back
61 comments
(CG)NAT can been a real cost to ISPs, especially smaller ones:

> Our [American Indian] tribal network started out IPv6, but soon learned we had to somehow support IPv4 only traffic. It took almost 11 months in order to get a small amount of IPv4 addresses allocated for this use. In fact there were only enough addresses to cover maybe 1% of population. So we were forced to create a very expensive proxy/translation server in order to support this traffic.

> We learned a very expensive lesson. 71% of the IPv4 traffic we were supporting was from ROKU devices. 9% coming from DishNetwork & DirectTV satellite tuners, 11% from HomeSecurity cameras and systems, and remaining 9% we replaced extremely outdated Point of Sale(POS) equipment. So we cut ROKU some slack three years ago by spending a little over $300k just to support their devices.

* https://community.roku.com/t5/Features-settings-updates/It-s...

* Discussion: https://news.ycombinator.com/item?id=35047624

This sounds like incompetence. You can procure IPv4 addresses in days as a monthly rental (go speak to Cogent etc), or even buy outright with little delay. Going rate is currently $34/address at the /24 level and cheaper for larger blocks.
This sounds like a great sob story but it's more like "people who aren't competent to run an ISP attempted to cut corners and encountered the inevitable consequences".
> "people who aren't competent to run an ISP attempted

Or it was people who weren't going to be served by commercial companies tried to help their community as best they could on a shoestring budget, with minimal funding, in a non-profit fashion.

Wow, that's pretty extreme. Maybe we can land somewhere in the middle here?

If you're trying to do an ISP on a budget, IPv4 makes things harder.

Can you please explain why you believe this?
Any network engineer worth their salt knows that ivp6-only connectivity is going to be flaky, which is why basically nobody does ivp6-only. Even bottom-of-the-barrel VPS providers selling ipv6-only servers for $15/year provides CGNAT for ivp4. An ISP charging presumably an order of magnitude more should be expected to be more competent than that.

The fact that they did try to go ipv6-only (ie. "cutting corners") shows that the people involved were blamed were incompetent.

> (CG)NAT can been a real cost to ISPs, especially smaller ones

Which is a perfect incentive for incumbent ISPs to delay and stall IPv6 rollout as much as possible to ruin the day of any would-be competitor.

Although some of the earlier adopters of IPv6 are the biggest ISPs, as their networks are so big that IPv6 actually simplifies their network management. In the US, Comcast was an early adopter and globally the mobile networks have been as well.
It really isn't. As the parent commenter mentioned, most of the ipv4 traffic comes from non-ISPs, which makes sense given that basically nobody uses p2p given how much of a pain NAT traversal is. Maybe there's a point that ISPs are the last holdouts, we're nowhere close to that yet.
It's really fun when your ISP starts using CG-NAT as a security feature in marketing. You ask them for a static IP and they have you sign an agreement that you won't be getting the BENEFITS of their CUSTOMER FIREWALL. Yeah ok, so if that's the language around this then we're just screwed aren't we? And you also can't tell me when you're planning to support IPv6 of course.
>they have you sign an agreement that you won't be getting the BENEFITS of their CUSTOMER FIREWALL

Sounds like the legal department didn't want them to get sued for "negligence" or whatever when some customer exposes their windows server 2008 installation to the internet and promptly gets hacked.

The way local ISPs talk IPv6 is the expensive support item and don't bother with it. They both run CGNAT too.
Eh? CGNAT is purely a cost saving measure. I have no idea who would try and run a pure IPv6 network for (i assume given Roku etc) home use and then get mad that some stuff doesn't support IPv4.

The 71% is almost certainly because Roku consumes a lot more bandwidth doing video streaming than the other services. Even if Roku did support it I'm sure the users wouldn't be happy that xx% of the web was unreachable.

CGNAT is cheaper than acquiring additional IPv4 addresses, but it is more expensive than the same traffic going over IPv6.
kind of a linguistic tangent do we say american european or american british or is that taboo?
"American Indian" is fairly standard nomenclature:

* https://en.wikipedia.org/wiki/Native_Americans_in_the_United...

Typically if you want to indicate that somebody is an immigrant in the US, you put the country of origin in the front. British-American or European-American would be ok I guess.

I guess an American-British would be somebody who immigrated to GB from the US in that convention, but actually I’m not sure what convention they use over there.

Anyway in this case they aren’t talking about anybody who’s immigrated at all so it is pretty much unrelated.

The nationality of ancestors is not very relevant to most Europeans, mostly because we're the native people of the continent.

People with multiple nationalities or who grew up in a different country than their nationality very often describe themselves in terms of a single nationality, often the place they spent most of their childhood. "I'm Argentinian" "Oh, was it difficult to get a visa to come here?" "Well, I have an Italian passport because of my mother."

Americans describing themselves as British-American or whatever seems strange to us, since we can recognize typical British people but aren't seeing any of it in the American.

Euro American most likely would be the correct terminology, sort of whatever rolls off the tongue better. A lot of non-Hispanic white Americans are actually not British, but are instead a broad mix of European countries that varies depending on geography (e.g. Louisiana is very French).

Even nailing it down to XYZ country in Europe is a bit of a stretch, as the European genepool isn't the most diverse thing in the world.

colonial american?
Tailscale's "How NAT traversal works" blog is a fascinating read:

https://tailscale.com/blog/how-nat-traversal-works

Google IPv6 traffic hit an all-time high this week: https://www.google.com/intl/en/ipv6/statistics.html
Judging by the weekly cycle having IPv6 at work is more rare than home (weekends are when IPv6 traffic hits its peaks).
Several major ISPs in the US rolled out IPv6 years ago, as did some of the big cell phone companies. US businesses generally have enough IPv4 addresses for their needs (though probably running NAT and considering the issues part of their firewall policy). As such there is an uptick on weekends and most people have no clue what is going on down in the bottom (which is a good thing - the average person shouldn't care about anything below OSI layer 7 - their application).
Yep, at home it's enabled automatically by the ISPs, at work, admins have to turn it on and that means extra work for them.
And still below 50%.

My personal benchmark: hotels. I have not seen a _single_ hotel that provides IPv6 on their WiFi. And I made a habit of checking this every time I check in.

And I've seen a hotel that was giving out public IPv4 addresses (in Mountain View, CA).

> And still below 50%.

Depends on the country. US>50%; FR>80%:

* https://www.google.com/intl/en/ipv6/statistics.html#tab=per-...

> I have not seen a _single_ hotel that provides IPv6 on their WiFi.

Currently staying at a Hilton hotel in Tucson, Arizona that has IPv6. I only checked because of the submission about ipv6.me yesterday [0].

[0] https://news.ycombinator.com/item?id=43256298

I'm not there at the moment, but I definitely took note of having an ipv6 address displayed on https://ip6.me/home.cgi

Trending up at about 2-5% every year, so about to cross the threshold within the next few years. We're in the middle of the S curve.
Got IPv6 over wifi in a hotel in Costa Rica, really nice.
I honestly can't tell if this is sarcastic. Just 30 more years to go right?
The article tries to label something objectively good as something bad:

>>One practical outcome is that government agencies find it harder to identify criminals behind particular IPv4 addresses.

lol, lmao even.

>>As a result, the agency says, investigations often involve examining and tapping the connections of many more people than really necessary.

just incompetence abound, the police should suffer if they don't know how to do their job more effectively

Most ISPs likely have logs of all of the clients who were behind a specific external IP anyway.
One practical outcome is that IPv4 provides the privacy IPv6 was designed to sabotage.

I'll be boycotting IPv6 for as long as it's possible.

>One practical outcome is that IPv4 provides the privacy IPv6 was designed to sabotage.

Well, that only applies if you think ISPs don't log your CGNAT sessions.

Exactly. Even if you enable "privacy addresses", you'll be disappointed to find that they only rotate every 24 hours by default, so all your incognito tab browsing can be trivially linked back to you, if they're done in the same day as your regular browsing.
Requiring web services and ISPs to retain detailed logs in perpetuity until IPv6 is universal would be one way to expedite the transition.

But personally I don't think IPv6 is ever going to happen. There's simply too little monetary incentive for supporting it. For outbound connections NAT/CGNAT works fine. For inbound connections you can use SNI routing with a tunnel[0].

[0]: https://github.com/anderspitman/awesome-tunneling

> But personally I don't think IPv6 is ever going to happen.

If you own a mobile phone you use it every day. IPv6 has already happened.

> There's simply too little monetary incentive for supporting it.

IPv6 allocations are orders of magnitude cheaper and wider than v4 allocations, which are already exhausted.

> For outbound connections NAT/CGNAT works fine. For inbound connections you can use SNI routing with a tunnel[0].

All of these add latency, IPv6 reduces latency (particularly the more widely it is deployed).

> IPv6 allocations are orders of magnitude cheaper and wider than v4 allocations, which are already exhausted.

Which is of no consequence to the incumbents who have enough existing stock to last them forever (with tricks like CGNAT/etc). The cost of IPv4s mostly impacts smaller players and/or new entrants, which works in favor of the incumbent ISPs.

> But personally I don't think IPv6 is ever going to happen.

Weird. I've had "native" IPv6 service continuously since... 2004? 2006? and IPv6 via a 6to4 tunnel that terminated in Hurricane Electric's network since two years before that.

Bonus: I discovered recently that the Zoom teleconferencing software works just fine if you have only IPv6 connectivity.

Is there stuff that's IPv4-only? Sure. But IPv4 doesn't need to be shut down for IPv6 to have happened (and have been happening for a long time now).

It's still growing fairly steadily, but I do feel like the need for it has been diminished. P2P software doesn't really exist for the mainstream anymore. Directly connecting between two end user computers without a server doesn't really happen much like it used to.

CGNAT still causes issues for long lived connections though. Things like SSH will get cut off.

It would happen much quicker if governments mandated IPv6 for all new connections.
My ISP, Metronet, is mostly CGNAT. That broke some things for me, so I called in and they gave me a "free" static IP to fix it. Except, once per year they start charging me for it and I have to call back, and then they make it free again.
Wait, with OpenDNS you can change settings for everyone on an IP address just by connecting from the that same IP address? That seems horribly insecure.
CGNAT providers are not ISPs. They're web service providers, WSP.
"CGNAT providers" is like saying "DHCP providers" or "PPPoE providers". I've never heard of a "WSP". What if I send an email on port 25 (not web) via my "WSP"? LOL.
In true Hacker News nerd style, an utterly meaningless, inconsequential, made-up squabbling over terminology.
Not to mention incorrect.