Simply Top Ad

Showing posts with label IPv6. Show all posts
Showing posts with label IPv6. Show all posts

Wednesday, May 11, 2011

How to get reliable IPv6 on Windows lappy

On 2 July 2010, I wrote about how to get IPv6 on a Windows laptop. This involved setting up gogoCLIENT from gogo6 to access Freenet6.

This did actually work, but it turned out it was not as good as it first appeared. The problem is that the Freenet6 PoP I was using (Amsterdam) seemed to keep going down. Once down it would stay down for days at a time until it was mended. It turns out that Freenet6 were aware of the problem but there was some limitation which meant that they weren't able to maintain it very well.

So I looked around againt to see what I could do. HE tunnelbroker.net was not satisfactory because they only offer classical 6in4/protocol-41 connections which do not work from behind a NATting router, at least not directly. Whilst HE tunnelbroker.net do offer a PPtP service to tunnel a public IPv4 address to a client system, over which a 6in4/protocol-41 service can then run, it is messy, extra work to use on a daily basis, more things to go wrong, and would route all my IPv4 over HE's network.

Then there was SixXS. I had previously decided I didn't want to use SixXS for various reasons, but as it was the only thing I hadn't now ruled out, I re-visited it. It turned out that I could use SixXS because they offer a service which runs over AYIYA which will work from a NATted connection.

To use AYIYA meant using the AICCU client software. This is now working, but was hard to set up. The AICCU software needs to run all the time you want IPv6 connectivity. So I had to get a shim software which would run an arbitrary program as a service. Also it wanted to use the same pseudo network interface that OpenVPN uses. So I had to arrange for a second instance of that network interface to be created.

Once this is all configured, AICCU will connect up and set up a tunnelled IPv6 connection. This is all well and good, but Windows 7 won't "believe" that it has "proper" IPv6 connectivity unless it sees a "real" IPv6 address assigned to the "main" network connection. The upshot of Windows 7's disbelief is that whilst it will allow IPv6 to work at the packet level, it will not use resolve AAAA records in preference to A records. So if you browse to a dual-stack website, you will still go over IPv4. If you go to a pure IP6 website, it will work (IIRC).

To get round this, we need to assign a proper-looking IPv6 address to the "main" interface. So we can add this to the wireless interface and also the ethernet interface. We can use addresses in the 6to4 space for RFC1918 private ranges (2002:C0A8::/32) which should never clash with a real IPv6 address but which look perfectly genuine to Windows.

Having done this, http://test-ipv6.com/ is now completely happy with my IPv6 connectivity, and http://whatismyv6.com/ is happy that IPv6 is preferred.

Friday, April 15, 2011

APNIC IPv4 Address Pool Reaches Final /8

As of Friday, 15 April 2011, the APNIC pool reached the Final /8 IPv4 address block, bringing us to Stage Three of IPv4 exhaustion in the Asia Pacific.

Last /8 address policy

IPv4 requests will now be assessed under section 9.10 in "Policies for IPv4 address space management in the Asia Pacific region".

APNIC's objective during Stage Three is to provide IPv4 address space for new entrants to the market and for those deploying IPv6.

From now, all new and existing APNIC account holders will be entitled to receive a maximum allocation of a /22 (1024 addresses) from the Final /8 address space.

http://www.apnic.net/services/services-apnic-provides/helpdesk/faqs/ipv4-stage3-faq

http://www.apnic.net/publications/news/2011/final-8

Monday, April 11, 2011

More registrar hunting

Still looking for the perfect registrar.

After asking around on the AAISP IRC channel #A&A, someone mentioned an outfit called Portfast.

Portfast appears to be a provider of hosting, virtual servers, and domain names. They offer native IPv6 (cool), they have a good name (Portfast), and they operate out of a .CO.UK domain name (portfast.co.uk) which is something I like to see. They appear to offer a no-nonsense service, and have sensible prices.

.UK domains are priced at £6+VAT per 2 years and .EU domains are priced at £9+VAT per year.

I liked what I saw so gave them a phone call. The phone was answered quickly, and the first person I spoke to had the technical ability to use the phrase "regular expression" in the conversation, and also the ability to recognise (in about one minute of conversation, starting from cold) that I would be able to understand that phrase. With other companies, this sort of ability doesn't manifest until about third-line support. I liked what I heard, so thought I'd give them a shot.

I have now taken my .CO.UK and my .EU over to Portfast.

There was no charge for taking the .CO.UK over. There was an annual renewal charge of £9+VAT for taking over the .EU, but that is par for the course because EURid charges registrars for transfers.

The .CO.UK went over fine. But the .EU appears to have hit a snag in that all the nameservers were lost in the transfer. This meant that there were no nameservers registered, which of course will have broken the domain name's operation. Fortunately Portfast offers on-line nameserver setting, and it seems these are pushed through to the EURid WHOIS and EURid nameservers within a matter of seconds, so it was easy enough to get things going again.

I asked Portfast about the loss of nameservers, and they replied quickly to indicate that this was not something that they expected to happen, and that their systems were specifically programmed not to touch the nameserver configuration over a registrar transfer. So a bit of a mystery there.

There is still a snag though. Portfast offers on-line configuration of IPv6 glue for .UK domain names. But for .EU domains, on-line configuration of glue records for .EU domains only goes as far as IPv4 glue and does not include IPv6 glue. To Portfast's credit, this is not a limitation imposed by them but rather by OpenSRS who Portfast use to register .EU domain names.

(It is not unreasonable for registrars to subcontract .EU domain name registrations to other registrars because of the somewhat onerous terms imposed upon registrars by EURid, for example the lodging of a €10,000 deposit.)

OpenSRS do not currently support the setting up of IPv6 glue on .EU domain names via an automation interface. So .EU domain name resellers using OpenSRS cannot reasonably offer automated IPv6 glue configuration to their customers.

(Despite APNIC being a mere 10 days away from running out of IPv4 addresses completely, the world does not seem to have realised that the time for saying "Oh we'll be handling IPv6 at ... [waves hand in a dismissive fashion] ... some point in the future" has long since passed.)

So I am currently pursuing the possibility of having Portfast pursue OpenSRS to set up IPv6 glue manually.

So far, OpenSRS has replied to say that they don't support IPv6 glue on .EU domain names. Unfortunately for them, I do not believe they have the option of taking this this position because under the registrar agreement they have with EURid, they will be obliged to offer all services to customers that EURid provides. I've submitted a request to Portfast that OpenSRS be asked again, and where we are now is that that request is currently outstanding.

Thus far Portfast has been entirely helpful and professional.

So at the minute it seems that Portfast per se are absolutely fine.

The problem I have left is that OpenSRS appear to be being a bit dim.

Results so far:


CompanySummary
AAISPReasonable level of technical competence within the organisation, and reasonably easy to get through to technically competent people on the phone. However they do not support on-line configuration of nameservers — you have to submit a support ticket, which is quite pants. Nor do they support automated registration of new domain names — you have to put in a support ticket, which is utterly hopeless if you are looking to "grab" a domain name. A generalised lack of automation on domain name handling — "all handled through tickets". Support tickets would be fine, however it typically take 1+ business days before you even get the initial response on a ticket. UK domain names quite pricey at £12+VAT per year. I don't know if they even provide .EU domain names. Recommendation: Not good for domain name registrations on their own, but OK if buying registrations along with other services, and you aren't cost conscious.
NamesCoTechnically incompetent. Don't touch with a bargepole
Nominate a.k.a. BB-OnlineTechnically incompetent. Don't touch with a bargepole
PortfastTechnically competent in and of themselves. Very reasonable pricing. Portfast handles IPv6 glue on .UK domain names "natively" through their on-line system. Unfortunately Portfast uses OpenSRS for .EU domain names, and it remains to be seen how OpenSRS will behave on IPv6 glue for .EU domain names. Recommendation: Seems to be good for .UK domain name registrations; the jury is still out on .EU domain name registrations.

Tuesday, March 1, 2011

Where have all the good DNS registrars gone?

I have been trying to register a couple of domain names, a .CO.UK and a .EU, and have them set up with my name servers with Glue Records (IPv4 and IPv6).

Should be simple right? But it has so far turned out to be a mammoth task.

I started out by looking for a not-too-expensive registrar who could cope with .CO.UK and .EU names, and who would process the initial registration automatically (and immediately), as opposed to requiring a message to be submitted to a human for processing whenever they saw fit.

After searching around, I landed on NamesCo. Their automated system processed the initial registrations straight off.

Unfortunately they rather messed-up the registrant's (i.e. my) e-mail address as recorded with EURid, putting their own e-mail address instead of mine — VERY naughty. Also it look a LOT of jumping up on down on them via several support tickets to get this fixed. In the end it looked like they had to do (what EURid call) a "trade", presumably at their expense, to get the domain ownership transferred to me. Eh? Yes. From EURid's point-of-view, the domain wasn't actually registered to me at all! So it looks like NamesCo were being extremely naughty and registering names requested by customers to themselves — seems to me to be really quite illegal.

Anyway, I eventually got around to wanting the nameservers and Glue Records set up. So I put in two support tickets, one for each domain name.

The .CO.UK was processed correctly within one business day and I was all set.

After a while, they came back to tell me that the .EU was done. I checked. It wasn't. I queried. A different person waded in on the support ticket and made a comment that was total nonsense. I queried. They made another nonsense comment. This went back and forth a few times before the original person re-surfaced and told me to disregard all the comments from the other person, and made a comment which made sense. Professional? Not really.

This first person made some enquiries, and finally came to the conclusion that they could not support IPv6 Glue Records on .EU domain names because the company which actually processed their .EU registrations (Register.IT) did not support IPv6 Glue Records on .EU domain names.

This was bad as it was. But it was made even worse by the fact that I had deliberately asked, in a support ticket a few weeks earlier, whether they supported IPv6 Glue Records for .EU domain names. Their reply was that their ability to support IPv6 Glue Records was limited only by the ability of the relevant registry to support them. So having said "yes", they now said "no".

I checked the sample agreement which is agreed between EURid and registrars. In section 2.5 it says that registrars must offer all the services to end-users that EURid offers. I also telephoned EURid in Belgium (English +32 2 401 27 60) and asked them if they supported IPv6 Glue. The chap I spoke with didn't know, but he telephoned me back later to say that they did. So it would seem that Register.IT is actually obliged to support IPv6 Glue on .EU domains, but doesn't. So what is that? Probably a civil wrong toward EURid. Ah well.

Eventually I decided that NamesCo was not for me and started to have a look round for another registrar. After looking around I found that AAISP have a domain name "aaisp.eu", and that was registered through an outfit called Nominate.

"Nominate"? Odd. Sounds like some kind of play on "Nominet", and really quite a silly name. Ordinarily I would not have any truck with a company which (a) has such a silly name and (b) appears to be deliberately trying to confuse people into thinking it might be some other organisation (Nominet). But, I thought, hey ho, if it's good enough for AAISP, it's good enough for me.

So I spoke with Nominate to see if (a) they did deal directly with the registries Nominet and EURid, and (b) if they would support IPv6 Glue. They said that they did deal directly with those two registries. On the subject of IPv6 Glue, they said that whilst it was not something they had done much of, they did have access to most registries, and doing "unusual" things with domain registration was something that was well within the sort of thing that they would do.

So I took a chance and promptly transferred my .CO.UK and .EU to Nominate.com.

Nominate.com duly took over the domain names. I then asked them to set up the .EU with the desired nameservers and Glue Records. Within a short while they had managed to get those set up correctly. Fantastic.

At this point both domains were set up and from a DNS point of view, all correct and returning the correct nameservers and Glue Records, including IPv6 Glue Records. In addition, the information recorded with the registries legally identifying me as the registrant owner was correct. Fantastic.

So Nominate were starting to look reasonbly good.

However their web control panel does leave quite a bit to be desired. For example the Postal/geographic address bit doesn't really have the right layout for UK postal addresses, and unless you have an unusually brief address you end up having to cram it in and shove bits of the address into what is really the wrong box.

Also, Nominate are incapable of accepting e-mail addresses which don't happen to fit into their own private definition of what is acceptable. RFC5322 doesn't seem to have reached as far as Longfield, Kent, and they will not accept an e-mail address with a plus symbol in it. Clang!

Even worse was the reason they cited. Something to do with their system treating e-mail addresses as regular expressions! Bizarre! So if the e-mail address contains a plus symbol, this will be interpreted as "match one or more of the previous entity"!

Now, I can tell you, as an I.T. professional with 20 years experience in the business, that this is HIDEOUSLY, HEINOUSLY BROKEN, and indicates that their technical staff (if they have any at all) are hideously incompetent and any company that is this technically incompetent should not be touched with a bargepole.

So in summary: I'm still looking for a DNS registrar which is at least a quarter decent. If you do have any suggestions, please do let me know.

Results so far:


CompanySummary
NamesCoTechnically incompetent. Don't touch with a bargepole
Nominate a.k.a. BB-OnlineTechnically incompetent. Don't touch with a bargepole

Tuesday, February 8, 2011

IPv4 address pool final allocations ceremony

Here is the video for the IPv4 address pool final allocations ceremony:

ICANN IPv4 Ceremony | Miami

http://www.youtube.com/watch?v=p9AzSl2MdFk

And whilst we're at it, let's have the IPv6 news conference:

ICANN IPv6 News Conference | Miami, Florida

http://www.youtube.com/watch?v=gveJs6YRYXU

Monday, February 7, 2011

gogo6 gogoCPE IPv6 tunnel router

Looks interesting. It appears to be an IPv6 tunnel router in a box.

http://gogoware.gogo6.com/4105/description.asp?product_id=180

It looks like it solves a number of problems. It looks like it could be used directly by end users to connect to Freenet6, or in connection with ISP-provided services to enable IPv6 over IPv4, or IPv4 over IPv6.

How to get IPv6 on Windows lappy

Update 2011-05-11: I have now ditched Freenet6 and am now using SixXS.

To get IPv6 going on the lappy, I had been using a Tunnelbroker.net tunnel from Hurricane Electric. One of the advantages for me was that the PoP is in London, which gives me a low latency connection.

But this was not without problems. Because it uses protocol 41 tunneling, it doesn't work through a conventionally NATted connection. To get around this, HE provides a public IPv4 address through a PPTP connection. The problem with this is that it then stuffs all of your IPv4 traffic through the PPTP connection, which is a bit smelly.

But recently discovered the gogoCLIENT from gogo6. This seems to be able to set up a tunnel over IPv4/UDP to Freenet 6. This then means that IPv4 traffic goes over its usual (direct) route, and IPv6 traffic is sent through the tunnel.

Now, my local Freenet 6 PoP is in Amsterdam. This is not the best, but at least it is on the same continent.

Friday, February 4, 2011

IPv6 (hopefully) explained for non-techies

Every connection with the Internet has to have a unique number (the IP address). This is because whenever any piece of data is sent across the Internet, it has to have the number of the connection where it is going to. There will be one number for your home broadband connection, one for my home broadband connection, one (or more) for any website you go to, etc.

These numbers are drawn from a pool of about 3.5 billion numbers.
The worldwide master pool is operated by IANA. IANA gives out blocks of numbers to five groups serving Africa; North America; South America; Asia Pacific; and Europe, the Middle East and Central Asia. These groups in turn hand out blocks of numbers to either national bodies or smaller bodies such as ISPs, and eventually numbers get assigned to individual connections.

What happened yesterday (3 Feb 2011) was that the master pool completely ran out of spare numbers.

IANA no longer has any spare numbers to hand out to the five groups it serves.

That doesn't mean there aren't any spare numbers, but rather that any spare numbers are now in the hands of the five regional groups and the smaller groups below them.

The number of spare numbers is declining. Fundamentally, there was no "step" reduction yesterday (3 Feb 2011) in the number of spare numbers available, so in theory it is not really news, but the fact that the global authority IANA no longer has any spare to dish out is considered by many to be a significant milestone or marker in the decline of the Internet addressing system.

Over time, the shortage of spare numbers will hamper the setting-up of new connections.

This issue has not gone unanticipated. By way of of a solution, in 1998, the boffins came up with a new way of operating the Internet called IPv6, which stands for the Internet Protocol version 6. (By way of background, the current way of operating the Internet is called IPv4.)

Amongst other benefits, IPv6 uses a much larger range of numbers to assign unique numbers to each connection. Whereas IPv4 has some 3.5 billion available numbers to assign to connections, IPv6 initially has sufficient space for about 2 billion billion connections (for geeks: I am assuming the first nybble is 2 or 3, and every connection is assigned a /64).

Unfortunately, we can't just switch on IPv6 and everything's peachy again. For IPv6 to work, the computers talking to each other must both talk IPv6, and the intervening bits of Internet must also be compatible with IPv6.

Fortunately IPv6 and IPv4 can happily coexist on computers, and on the Internet in between them. Fortunately again, most of the stuff you usually use like web browsing and e-mail has already been upgraded to be compatible with IPv6 and will automatically use IPv4 or IPv6 depending on what's available. So for the ordinary person, there should not be much in the way of a noticeable difference.

So many people expect that the way forward will be for the existing IPv4 operations to move to combined IPv4 and IPv6 operations. Eventually we should get to a tipping point where more-or-less everything works fine with IPv6 and we can start dropping the old IPv4 system.

The problem is that there is some resistance amongst ISP to adopting IPv6 alongside IPv4. It seems that most ISPs seem to be waiting until there is a "brick wall" problem in front of their nose, at which point they will start running round like headless chickens trying to fix things.

Now, IPv6 is by no means a new technology. It has been live in many places for many years. The problem is that it will take time for people new to the subject to get their knowledge up to speed, systems to be upgraded, problems to shake out etc. and this will take months to years. If ISPs wait until the last minute, then it isn't going to work.

So there are various people trying to make noise, raise awareness etc.

We shall see.