4 network as well (i.e. dual stack). In that case, it's cheaper and simpler to build and manage an IPv4-only network, so that's what most people do.

Ultimately, we still really could use the longer addresses, and the pain is felt acutely at the side of access ISPs (those who provide end-user connections). But the pain isn't felt at the content provider side: they've been sharing IPv4 addresses for years, via virtual hosting, reverse proxies, and CDNs.

The sad thing is, content providers *could* make their content available over IPv6 with little effort. However many can't be bothered, because the whole world can view their content via IPv4 anyway. That is: all eyeballs are either IPv4-only or IPv4+IPv6 dual stack.

The one thing that might push this is if and when China goes IPv6 single-stack: content providers will lose a large chunk of their global audience if they don't keep up. OTOH, by that point, China might not be trading with the rest of the world anyway.

[1] https://issuetracker.google.com/issues/36949085?pli=1

fnusnu

The thing is that whatever you need to do with IPv4 you can do it either in your head or on a piece of paper. I can look at an IP address and know it belongs to my organisation. Heck, I can likely even tell you which building's VLAN it belongs to. With IPv6? Not a chance.

Can't disagree with anything there

David Austin

IPv6 works (well, assuming you have no vendor bugs and a helpful ISP to hand), and does solve all the technical hurdles it was meant to.

The problem is it very much looks like it was developed in a lab by very clever people under perfect network conditions, with scant regard to how people do things in the real world due to a lack of knowledge, budget constraints, or complete apathy.

Compared to the simpler, backwards compatible option of dropping a few extra octets onto IPv4 to solve the address shortage, it may be a case that IPv6 let perfect be the enemy of good.

No-one's arguing IPv6 won't eventually be the dominant protocol: We're too far down that road, and too much has been invested into it, and again, it does actually work and solve these issues. But until you *Have* to use it, you may as well plod on with IPv4 which can do everything you need it to, and let the bleeding edge companies (And server to server traffic) work out the kinks for you, then worry and spend on it when you need to.

I've tried on and off every few years to get a Dual Stack link to the outside world on my home network; every time, I got so far down that path before hitting a roadblock (Flaky ISP Support, router support, router bugs, [1]Happy Eyeball issues), before stopping and seeing I'd be spending a lot of time and money to make things technically better, but not letting me do anything new, and shelving the attempt again.

[1] https://en.wikipedia.org/wiki/Happy_Eyeballs

Re: Can't disagree with anything there

Fred Daggy

Point of order guv. Any adjustment to the IPv4 addressing involves needing a new IPvWhatever stack. Just no additional space to pad out the addresses.

But yeah, point well made about the perfect being the enemy of the good. The time to nip Ipv4 in the bud was much earlier on, 4 billion (theoretical) addresses and the usable ones nearly full? Too much inertia now.

Give up

Starace

All these years later and they're still arguing and trying to get people to use it. Yet even shiny new stuff mostly ignores it.

They built a solution that's too complex to use and aims for a utopian ideal of all those billions of devices existing in a nice flat world where everything is individually addressable - and we know that isn't how the world works and never will be.

It might be antique but IPv4 is good enough and it works so it'll stay for most things forever.

Fred Daggy

Free rein to the marketing department only ever leads to disaster. This is a self-evident truth.

Similarly, free rein to the engineers can lead to disaster. IPv6 is the evidence that it can happen.

Both need someone from the real world to ask the important "What if?" and "Why?" and "are you a f*çXing idiot?" questions.

"Well, they don't. "

LDS

Actually, only the incumbents don't - mostly, the old telephone companies. Those who could request millions of IPs in the early days of the Internet, and have enough IPv4 for their needs.

Newer one may have not enough. When Sky (Comcast) entered the ISP market here in Italy, it had to borrow IPv4 from Sky UK to start, now they have been returned, some have been bought from India - but the network is being run as a native IPv6 one using MAP-T to allow IPv4 connectivity, there was little choice.

Vodafone Italia is activating CG-NAT to users because it has no longer enough IPv4 available - even using local NAT. Rumors say it will be forced to roll out IPv6 soon. Only TIM and Wind3 (born from the merger of Wind and H3G) have enough IPv4 available - and will try to exploit that "treasure" as much as they can.

All new entries here have to resort too to some form of CG-NAT - with all the downsides for users - to allow IPv4 connectivity. RIPE no longer assigns blocks large enough, and buying them on the market is expensive.

Even users start to feel the downsides of NATs - especially CG-NAT - as other services that aren't NAT friendly at all expand, not only gamers, but for example as VoIP becomes more common, and you may not want to use the ISP service only, and its CPE.

The only real downside of IPv6 roll outs is most IPv6 are doing it the very wrong way. /64 prefixes, dynamic prefixes, CPE that can't perform prefix delegation even when larger prefix are assigned. All of that will make customers' "network lives" miserable when they find they can't create subnets and/or assign static IPs without resorting to ugly workarounds.

Moslty because ISPs graybeards can't update their skills and reconfigure devices correctly.

Anonymous Coward

The "unreadability" of IPv6 addresses is greatly over-exaggerated. I did many years of third-line IPv6 support and, in the end, found the addressing no harder to handle (read/track/correlate)than IPv4. Of course, there is a period of adaptation. As for the wonders of NAT well ...

IPv6. Threatens current business so there is no rush

Anonymous Coward

IPV6 does make a difference since so many providers phone companies and also fibre ISP like Hyperoptic hide their users behind CGNAT which means home and business devices cannot be reached from the internet with IPv4. An annoying "security feature". Pay for IPv4 fixed does not do much when the better option is free.

IPv6 fixed routable IPs ranges are allocated direct to the router. Once set pinholes on the router we can have multiple devices using the same port. Many servers running https. Magic. Impossible with IPv4.

So with IPv6 we don't have to pay for a fixed IP or for an IP outside CGNAT to be reachable.

Use the IPv6. if you have to use IPv4 it is easy to map IPv4 address to a IPv6 with the SOCAT command running on an external machine, but back to just one port available.

I suspect there is rush for IPv6 as its adoption could destroy too many business models if every man and his dog can run their own servers with their 1GB fibre connections or contribute to distributed networks solutions and even earn a little from their spare internet capacity.

Gerry

Employees and their families are not eligible.