#IPv4only

Kevin Karhan :verified:kkarhan@infosec.space
2025-04-25

@landley @jschauma @ryanc @0xabad1dea yeah, the exhaustion problem would've been shoved back with a #64bit or sufficiently delayed by a 40bit number.

Unless we also hate #NAT and expect every device to have a unique static #IP (which is a #privacy nightmare at best that "#PrivacyExtensions" barely fixed.)

  • I mean they could've also gone the #DECnet approach and use the #EUI48 / #MAC-Address (or #EUI64) as static addressing system, but that would've made #vendors and not #ISPs the powerful forces of allocation. (Similar to how technically the #ICCID dictates #GSM / #4G / #5G access and not the #IMEI unless places like Australia ban imported devices.

I guess using a #128bit address space was inspired by #ZFS doing the same before, as the folks who designed both wanted to design a solution that clearly will outlive them (way harder than COBOL has outlived Grace Hopper)...

If I was @BNetzA I would've mandated #DualStack and banned #CGNAT (or at least the use of CGNAT in #RFC1918 address spaces) as well as #DualStackLite!

Kevin Karhan :verified:kkarhan@infosec.space
2025-04-21

@shoppingtonz @alternativeto @torproject also every #Tunneling - regardless if #SSH or #VPN or whatever - will inevitably introduce #latency (unless you happen to be customer of a shitty #ISP with horrible #peering and thus can cut down on hops needed, which is AFAIK only a theoretical scenario)...

In fact I stopped using #HEnet #Tunnelbroker and #IPv6-#GIF-Tunneling because it created more issued than it solved on my #IPv4only #Internet connection…

2025-04-08

Configuring an #unbound DNS Server I learned that it has a #NAT64 mode.

Saved me from having to configure this server dual stacked to reach #IPv4only authoritative nameserver.

Looking at you @ZDF!

#IPv6

#HowIPv6HelpedMeThisWeek

Kevin Karhan :verified:kkarhan@infosec.space
2025-03-28

@neil my #ISP is #IPv4only and refuses to allocate me even a single /64 of #IPv6 but happily offers me another /28 of #IPv4's...

  • I wish I was kidding
Kevin Karhan :verified:kkarhan@infosec.space
2025-03-24

@fusl @mnalis @0xF21D

I do that with #pfSense & #OPNsense (depending on the exact network in question) and have it merge multiple sources that get cached.

In total, I do may out the 30 DNS servers and whilst I have #IPv4only, I have everything ready for #DualStack (#IPv4 + #IPv6) once my ISP stops keeing it's thumbs um their ass...

#sarcasm

Kevin Karhan :verified:kkarhan@infosec.space
2025-03-20

@fuchsiii @krzym Problen ist vorallem.dass der Anschluss #IPv4only ist!

Kevin Karhan :verified:kkarhan@infosec.space
2025-03-02

#WhatsMissing: A tool to check if #TorBridges are still available/online/reachable that one can use either #standalone (with #TorBrowser and/or #Tor Expert Bundle) or on @tails_live / @tails / #Tails.

  • Cuz I do run into issues and kinda want to sort #Bridges by availability so I don't waste time on a #TorBridge that is down and also thin-out the list of bridges that ain't online anymore.

Whilst I do acknowledge that @torproject do disrecommend having a huge list of Tor Bridges on hand, I do regularly need them for contacts who are behind a #GreatFirewall and can't #SSH-Tunnel out of it.

Espechally being able to filter for #IPv4only and not just #IPv6only is something I miss, alongside the filter for #PluggableTransports type as @guardianproject #Orbot seems to only handle #obfs4 and not webtunnel or #meek at all...

  • I'm pretty certain that merely pinging a bridge at it's port isn't working as a shure-fire way to check for it's availability.
Kevin Karhan :verified:kkarhan@infosec.space
2025-02-14

@xyno +9001%

@BNetzA should mandate a /64 of #IPv6 for every single #IPv4 if not a /56 - /48 as minimum for bigger allocations.

Kevin Karhan :verified:kkarhan@infosec.space
2025-02-11

@lucasmz ???

I can't see your profile. I'm stuck on an #IPv4only connection!

Kevin Karhan :verified:kkarhan@infosec.space
2024-12-07

@alyx I know, but since I am pissed about my #ISP in #Germany who's unwilling to assign me even a single /64 of #IPv6 whilst I have a whole /28 of #IPv4's and they'd gladly offer me more of those I do want to get regularoy action ( @BNetzA ) BEFORE I'd have to spin my own #ASN via @ripencc ...

Kevin Karhan :verified:kkarhan@infosec.space
2024-12-06

@disarray @alyx rn I can't blow money on @ripencc member fees and getting an #ASN online, so I'm stuck with my /28 and #IPv4only connectivity.

AFAIK #RIPE_NCC only offers /24 to existing ASes with #IPv6 connectivity...

Not The Wookiewook@infosec.exchange
2024-12-03

When you move to a small town you have to get small-town internet service. I consider myself lucky to have gotten 1Gig fiber to my home. If I'm honest, I don't have any need for IPv6. There's nothing you can get via v6 you can't get via v4. But still, makes me a little sad not to have gotten a prefix.

#ipv6 #ipv4only

2024-12-02

@gyptazy
These kind of switches are tempting but have the problem that management is mostly #IPv4only.

Do you have other experiences?

Kevin Karhan :verified:kkarhan@infosec.space
2024-11-09
Kevin Karhan :verified:kkarhan@infosec.space
2024-09-25

@goetz @fluepke @BNetzA sadly, #IPv6only would brick shit for me even worse than #IPv4only...

Kevin Karhan :verified:kkarhan@infosec.space
2024-09-24

@goetz @fluepke

#Fact is my #ISP won't even issue me a single /64 of #IPv6's but had no problem allocating me a whole /28 of #IPv4's...

And since they seem unwilling to even offer me a /64 (not even talking about a /48) I'm stuck on #IPv4only internet until I can afford the overhead of €500 p.a. just for a @RIPE_NCC membership, not even accounting for the cost of having to setup and maintain my own #ASN and acquiring a /24 of IPv4's + /48 of IPv6's...

If @BNetzA actually cared they'd mandate a #free /64 with every single IPv4 allocation.

Kevin Karhan :verified:kkarhan@infosec.space
2024-07-04

@baldur generally, #GeoIP and other #IP-based #Geolocation and #Geoblocking is just garbage.

I'm stuck on an #IPv4only conmection because my #ISP is unable and/or unwilling to provide proper #DualStack connectivity or even a /64 of #IPv6 (when in fact they could easily do a /48 if not /40 since they gave me a /28 of #IPv4's at no added cost).

  • And no, tunnelbroker.net doesn't work for me because then stuff will prefer IPv6 and a shitload of stuff does #GeoIP and then geoblocks me despite choosing the #PoP in #FRA because they Geolocate entire #ASN|s and not single allocations!
Kevin Karhan :verified:kkarhan@infosec.space
2024-06-30

@antonis Yes, I still need #IPv4 because my #ISP offers me #IPv4only and unless @BNetzA makes #DualStack mandatory, I won't be able to get #IPv6 connectivity, cuz 'fuck the consumer'!

Kevin Karhan :verified:kkarhan@mstdn.social
2023-10-12

@torproject mstdn.social/@kkarhan/11122388
Cuz regardless if I query:

bridges.torproject.org/bridges
or
bridges.torproject.org/bridges

I get the same #IPv6 bridge and no #IPv4 bridge...

It does have Port 443 tho...
But it doesn't solve the issue that in 2023 we still don't have #DualStack everywhere and some places are still #IPv4only!

Kevin Karhan :verified:kkarhan@mstdn.social
2023-02-19

@Toasterson I'd recommend taking a look at #pfSense / #OPNsense for that task.

I've done Tunneling #IPv6 on #IPv4only WAN networks and had to deal with #CGNAT - #IPv4 + IPv6 and having to implement #DualStack on #WAN-side.

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst