Re: IPv6 recap

Adam Augustine <[email protected]>
Newsgroups gmane.mail.imap.courier.general
Message-ID <[email protected]>
Hello Ale,

I have some practical experience with IPv6 environments.

"Is it advisable to use different numbers (in the same /64) for outgoing 
(ip6out) and incoming MX, esmtpd, esmtpd-msa, esmtpd-ssl, pop3d, 
pop3d-ssl, imapd and imapd-ssl?"

Short answer, do whatever makes things easy for you.

Longer answer:
Despite what people say about "Everything is different in IPv6!" my 
experience has been that 90% if not more of everything is exactly the 
same, just with longer addresses. The remaining 10% or so that does 
change has mostly to do with how IPv6 addresses get assigned in dynamic 
environments (cases where you would use DHCP in the IPv4 world). You 
don't have to use those functions if you don't want to. IPv6 was meant 
to be a drop-in replacement for IPv4, and it actually works that way, 
assuming the applications are coded correctly.

I may or may not have tested IPv6 with Courier a few times on a 
production system with a light but non-trivial load. It just worked. I 
may possibly have accidentally left my test running for more than a year 
or so before someone noticed and said something about the funny addresses.

If you are already hosting all those services (SMTP, POP, IMAP, and 
their encrypted counterparts) on a single IPv4 address and that is 
working for you today, then follow the same operational pattern with 
IPv6. Think of it like adding another network interface with a second 
IPv4 address. Would you do anything different from what you are doing 
today in that scenario? Probably not. So don't change anything and do 
IPv6 the same way.

At least, at first. There /is/ a psychological barrier that you are 
going to need to get over to get used to IPv6, and that barrier is just 
unfamiliarity. Once you get comfortable and are used to looking at those 
addresses as normal and fully accept that things work exactly the same 
as they did with IPv4, start imagining what you could do if you had all 
the IPv4 addresses you could ever possibly want and could waste them in 
embarrassing ways. IPv6 gives you that, you just have a longer address.

If it would makes your life easier to have a separate IPv4 address for 
each service, then you can do that with IPv6.

If it would make sense for you to have a separate IP address for /each 
and every incoming and outgoing connection and never _ever_ re-use that 
address again/, you can do that with IPv6. And only after 3,928 years 
would you need another /64 subnet. And that is assuming a 100 gigabit 
ethernet network and a single 64 byte packet representing each 
connection. So that's a lower bound.

It is hard to break out of the "I must conserve" mindset of IPv4, so 
exercises like that help open the mind to the possibilities.

One bit of production roll-out advice I would give. You won't get 
traffic on IPv6 until you publish the "AAAA" equivalent of the DNS "A" 
record for your MX record. So don't create the "AAAA" record until you 
are ready to take traffic on your IPv6 address. And when you do, set the 
TTL to something short (60 seconds maybe). That way, if you do make a 
mistake in the configuration somewhere, you can remove the "AAAA" and 
figure things out at your leisure. Minimal impact. It is helpful in 
situations like if you forgot to open the inbound port 25 on IPv6 in 
addition to the already open port 25 on IPv4 on the firewall. Just an 
example.

Anyway, I hope that is at least somewhat useful. And thanks for all the 
work you do to keep my email flowing. You don't know it, but some of 
your posts have really helped me over the years.

  Adam Augustine


On 3/20/24 09:18, Alessandro Vesely wrote:
> Hi all,
>
> I've always compiled Courier using the --without-ipv6 option.  Now 
> I've got some IPv6 addresses, so I'd try and enable IPv6 for mail.  In 
> order to keep behavioral changes to a minimum, I've already set IPv4 
> preference in /etc/gai.conf, and will leave courierd's 
> ESMTP_PREFER_IPV6_MX commented out.
>
> What else?
>
> Is it advisable to use different numbers (in the same /64) for 
> outgoing (ip6out) and incoming MX, esmtpd, esmtpd-msa, esmtpd-ssl, 
> pop3d, pop3d-ssl, imapd and imapd-ssl?
>
> TIA for any hint
>
> Best
> Ale



_______________________________________________
courier-users mailing list
[email protected]
Unsubscribe: https://lists.sourceforge.net/lists/listinfo/courier-users
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.