[dhcwg] Re: [v6ops] Re: [IPv6]Re: Android now su pports DHCPv6 PD
Daryll Swer <[email protected]> Tue, 16 Sep 2025 23:04:40 +0530
| Newsgroups | gmane.ietf.dhc,gmane.ietf.v6ops |
|---|---|
| Message-ID | <CACyFTPHtUUobfDMzOGfbPRi2c-oEVJeFUvKMa6zETXk8zndhCQ@mail.gmail.com> |
--===============1668967842741316403== Content-Type: multipart/alternative; boundary="0000000000001b9249063eee8bc8" --0000000000001b9249063eee8bc8 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable > > If but anyone had warned of this outcome before. > Ha, I've been doing /44s per-site as a minimum policy in all my IPv6 projects for years, and was sneezed at by some very members of this list a while ago, IIRC. Yet here we are talking about larger prefixes. Quick recap for those who may not be familiar with what I suggested as a *minimum* (in the past): /32 per org (purely for backbone-only, no customer links/VMs/Hosts/End-users are ever part of this global /32) =E2=80=94 in ot= her words, if any law enforcement comes knocking at your door, we should never see a request originating from this /32 if we can help it. The prefix is for the infra, not human use. /44 per backbone PoP/Site, even your smaller colos near the street cabinets for SPs. /48 per parent aggregate function, then proceed to go smaller depending on the function and sub-function, but nothing smaller than /64 excluding shared /64 for loopbacks (/128 per loopback). Separate /32s for customer/human-use subnetting, the number of /32s will vary based on business scale, type, scope etc; CSP vs ISP vs carrier-only SP vs LTE/5G carrier vs tiny WISP in the middle of nowhere vs niche cases like a =E2=80=9CStock market Trading-network-only VPS provider, no EVPN/VXL= AN, No K8s, No containers, No Docker, just plain L3 unicast BGP to the host hypervisor=E2=80=9D (an interesting use-case that came to me recently) etc. I'm pro-routing (L2 should be minimised in a design), pro-IPv6 and I think ia_pd (as it stands today) is probably the closest (let's not get into a debate on what defines a routing protocol though) thing to es-is, i.e. route everything as much as possible, down to your endpoints (phones, laptops etc). I wonder if Lorenzo envisioned this all long to push for global /48s? I don't know, but either way, I'm a fan of /48s (or larger), life's easier. NAT66 and ULAs be damned! For LTE/5G, I perhaps may be able to push an LTE/5G provider to do /63s per UE, at least (if their 3GPP/EPC stuff is compatible, I'm no expert on that side of the fence). I'll be sure to share my findings from real-life hands-on ops, should I come across anything interesting. *--* Best Regards Daryll Swer Website: daryllswer.com <https://l.shortlink.es/l/288dacdda2ad7df49bdbe485f22b48d053ebd405?u=3D2153= 471> On Tue, 16 Sept 2025 at 20:32, Gert Doering <[email protected]> wrote: > Hi, > > On Tue, Sep 16, 2025 at 06:04:33PM +0900, Lorenzo Colitti wrote: > > Recommendations for network operators are written in RFC 9663. Some tex= t > > about expected prefix lengths is in section 8 of that RFC. RFC 9762 say= s > > the prefix must be SLAAC-sized, which currently means it must be a /64 > per > > device. A /48 is fine for a small or medium network, but a campus with > tens > > of thousands of devices on it probably needs more than that. > > If but anyone had warned of this outcome before. > > Gert Doering > -- NetMaster > -- > have you enabled IPv6 on something today...? > > SpaceNet AG Vorstand: Sebastian v. Bomhard, > Karin Schuler, Sebastian Cler > Joseph-Dollinger-Bogen 14 Aufsichtsratsvors.: A. Grundner-Culemann > D-80807 Muenchen HRB: 136055 (AG Muenchen) > Tel: +49 (0)89/32356-444 USt-IdNr.: DE813185279 > > _______________________________________________ > v6ops mailing list -- [email protected] > To unsubscribe send an email to [email protected] > --0000000000001b9249063eee8bc8 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><img width=3D"0" height=3D"0" class=3D"mailtrack-img" alt= =3D"" style=3D"display:flex" src=3D"https://mailtrack.io/trace/mail/9c23512= 2495fbc81d09e24704cdebaec4a7be3bb.png?u=3D2153471"><div dir=3D"ltr"><blockq= uote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1p= x solid rgb(204,204,204);padding-left:1ex">If but anyone had warned of this= outcome before.<br></blockquote><div>Ha, I've been doing /44s per-site= as a minimum policy in all my IPv6 projects for years, and was sneezed at = by some very members of this list a while ago,=C2=A0IIRC. Yet here we are t= alking about larger prefixes.</div><div><br></div><div>Quick recap for thos= e who may not be familiar with what I suggested as a <i>minimum</i> (in the= past):</div><div>/32 per org (purely for backbone-only, no customer links/= VMs/Hosts/End-users are ever part of this global /32) =E2=80=94 in other wo= rds, if any law enforcement comes knocking at your door, we should never se= e a request originating from this /32 if we can help it. The prefix is for = the infra, not human use.</div><div>/44 per backbone PoP/Site, even your sm= aller colos=C2=A0near the street cabinets for SPs.</div><div>/48 per parent= aggregate function, then proceed to go smaller depending on the function a= nd sub-function, but nothing smaller than /64 excluding shared /64 for loop= backs (/128 per loopback).</div><div><br></div><div>Separate /32s for custo= mer/human-use subnetting, the number of /32s will vary based on business sc= ale, type, scope etc; CSP vs ISP vs carrier-only SP vs LTE/5G carrier vs ti= ny WISP in the middle of nowhere vs niche cases like a =E2=80=9CStock marke= t Trading-network-only VPS provider, no EVPN/VXLAN, No K8s, No containers, = No Docker, just plain L3 unicast BGP to the host hypervisor=E2=80=9D (an in= teresting use-case that came to me recently) etc.</div><div><br></div><div>= I'm pro-routing (L2 should be minimised in a design), pro-IPv6 and I th= ink ia_pd (as it stands today) is probably the closest (let's not get i= nto a debate on what defines a routing protocol though) thing to es-is, i.e= . route everything as much as possible, down to your endpoints (phones, lap= tops etc). I wonder if Lorenzo envisioned this all long to push for global = /48s? I don't know, but either way, I'm a fan of /48s (or larger), = life's easier. NAT66 and ULAs be damned!</div><div><br></div><div>For L= TE/5G, I perhaps may be able to push an LTE/5G provider to do /63s per UE, = at least (if their 3GPP/EPC stuff is compatible, I'm no expert on that = side of the fence). I'll be sure to share my findings from real-life ha= nds-on ops, should I come across anything interesting.</div><div><br></div>= <div><div dir=3D"ltr" class=3D"gmail_signature"><div dir=3D"ltr"><font colo= r=3D"#000000" face=3D"arial, sans-serif"><b>--</b><br></font><div><font col= or=3D"#000000" face=3D"arial, sans-serif">Best Regards</font></div><div><fo= nt color=3D"#000000" face=3D"arial, sans-serif">Daryll Swer</font></div><di= v><font color=3D"#000000" face=3D"arial, sans-serif">Website: <a href=3D"ht= tps://l.shortlink.es/l/288dacdda2ad7df49bdbe485f22b48d053ebd405?u=3D2153471= " target=3D"_blank">daryllswer.com</a></font></div></div></div></div><br></= div><br><div class=3D"gmail_quote gmail_quote_container"><div dir=3D"ltr" c= lass=3D"gmail_attr">On Tue, 16 Sept 2025 at 20:32, Gert Doering <<a href= =3D"mailto:[email protected]">[email protected]</a>> wrote:<br></div><blockquo= te class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px = solid rgb(204,204,204);padding-left:1ex">Hi,<br> <br> On Tue, Sep 16, 2025 at 06:04:33PM +0900, Lorenzo Colitti wrote:<br> > Recommendations for network operators are written in RFC 9663. Some te= xt<br> > about expected prefix lengths is in section 8 of that RFC. RFC 9762 sa= ys<br> > the prefix must be SLAAC-sized, which currently means it must be a /64= per<br> > device. A /48 is fine for a small or medium network, but a campus with= tens<br> > of thousands of devices on it probably needs more than that.<br> <br> If but anyone had warned of this outcome before.<br> <br> Gert Doering<br> =C2=A0 =C2=A0 =C2=A0 =C2=A0 -- NetMaster<br> -- <br> have you enabled IPv6 on something today...?<br> <br> SpaceNet AG=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 = =C2=A0 =C2=A0 Vorstand: Sebastian v. Bomhard,<br> =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2= =A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 = =C2=A0Karin Schuler, Sebastian Cler<br> Joseph-Dollinger-Bogen 14=C2=A0 =C2=A0 =C2=A0 =C2=A0 Aufsichtsratsvors.: A.= Grundner-Culemann<br> D-80807 Muenchen=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2= =A0HRB: 136055 (AG Muenchen)<br> Tel: +49 (0)89/32356-444=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0USt-IdNr.: DE8131= 85279<br> <br> _______________________________________________<br> v6ops mailing list -- <a href=3D"mailto:[email protected]" target=3D"_blank">v= [email protected]</a><br> To unsubscribe send an email to <a href=3D"mailto:[email protected]" tar= get=3D"_blank">[email protected]</a><br> </blockquote></div></div> --0000000000001b9249063eee8bc8-- --===============1668967842741316403== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KZGhjd2cgbWFp bGluZyBsaXN0IC0tIGRoY3dnQGlldGYub3JnClRvIHVuc3Vic2NyaWJlIHNlbmQgYW4gZW1haWwg dG8gZGhjd2ctbGVhdmVAaWV0Zi5vcmcK --===============1668967842741316403==--