Tweaks to IPv4 could free up 'hundreds of millions of addresses'
- Reference: 1654099633
- News link: https://www.theregister.co.uk/2022/06/01/ipv4_proposed_changes/
- Source link:
While the world is still slowly moving towards [1]broader adoption of the newer IPv6 protocol , which offers a vast address space, the widespread continued use of IPv4 has caused problems because all available ranges of the roughly 4.3 billion addresses it supports have [2]largely been allocated .
Now it seems that Seth Schoen, formerly a senior staff technologist at the Electronic Frontier Foundation and co-founder of Let's Encrypt, has made proposals collectively labelled either the IPv4 Unicast Extensions Project or the IPv4 Cleanup Project (both are used on the [3]project's GitHub page ).
[4]
Writing in a post on the [5]APNIC blog , Schoen detailed his proposals.
[6]
[7]
These are also outlined in four Internet Drafts filed with the Internet Engineering Task Force (IETF), which call for four categories of "special" addresses that are currently unavailable for standard addressing purposes to be redefined as ordinary unicast addresses, meaning they should no longer be regarded as reserved, invalid, or loopback addresses.
The reasons for the existence of these special addresses go back to the creation of the IPv4 version of the Internet Protocol in the early 1980s, but many of them have never been used for the purpose that they were reserved for, according to Schoen, yet have continued to be treated as special addresses.
[8]
Those four categories of addresses that the project is aiming at comprise the lowest address in each IPv4 subnet, 240/4, 0/8 and 127/8. Each was reserved for a different reason, and Schoen acknowledges that each one presents a different set of challenges to change.
Of the four, the [9]lowest address fix is regarded as the least problematic. It proposes eliminating a duplicate broadcast address within each local network segment.
The standard broadcast address on a subnet is the highest one (i.e. 255 on a 24-bit subnet which uses 8 bits for the host addresses), but for historical reasons the "zeroth" address (i.e. 0) is also reserved, according to Schoen.
[10]
Changing this only frees up a single address per subnet, but allows organizations to "take a small step to unilaterally increase the efficiency of their use of their existing IPv4 allocations."
The other changes require code-level changes in IPv4 stack implementations, which will no doubt set alarm bells ringing among any IT admin staff out there along with network software engineers.
However, Schoen claims that some of these changes are in widespread use already, particularly the [11]proposed changes for the 240/4 addresses that were reserved as a future-use Class E network block, comprising a total of 256 million addresses.
Changing these into recognized unicast addresses was previously proposed to the IETF more than a decade ago and apparently implemented in several operating systems now running in millions of nodes on the internet, and "has not caused any problems over the past decade," he states.
The [12]0/8 address range comprises another 16 million addresses that were reserved for potential device auto configuration based around ICMP messages, but these are effectively unused (apart from 0.0.0.0).
[13]China again signals desire to shape IPv6 standards
[14]Big Tech shrank the internet while growing its own power
[15]How legacy IPv6 addresses can spoil your network privacy
[16]Microsoft Azure DevOps revives TLS 1.0/1.1 with rollback
[17]FreeDOS puts out first new version in six years
[18]IPv6 is built to be better, but that's not the route to success
Likewise, 127/8 represents another 16 million address block that was reserved as loopback addresses, and this is maintained despite the fact that virtually all applications use only a single loopback address (127.0.0.1).
These addresses will gradually become more useful as more implementations accept them as valid address space
[19]Schoen's proposal is to reduce the range of this block so that only 127.0/16 is reserved for local loopback purposes.
Whether these changes are really necessary is debatable, since many organizations that are still using IPv4 will be sitting behind a network address translation (NAT) gateway that presents a small number of IP addresses to the outside world and operates a private addressing scheme on the internal network.
Nevertheless, Schoen believes that these measures will prove useful during the drawn-out IPv4 to IPv6 transition, if there continues to be demand for IPv4 space.
"We are continuing to encourage implementers to make the required changes, and developing software patches to support them. These addresses will gradually become more useful as more implementations accept them as valid address space," he wrote.
The proposals have already met some understandable resistance.
"Testing and changing all devices that know that 240/8, 0/8, and 127/8, etc, are 'special' is a bigger job than making them just use IPv6," [20]tweeted Adrian Kennard, who runs UK ISP Andrews & Arnold. "The 0 address being usable probably only helps local networks." ®
Get our [21]Tech Resources
[1] https://www.theregister.com/2020/06/05/ipv4_v_ipv6/
[2] https://www.theregister.com/2019/11/25/ipv4_addresses_gone/
[3] https://github.com/schoen/unicast-extensions
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YpfhgTtWXWEw83pdpvSRDAAAAE0&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[5] https://blog.apnic.net/2022/05/31/cutting-down-on-ip-address-waste/
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YpfhgTtWXWEw83pdpvSRDAAAAE0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YpfhgTtWXWEw83pdpvSRDAAAAE0&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YpfhgTtWXWEw83pdpvSRDAAAAE0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[9] https://datatracker.ietf.org/doc/draft-schoen-intarea-unicast-lowest-address/
[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/networks&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YpfhgTtWXWEw83pdpvSRDAAAAE0&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[11] https://datatracker.ietf.org/doc/draft-schoen-intarea-unicast-240/
[12] https://datatracker.ietf.org/doc/draft-schoen-intarea-unicast-0/
[13] https://www.theregister.com/2022/04/26/china_ipv6_plan/
[14] https://www.theregister.com/2022/05/11/internet_has_shrunk/
[15] https://www.theregister.com/2022/03/22/legacy_ipv6_addressing_standard_enables/
[16] https://www.theregister.com/2022/03/15/microsoft_azure_tls/
[17] https://www.theregister.com/2022/02/23/freedos_13/
[18] https://www.theregister.com/2022/01/24/opinion_column_ipv6/
[19] https://datatracker.ietf.org/doc/draft-schoen-intarea-unicast-127/
[20] https://twitter.com/TheRealRevK/status/1532033651650830339
[21] https://whitepapers.theregister.com/
I think you're opening a big can of worms there with the ol' first Vs last address for your gateway.
I'll just get a fresh box of popcorn and enjoy the show.
I’ll bite
You can use any address in the subnet as the gateway.
Doesn’t have to be the first or the last.
I agree that .0 would be useful as a vip or gateway address.
It grates me seeing the first few numbers of the last octet as interface IP’s then the vip address, why not just make the vip the first or the last then you can add other ha IP’s if needed perhaps when migrating?
/31
/31s allow for this on point to point links.
Understand your suggestion/query of course.
If you use a netmask smaller than /24, you can already use .0 if that's esthetically more pleasing to you.
Eg, 192.168.1.0/23 is a valid, usable IP address.
I can see the pros with the 0/8 & 240/4, but the reduction of 127/8 to a /16 could cause problems: I've seen systems configured with 127.1.x.x on their loopback interface.
(No, I'm not going to get into the debate about IPv6. Yes, I have configured systems to use IPv6 so don't try and accuse me of being a luddite)
0/8 no way
A long time ago I worked at a location that had a B class address x.255.0.0. Solaris would not accept that as a valid address for the first few releases, you had to tell the installer the address was x.254.y.z and fix it up after the install was complete. I doubt that was the only such case, just the only one I was aware of. Now multiply that a thousand fold because there is no way there aren't a bunch of GUIs that won't take '0' as the first octet, not to mention a bunch of TCP/IP stacks that treat any 0/8 via some sort of special case.
Not worth the hassle when using 240/4 sounds easy and is 15x larger (not 16x, because 255/8 has the same problem)
The idea is to have something you can use immediately, not only those running the right sort of software.
"We are continuing to encourage implementers to make the required changes, and developing software patches to support them. These addresses will gradually become more useful as more implementations accept them as valid address space," he wrote.
I think the author might be missing the point that IPv4 isn't going away any time soon because there's a shitload of stuff that only understands IPv4 and is never going to be updated .
So it needs to live in an environment with a gateway…
IPv4 really shouldn’t be required online any more.
If your ISP router would support IPv6 then you can run whatever you like internally, and still present as IPv6 to the rest of the world.
Honest question - how much of the non domestic internet can’t handle IPv6 for public communications?
Virgin Media home routers don't know what IPv6 is. They only do IPv4.
So pick an ISP that isn't living in the stone age. Even BT can do IPv6 for fuck's sake - why not Beardie net?
Unfortunately, I think a lot of smaller ISPs (for example SONIC) do not support IPv6 natively. I agree that it would be great if they did, but SONIC is focusing on building out their fiber optic capability instead, which I suspect is a more profitable endeavor for them than trying to get IPv6 working right. I, for one, would love to see it, but the project seems to have been put on indefinite hold.
Most carriers support it; backbone providers etc. But most ISPs - in the UK at least - who provide the last mile. BT, Virgin and EE are three, and they probably cover 80% of the domestic endpoints. I know you asked about non-domestic but the reality is that most users and probably most SMEs use domestic-class connections.
Used to get IPv6 on the work and personal mobiles, which was handy for testing out an IPv6 tunnel on the broadband but noticed a while back that both had quietly dropped it and now only get a 10.x.x.x. I can only guess that CGNAT must be cheaper that IPv6. Pity.
For your ipv6 router to route ipv4 it’ll be seen as a security risk as it’ll effectively have to either tunnel your ipv4 traffic to some end point you don’t control and NAT it like in cgnat or it’ll have to rewrite the ipv4 packet to be ipv6 and all the checksums and ssl security will be off so to do it properly it’ll effectively be a proxy and able to read all your encrypted coms.
Far easier for VM or any other isp to keep their nose out and just relay the packets as undisturbed as possible.
"and is never going to be updated"
This is the point made at the end of the article. If you tell programmers for 40 years that .0 is reserved (and can be used to identify a network) then they will build that into their code. Likewise with 0/8 and 127/8. I've certainly written code that classifies addresses as multicast or node-scope based on the numbering. In fact, I'm not aware of any other way to perform such a classification, so I'm not even sorry.
Conversely, I think you might be missing the point that the number of devices that can /only/ support IPv4 is small, and not growing.
It's rather unlikely their number has any relevance today.
?
So I guess the question isn't whether this should be done or not, but rather - who would get these new addresses? Are they going to auction them off like they do radio spectrum? If so, won't they just wind up getting hoovered up by the deep-pocketed likes of Microsoft, IBM, Verizon, etc, etc, for their own internal use, and won't do the rest of us Internetians any good?
Re: ?
Why would they need more addresses for internal use, when they have the whole 10.x.x.x space, and can re-use ranges of that over and over again for stuff that's internally internal (i.e. doesn't need to communicate with everything on their internal network)
They might not be grabbed by Microsoft or Verizon, but they would be grabbed in the west - when it is Asia and Africa that got shortchanged in the initial allocation and are most in shortage now (but to be fair, are also much further along the IPv6 path than we are for that very reason)
"Why would they need more addresses for internal use"
Cloud.
Re: ?
Sorry, I didn't mean "internal" as in private IPs, I meant it more as they'll use them in their public-accessible products, clouds, etc, instead of these refurbished addresses being used to help "the Internet" in general.
Re: ?
Worked on an as-a-service project a few years ago, where thanks to having to allocate multiple subnets at design time (and before launching too, so no idea just how big the subnets would really have to be, or how many we would actually sell) the 10.x.x.x space wasn't big enough.
Also brought home just how wasteful IPv4 subnetting really is, and how inflexible a lot of networky things are. For home use I have an entire IPv6 /48 just for fun, and I can't afford the 'leccy bill to use even a tiny percent of that. Even assuming I could get a gazillion RPi's in the first place.
Party Line
When I were a nipper the family telephone line was a party line, shared with the house next door. I mean it's just an idea that I'm putting out there, but, shared IPv4 addresses anybody? You know, just for the lowly plebs you understand, nuffin important like. No?
Re: Party Line
Mobile carriers (at least in my neck of the woods) already heavily use NAT... I wonder if residential cable could use NAT a lot more heavily as well. Each neighborhood gets a single IPv4... and if you want to do something unsupported like a run a server with an open port, pay an extra ten bucks/mo to get your own IP.
Re: Party Line
Webservers, offices, houses etc already share IP's.
Re: Party Line
That already exists, and is called CGNAT (carrier grade NAT). Lowly plebs get an IP from the range 100.64.0.0/10 (analogous to the ring pattern on a party line) while the external address is from the carrier's pool.
Re: Party Line
And it works, but it's impossibly to host anything. Great for Joe Public, but probably not for most of the readers of this website.
If you can't upgrade...
If you have old crud that can't upgrade to IPv6, how are you going to upgrade the IPv4 allocations? Think of all the hardcoded subnets in firewall rules, routing rules, and configuration wizards. It's in your old network hardware, your old OS, and your old apps.
It makes NAT or IPv6 look easy by comparison.
far beyond stupid
This idea is bat-shit crazy.
There's an unknown but significant installed base that cannot properly handle these "special" /8s. There's next to no chance of fixing those elderly and unsupported/unmaintained protocol stacks.
Even if these backwards compatibility issues could be addressed (excuse the pun), freeing up those three /8s will be an utter waste of time. In the last 3-4 years of IPv4 distribution, the Internet went through 1 /8 of v4 every month or theresabouts. If these three /8s could be made available now - how? - they'd be used up by September. And probably a lot sooner than because the address brokers and speculators will surely snaffle them up.
Stop fucking about with the dregs of IPv4. There's no point. Any effort wasted on that is better spent getting IPv6 deployed.
...slowly moving towards broader adoption of the newer IPv6 protocol...
That's being generous. If it weren't for global warming the adoption would be being caught and overtaken by glaciers.
I'm willing to bet my house that I'll not see it overtake IPv4 during my lifetime, and I'm only aged 49.999999.
I still have a single C class
I got almost 30 years ago.
I've watched the value slowly increase over time, last I checked I could probably get about $5000 for it. I keep waiting figuring it can only go up in value. Adding a bunch of new IPv4 space would probably depress that value but it would probably also depress momentum towards eliminating IPv4 so in the long run it might make my class C even more valuable lol!
Re: I still have a single C class
Would you be willing to trade it for my apes? Their value is skyrocketing!
Somebody's talking bollocks
The article says "a new initiative has been proposed that could free up hundreds of millions of addresses that are currently unused". But it only mentions 3 /8s. Which can't easily be brought into use. 3 /8s is ~48M IPv4 addresses. Which is quite a lot less than hundreds of millions.
BTW if there were hundreds of millions of IPv4 addresses going spare, somebody would have figured out how to distribute them by now. They haven't. That's because there's next to no IPv4 space left to allocate. It's almost all gone.
Re: Somebody's talking bollocks
No, "Class E" is a /4. So it's about 256M - which looks a lot maybe for a single RIR (but APNIC) - but if you start to allocate pieces of it to each RIR, they don't look so many after all. And cloud providers would probably go after them immediately...
Also while computer OS might take those addresses without issues - the problem is network devices which may have embedded OS far pickier.
Re: Somebody's talking bollocks
The US DoD owns a huge block of addresses.
Incidentally, I've been watching IPv6 touted as the 'new thing' for well over 20 years now. Its adoption has been fairly glacial because its really unwieldy to use, its what I'd term 'inelegant'. Maybe what we should come up with is IPv5, something with a larger address space (but not so ludicrously large as v6) and without all the extra bells and whistles that v6 brought that never really got implemented.
(v6 for me breaks one of the most important rules, one that this article touches on. Don't go around subdividing spaces by address blocks in anticipation of some future development. A number's a number so apart from one or two widely known and used constants all addresses should be equivalent, we're long past the point where a /8 and /24 could take advantage of different processing paths.)
Re: Somebody's talking bollocks
IPv5 has been and gone. As have IPv7, IPv8 and IPv9. At this rate it won't be long before we have to start doing NAT for the Protocol Version Header
https://en.wikipedia.org/wiki/List_of_IP_version_numbers
I'd love to be able to use the .0 in a subnet as a default gateway! I hate having to either choose .1 (so my actual hosts start from .2) or .254 (YUK)