[Witarea] Re: How to make an elegant IPv4 outage

Erik Nygren <[email protected]> Fri, 12 Jun 2026 10:19:07 -0400
Newsgroups gmane.ietf.tsv-area,gmane.ietf.general,gmane.ietf.v6ops
Message-ID <CAKC-DJjyRZKgZOYLc2zymzfzeQd8-k+LSZv=TA2z4d3bPfxh9g@mail.gmail.com>
--===============8179575107328316765==
Content-Type: multipart/alternative; boundary="000000000000ae985006540f294c"

--000000000000ae985006540f294c
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

+ v6ops

On the topic of the original draft (
https://datatracker.ietf.org/doc/html/draft-martin-retry-over-ipv6-01):

1) I wonder if this is pointing towards a desire to either start sunset4
back up again, or to charter work within some existing WG (v6ops, 6man,
others?) to pick back up on where sunset4 left off, specifically looking
for technology solutions and operational recommendations to provide a path
towards phasing out IPv4 in various environments.  (Some of the work Jordi
and v6ops are doing on trying to define "IPv6-only" is a good start in this
direction.) While this may be a long way off for the general end-user
consumer usability, as mentioned by others there are increasing
environments (eg, cloud applications, building infrastructure) where
IPv6-only is now viable.

2) For your specific proposal, I wonder if DNS signaling might be a less
invasive way to do this?  In particular, we might want to define a SVCB
SvcParam for "ipv6only" to indicate that an endpoint has no IPv4 support.
Clients could achive something similar to your proposal by warning if the
most preferred SVCB endpoints are IPv6-only and the client is unable to use
them for that reason.  For the specific example of the Czechia use-case,
they could have HTTPS RRs in the DNS where the top priority one indicates
that it is IPv6-only followed by a lower priority one which is
dualstacked.  They could later drop the dualstacked endpoint.  I think this
could achieve the same results as your retry-over-ipv6 draft with less
complexity and with less need for fallback.

Erik





On Wed, Jun 3, 2026 at 5:29=E2=80=AFPM Franck Martin <[email protected]=
g> wrote:

> Moving to Witarea, but keeping ietf in the loop for the moment.
>
> Hi Surya,
>
> Many thanks for those great points.
>
> On Jun 3, 2026, at 13:00, S Moonesamy <[email protected]> wrote:
>
> Hi Franck,
>
> [Cc to witarea@]
>
> At 11:32 AM 03-06-2026, Franck Martin wrote:
>
> Today I submitted this Internet Draft (I-D) to the IETF
> https://datatracker.ietf.org/doc/draft-martin-retry-over-ipv6/
>
> I have been building this site: pacific.ipv6forum.com and I have been
> wondering, how could I do an IPv4 outage on this site on 6/6?
>
> I have also seen that Czechoslovakia has mandated the end of IPv4 on
> government sites on 6/6/2032, 6 years from now.
>
> I also recall (from recent experience) that it is relatively easy to reac=
h
> >90% of IPv6 connections to an internal network (think datacenter), but t=
he
> remaining last % are difficult to identify (or discard) because services
> may misbehave and prefer IPv4 from time to time: You don't know if they
> can't really do IPv4 or if they did not bother to do IPv6.
>
> In an enterprise environment, micro-services are made redundant, there ar=
e
> multiple IPs and have fallback mechanisms when they encounter a 5xx error
> on one endpoint.
>
> So, I started to work on this Internet Draft. It is ready for the first
> round of public comments. I suspect, if successful, it will take 1 or 2
> years to make it a standard. Then an extra 1 or 2 years, before it is
> implemented on enough clients (and browsers), we will be just in time for
> doing enough IPv4 outages on 6/6 to meet the 6/6/2032 deadline.
>
>
> There is a recent thread about IPv6 at
> https://mailarchive.ietf.org/arch/msg/ipv6/BxSOgbF34xbBcijtxf85Pfnb5tc/ I
> don't remember seeing anything resulting from that discussion.  Having a
> draft is, relatively, better than the usual email discussion.  The draft
> falls under the WIT Area and v6ops (which is in another IETF Area).
>
>
> I quickly read the thread, and also asked for a summary. I agree with man=
y
> points like : some mobiles are IPv6-only (T-Mobile, Reliance,=E2=80=A6), =
some
> networks are IPv6-only on the management side (Comcast),.. StarLink is
> moving the needle A LOT in small countries, see countries on
> https://pacific.ipv6forum.com.. but yes the frontier is Entreprise
> adoption. I have some experience here that I=E2=80=99m trying to share.
>
>
> Section 1.1 of the draft states that "Governments are also publishing
> fixed IPv4 end dates" and lists one example [1].  Are there any other
> governments which have a fixed end date?
>
>
> I am not aware of other governments that have published an equally
> specific =E2=80=9CIPv4 service ends on <date>=E2=80=9D policy for their p=
ublic services.
> Several others publish IPv6 transition *milestones* rather than a fixed
> IPv4 shutdown date =E2=80=94 for example, US OMB M-21-07 (80% of federal =
IP-enabled
> assets in IPv6-only environments by FY 2025, with strategic intent to pha=
se
> out IPv4):
> https://www.whitehouse.gov/wp-content/uploads/2020/11/M-21-07.pdf
>
> The Netherlands and others have long-standing IPv6 =E2=80=9Cuse-or-explai=
n=E2=80=9D or
> adoption targets, but not, to my knowledge, a single published IPv4 end
> date comparable to the Czech case.
>
> There was also a memo from the State of Washington going in the same
> direction=E2=80=A6
>
> I used to track all those=E2=80=A6 looks like I need to do that again.
>
> And I agree that those memos come and go=E2=80=A6 Why? Because it is not =
trivial,
> we (IETF?) ought to make it easier.
>
>
>
> Section 3 of the draft states that "Many operators plan to remove or
> disable IPv4 while retaining IPv6 service."  Are those plans available on
> the operators' websites?
>
>
> I tend to abuse the word =E2=80=9CMany=E2=80=9D, you caught me! I make a =
note to change it
> to =E2=80=9CSome"
>
> That being said:
>
>    - Meta is IPv6-only in their data centers:
>    https://engineering.fb.com/2017/01/17/production-engineering/legacy-su=
pport-on-ipv6-only-infra/
>
>    - Google Cloud has guidance for IPv6-only:
>    https://cloud.google.com/blog/products/networking/connect-ipv6-only-wo=
rkloads-to-ipv4-with-dns64-and-nat64
>
>    - All the could providers are moving to support IPv6 (because for
>    instance K8S bring undue complexity when you use NAT, also with the
>    explosion of AI agents, this will not be sustainable, I=E2=80=99m not =
worry, they
>    can afford to buy large chunks of IPv4 - side note: I spoke recently w=
ith a
>    banker on why IPv4 is not on the balance sheet of companies?)
>    - Cisco has an IPv6-only building:
>    https://blogs.cisco.com/networking/an-ipv6-campus-of-the-future
>    - Orange is considering IPv6-only:
>    https://www.youtube.com/watch?v=3DahlY1vwM8qE
>    - Microsoft has IPv6-only deployments (I know that in Azure this is
>    way more complicated):
>    https://labs.ripe.net/author/mirjam/ipv6-only-at-microsoft/
>    - LinkedIn is moving to Dual Stack and IPv6-only in their Datacenters.
>    I may point you to the links in this post:
>    https://www.patreon.com/posts/ipv6-in-lessons-159595711 where I share
>    my experience with IPv6.
>
>
> On this last point, I want to say my motivation is more on how to make
> life easier for internal deployments than external deployments. As such I
> found out that making a software outage is easier than an infrastructure
> outage, and easier and faster to rollback. =E2=80=9CYou can=E2=80=99t fix=
 what you don=E2=80=99t
> measure=E2=80=9D, if you can differentiate an IPv4 outage from any other =
outage,
> then you don=E2=80=99t know what to fix.
>
> I=E2=80=99m not expecting the web browsers to implement anything fast, bu=
t I think
> we can have =E2=80=9Cfaster=E2=80=9D implementation in open source softwa=
re like gRPC and
> Rest.Li to make life easier in enterprises, therefore impacting other
> software in those enterprises, which will lead to make it easier on the
> public Internet...
>
> So thanks for all those valid points, I=E2=80=99ll figure out how to bett=
er answer
> them in version -01.
>
> I tried to address the same with email, a while back. See those expired
> ID:
> https://datatracker.ietf.org/doc/draft-martin-smtp-ipv6-to-ipv4-fallback/
> ,
> https://datatracker.ietf.org/doc/draft-martin-smtp-target-host-selection-=
ipv4-ipv6/.
> I hope this ID has a bit more chances.
>
> Franck
> PS: if any has more references of mandate or wannabe mandates, please let
> me know.
>
>
> Regards,
> S. Moonesamy
>
> 1. The IPv6 adoption rate for a social network in that country is 35.2%.
>
>
>

--000000000000ae985006540f294c
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div class=3D"gmail_default" style=3D"font-family:tahoma,s=
ans-serif">+ v6ops</div><div class=3D"gmail_default" style=3D"font-family:t=
ahoma,sans-serif"><br></div><div class=3D"gmail_default" style=3D"font-fami=
ly:tahoma,sans-serif">On the topic of the original draft (<a href=3D"https:=
//datatracker.ietf.org/doc/html/draft-martin-retry-over-ipv6-01">https://da=
tatracker.ietf.org/doc/html/draft-martin-retry-over-ipv6-01</a>):</div><div=
 class=3D"gmail_default" style=3D"font-family:tahoma,sans-serif"><br></div>=
<div class=3D"gmail_default" style=3D"font-family:tahoma,sans-serif">1) I w=
onder if this is pointing towards a desire to either=C2=A0start sunset4 bac=
k up again, or to charter work within some existing WG (v6ops, 6man, others=
?) to pick back up on where sunset4 left off, specifically looking for tech=
nology solutions and operational recommendations to provide a path towards =
phasing out IPv4 in various environments.=C2=A0 (Some of the work Jordi and=
 v6ops are doing on trying to define &quot;IPv6-only&quot; is a good start =
in this direction.) While this may be a long way off for the general end-us=
er consumer usability, as mentioned by others there are increasing environm=
ents (eg, cloud applications, building infrastructure) where IPv6-only is n=
ow viable.</div><div class=3D"gmail_default" style=3D"font-family:tahoma,sa=
ns-serif"><br></div><div class=3D"gmail_default" style=3D"font-family:tahom=
a,sans-serif">2) For your specific proposal, I wonder if DNS signaling migh=
t be a less invasive way to do this?=C2=A0 In particular, we might want to =
define a SVCB SvcParam for &quot;ipv6only&quot; to indicate=C2=A0that an en=
dpoint has no IPv4 support.=C2=A0 Clients could achive something similar to=
 your proposal by warning if the most preferred SVCB endpoints are IPv6-onl=
y and the client is unable to use them for that reason.=C2=A0=C2=A0For the =
specific example of the Czechia use-case, they could have HTTPS RRs in the =
DNS where the top priority one indicates that it is IPv6-only followed by a=
 lower priority one which is dualstacked.=C2=A0 They could later drop the d=
ualstacked endpoint.=C2=A0 I think this could achieve the same results as y=
our retry-over-ipv6 draft with less complexity and with less need for fallb=
ack.</div><div class=3D"gmail_default" style=3D"font-family:tahoma,sans-ser=
if"><br></div><div class=3D"gmail_default" style=3D"font-family:tahoma,sans=
-serif">Erik</div><div class=3D"gmail_default" style=3D"font-family:tahoma,=
sans-serif"><br></div><div class=3D"gmail_default" style=3D"font-family:tah=
oma,sans-serif"><br></div><div class=3D"gmail_default" style=3D"font-family=
:tahoma,sans-serif"><br></div><div class=3D"gmail_default" style=3D"font-fa=
mily:tahoma,sans-serif"><br></div></div><br><div class=3D"gmail_quote gmail=
_quote_container"><div dir=3D"ltr" class=3D"gmail_attr">On Wed, Jun 3, 2026=
 at 5:29=E2=80=AFPM Franck Martin &lt;<a href=3D"mailto:franck@peachymango.=
org">[email protected]</a>&gt; wrote:<br></div><blockquote class=3D"gm=
ail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,=
204,204);padding-left:1ex"><div><div>Moving to Witarea, but keeping ietf in=
 the loop for the moment.</div><div><br></div>Hi Surya,<div><br></div><div>=
<div>Many thanks for those great points.</div><div><br><blockquote type=3D"=
cite"><div>On Jun 3, 2026, at 13:00, S Moonesamy &lt;<a href=3D"mailto:sm%2=
[email protected]" target=3D"_blank">[email protected]</a>&gt; wrote:</=
div><br><div><div>Hi Franck,<br><br>[Cc to witarea@]<br><br>At 11:32 AM 03-=
06-2026, Franck Martin wrote:<br><blockquote type=3D"cite">Today I submitte=
d this Internet Draft (I-D) to the IETF<br><a href=3D"https://datatracker.i=
etf.org/doc/draft-martin-retry-over-ipv6/" target=3D"_blank">https://datatr=
acker.ietf.org/doc/draft-martin-retry-over-ipv6/</a><br><br>I have been bui=
lding this site: <a href=3D"http://pacific.ipv6forum.com" target=3D"_blank"=
>pacific.ipv6forum.com</a> and I have been wondering, how could I do an IPv=
4 outage on this site on 6/6?<br><br>I have also seen that Czechoslovakia h=
as mandated the end of IPv4 on government sites on 6/6/2032, 6 years from n=
ow.<br><br>I also recall (from recent experience) that it is relatively eas=
y to reach &gt;90% of IPv6 connections to an internal network (think datace=
nter), but the remaining last % are difficult to identify (or discard) beca=
use services may misbehave and prefer IPv4 from time to time: You don&#39;t=
 know if they can&#39;t really do IPv4 or if they did not bother to do IPv6=
.<br><br>In an enterprise environment, micro-services are made redundant, t=
here are multiple IPs and have fallback mechanisms when they encounter a 5x=
x error on one endpoint.<br><br>So, I started to work on this Internet Draf=
t. It is ready for the first round of public comments. I suspect, if succes=
sful, it will take 1 or 2 years to make it a standard. Then an extra 1 or 2=
 years, before it is implemented on enough clients (and browsers), we will =
be just in time for doing enough IPv4 outages on 6/6 to meet the 6/6/2032 d=
eadline.<br></blockquote><br>There is a recent thread about IPv6 at <a href=
=3D"https://mailarchive.ietf.org/arch/msg/ipv6/BxSOgbF34xbBcijtxf85Pfnb5tc/=
" target=3D"_blank">https://mailarchive.ietf.org/arch/msg/ipv6/BxSOgbF34xbB=
cijtxf85Pfnb5tc/</a> I don&#39;t remember seeing anything resulting from th=
at discussion.=C2=A0 Having a draft is, relatively, better than the usual e=
mail discussion.=C2=A0 The draft falls under the WIT Area and v6ops (which =
is in another IETF Area).<br></div></div></blockquote><div><br></div><div>I=
 quickly read the thread, and also asked for a summary. I agree with many p=
oints like : some mobiles are IPv6-only (T-Mobile, Reliance,=E2=80=A6), som=
e networks are IPv6-only on the management side (Comcast),.. StarLink is mo=
ving the needle A LOT in small countries, see countries on <a href=3D"https=
://pacific.ipv6forum.com" target=3D"_blank">https://pacific.ipv6forum.com</=
a>.. but yes the frontier is Entreprise adoption. I have some experience he=
re that I=E2=80=99m trying to share.</div><br><blockquote type=3D"cite"><di=
v><div><br>Section 1.1 of the draft states that &quot;Governments are also =
publishing fixed IPv4 end dates&quot; and lists one example [1].=C2=A0 Are =
there any other governments which have a fixed end date?<br></div></div></b=
lockquote><div><br></div><div>I am not aware of other governments that have=
 published an equally specific =E2=80=9CIPv4 service ends on &lt;date&gt;=
=E2=80=9D policy for their public services. Several others publish IPv6 tra=
nsition *milestones* rather than a fixed IPv4 shutdown date =E2=80=94 for e=
xample, US OMB M-21-07 (80% of federal IP-enabled assets in IPv6-only envir=
onments by FY 2025, with strategic intent to phase out IPv4): <a href=3D"ht=
tps://www.whitehouse.gov/wp-content/uploads/2020/11/M-21-07.pdf" target=3D"=
_blank">https://www.whitehouse.gov/wp-content/uploads/2020/11/M-21-07.pdf</=
a></div><div><br></div><div>The Netherlands and others have long-standing I=
Pv6 =E2=80=9Cuse-or-explain=E2=80=9D or adoption targets, but not, to my kn=
owledge, a single published IPv4 end date comparable to the Czech case.</di=
v><div><br></div><div>There was also a memo from the State of Washington go=
ing in the same direction=E2=80=A6</div><div><br></div><div>I used to track=
 all those=E2=80=A6 looks like I need to do that again.</div><div><br></div=
><div>And I agree that those memos come and go=E2=80=A6 Why? Because it is =
not trivial, we (IETF?) ought to make it easier.</div><div>=C2=A0</div><blo=
ckquote type=3D"cite"><div><div><br>Section 3 of the draft states that &quo=
t;Many operators plan to remove or disable IPv4 while retaining IPv6 servic=
e.&quot; =C2=A0Are those plans available on the operators&#39; websites?<br=
></div></div></blockquote><div><br></div>I tend to abuse the word =E2=80=9C=
Many=E2=80=9D, you caught me! I make a note to change it to =E2=80=9CSome&q=
uot;</div><div><br></div><div>That being said:=C2=A0</div><div><ul><li>Meta=
 is IPv6-only in their data centers:=C2=A0<a href=3D"https://engineering.fb=
.com/2017/01/17/production-engineering/legacy-support-on-ipv6-only-infra/" =
target=3D"_blank">https://engineering.fb.com/2017/01/17/production-engineer=
ing/legacy-support-on-ipv6-only-infra/</a>=C2=A0</li><li>Google Cloud has g=
uidance for IPv6-only:=C2=A0<a href=3D"https://cloud.google.com/blog/produc=
ts/networking/connect-ipv6-only-workloads-to-ipv4-with-dns64-and-nat64" tar=
get=3D"_blank">https://cloud.google.com/blog/products/networking/connect-ip=
v6-only-workloads-to-ipv4-with-dns64-and-nat64</a>=C2=A0</li><li>All the co=
uld providers are moving to support IPv6 (because for instance K8S bring un=
due complexity when you use NAT, also with the explosion of AI agents, this=
 will not be sustainable, I=E2=80=99m not worry, they can afford to buy lar=
ge chunks of IPv4 - side note: I spoke recently with a banker on why IPv4 i=
s not on the balance sheet of companies?)</li><li>Cisco has an IPv6-only bu=
ilding:=C2=A0<a href=3D"https://blogs.cisco.com/networking/an-ipv6-campus-o=
f-the-future" target=3D"_blank">https://blogs.cisco.com/networking/an-ipv6-=
campus-of-the-future</a></li><li>Orange is considering IPv6-only:=C2=A0<a h=
ref=3D"https://www.youtube.com/watch?v=3DahlY1vwM8qE" target=3D"_blank">htt=
ps://www.youtube.com/watch?v=3DahlY1vwM8qE</a></li><li>Microsoft has IPv6-o=
nly deployments (I know that in Azure this is way more complicated):=C2=A0<=
a href=3D"https://labs.ripe.net/author/mirjam/ipv6-only-at-microsoft/" targ=
et=3D"_blank">https://labs.ripe.net/author/mirjam/ipv6-only-at-microsoft/</=
a></li><li>LinkedIn is moving to Dual Stack and IPv6-only in their Datacent=
ers. I may point you to the links in this post:=C2=A0<a href=3D"https://www=
.patreon.com/posts/ipv6-in-lessons-159595711" target=3D"_blank">https://www=
.patreon.com/posts/ipv6-in-lessons-159595711</a> where I share my experienc=
e with IPv6.</li></ul><div><br></div><div>On this last point, I want to say=
 my motivation is more on how to make life easier for internal deployments =
than external deployments. As such I found out that making a software outag=
e is easier than an infrastructure outage, and easier and faster to rollbac=
k. =E2=80=9CYou can=E2=80=99t fix what you don=E2=80=99t measure=E2=80=9D, =
if you can differentiate an IPv4 outage from any other outage, then you don=
=E2=80=99t know what to fix.=C2=A0</div><div><br></div><div>I=E2=80=99m not=
 expecting the web browsers to implement anything fast, but I think we can =
have =E2=80=9Cfaster=E2=80=9D implementation in open source software like g=
RPC and Rest.Li to make life easier in enterprises, therefore impacting oth=
er software in those enterprises, which will lead to make it easier on the =
public Internet...</div><div><br></div><div>So thanks for all those valid p=
oints, I=E2=80=99ll figure out how to better answer them in version -01.</d=
iv><div><br></div><div>I tried to address the same with email, a while back=
. See those expired ID:=C2=A0<a href=3D"https://datatracker.ietf.org/doc/dr=
aft-martin-smtp-ipv6-to-ipv4-fallback/" target=3D"_blank">https://datatrack=
er.ietf.org/doc/draft-martin-smtp-ipv6-to-ipv4-fallback/</a>,=C2=A0<a href=
=3D"https://datatracker.ietf.org/doc/draft-martin-smtp-target-host-selectio=
n-ipv4-ipv6/" target=3D"_blank">https://datatracker.ietf.org/doc/draft-mart=
in-smtp-target-host-selection-ipv4-ipv6/</a>. I hope this ID has a bit more=
 chances.</div><div><br></div><div>Franck</div><div>PS: if any has more ref=
erences of mandate or wannabe mandates, please let me know.</div></div><div=
><br><blockquote type=3D"cite"><div><div><br>Regards,<br>S. Moonesamy<br><b=
r>1. The IPv6 adoption rate for a social network in that country is 35.2%.<=
/div></div></blockquote></div><br></div></div></blockquote></div>

--000000000000ae985006540f294c--


--===============8179575107328316765==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

LS0gCldpdGFyZWEgbWFpbGluZyBsaXN0IC0tIHdpdGFyZWFAaWV0Zi5vcmcKVG8gdW5zdWJzY3Jp
YmUgc2VuZCBhbiBlbWFpbCB0byB3aXRhcmVhLWxlYXZlQGlldGYub3JnCg==

--===============8179575107328316765==--