IPv4 Depletion(arin.net)
arin.net
IPv4 Depletion
https://arin.net/resources/request/ipv4_countdown.html
9 comments
Mobile should have been IPv6 from the beginning. In China, it mostly is. If we could get all the handsets on IPv6, that would free up much address space. T-Mobile has been pushing IPv6, but they had problems with Skype and WhatsApp, which apparently don't talk IPv6 properly.
Verizon Wireless and T-Mo have very large amounts of IPv6 deployed. They use 464XLAT, and anything with hard-coded IPv4 literals (bad practice) works kinda poorly.
Interesting, especially in the light of google reported ~2 percent IPv6 penetration in China.
My personal experience in managing somewhat popular sites (dual stack) in line with Google reported numbers. https://www.google.ca/intl/en/ipv6/statistics.html#tab=per-c...
I tested Skype back in January on IPv6only+NAT64, worked for me.
Anyway given this: http://www.internetsociety.org/deploy360/blog/2015/06/apple-..., the days of "Apps not working with IPv6" are counted.
Anyway given this: http://www.internetsociety.org/deploy360/blog/2015/06/apple-..., the days of "Apps not working with IPv6" are counted.
What? As a Chinese I have never been able to access IPv6 through mobile network or WiFi. Are you sure about your statement?
Me either, and I've used all providers historically. I think Animats was confused with Japan.
Is ipv4 depletion an issue for the big cloud providers (Amazon , Google, DigitalOcean, Rackspace)? How many ips do they have left?
The most widely known is Azure, when they had to shuffle addresses around:
http://www.internetsociety.org/deploy360/blog/2014/06/ipv4-e...
Google already started charging a nominal fee for idle IPv4 addresses: https://cloud.google.com/sql/, search for "Idle IPv4 address"
http://www.internetsociety.org/deploy360/blog/2014/06/ipv4-e...
Google already started charging a nominal fee for idle IPv4 addresses: https://cloud.google.com/sql/, search for "Idle IPv4 address"
It has been an issue for some in the past[1].
[1] http://www.internetsociety.org/deploy360/blog/2014/06/ipv4-e...
[1] http://www.internetsociety.org/deploy360/blog/2014/06/ipv4-e...
Amazon landed the largest address transfer that I'm aware of to date (a /10) when du Pont chopped up 52/8. Reddit mentioned it, but I didn't see news on it:
https://www.reddit.com/r/networking/comments/2tc4ss/looks_li...
https://www.reddit.com/r/networking/comments/2tc4ss/looks_li...
They keep buying space. Microsoft for example http://www.networkworld.com/article/2228854/microsoft-subnet...
There's a secondary market that is surprisingly lacking in interest. I have a site that brokers large blocks of IPv4 to interested parties, and the most interest I've seen is for a /21. We have a /8 and can not come anywhere close to drumming up interest for it.
http://ipv4hub.com
http://ipv4hub.com
There is a lot of FUD surrounding this market. Apparently Iran has been buying blocks of IPv4 from Romania, only to discover that the Romanians were continuing to advertise those same blocks after the sale!! See https://youtu.be/Jn5ztZSigHA
That's pretty egregious, why the heck did the romanian upstream peers not just drop them after they started obviously highjacking the /23? I mean you have something that is obviously not just some misconfiguration, if you know that one of your peers is intentionally hijacking some prefix why would you be complacent in being a part of their fraud?
Hmm, you have an IPv4 /8 that you don't need that you want to sell ?
I'm sure with ARIN running out probably tomorrow there would surely be interest soon!
I'm sure with ARIN running out probably tomorrow there would surely be interest soon!
Well, if you have $250M, you can buy it for yourself
$250M for a /8 (2^24) is almost $15 per address, which is 35% higher than the recent public deal [1] (though in RIPE address space), so maybe the time of $16 per IP did not come yet ;-).
I guess you've seen that at least in RIPE the transfers are alive and well: https://labs.ripe.net/Members/wilhelm/ipv4-transfers-in-the-...
And ARIN just the other day put up for discussion the simplifications in transfer [2], so with the impending scraping the bottom of the barrel (today morning only /23s and /24s left, in total less than 200000 addresses) it should liven up.
OTOH the higher the price per Legacy IP goes, the more incentive folks have to do IPv6. There's a odd satisfaction in having the lots "I told you so" moments in the past half a year or so, although I feel sad for folks who made the life for themselves more difficult than it should've been by pretending the IPv6 not to be a thing.
Especially for the folks on HN doing startups: whereas before you could have gotten away with temporarily glitches in IPv6 connectivity when it was available with 2% users, today when you enable IPv6, 1 out of 5 users in the US will use it [3] - and predominantly mobile [4] - the US is leading. Not much time for learning on the job now! Luckily Cloudflare [5] and Akamai offer at least a temporary patch by frontending the site with IPv6 and providing the X-Forwarded-For.
Later on, the use of CGN on IPv4 and NAT64 to reach the legacy IP sites will increase - now think of all these precious analytics they are missing because of CGNs hiding the individual users...
Anyway a /8 could become more valuable when the IPv4 routing table grows bad enough that the operators start to filter the routes more aggressively. This is the fun part in the whole game to catch the moment to cash out.
Sorry, this turned out to be quite a bit longer and more offtopic than I wanted, but hopefully might help some.
[1] http://www.bbc.com/news/technology-32826353
[2] https://www.arin.net/policy/proposals/2015_7.html
[3] http://6lab.cisco.com/stats/index.php?option=all
[4] http://www.worldipv6launch.org/measurements/
[5] https://www.cloudflare.com/ipv6
I guess you've seen that at least in RIPE the transfers are alive and well: https://labs.ripe.net/Members/wilhelm/ipv4-transfers-in-the-...
And ARIN just the other day put up for discussion the simplifications in transfer [2], so with the impending scraping the bottom of the barrel (today morning only /23s and /24s left, in total less than 200000 addresses) it should liven up.
OTOH the higher the price per Legacy IP goes, the more incentive folks have to do IPv6. There's a odd satisfaction in having the lots "I told you so" moments in the past half a year or so, although I feel sad for folks who made the life for themselves more difficult than it should've been by pretending the IPv6 not to be a thing.
Especially for the folks on HN doing startups: whereas before you could have gotten away with temporarily glitches in IPv6 connectivity when it was available with 2% users, today when you enable IPv6, 1 out of 5 users in the US will use it [3] - and predominantly mobile [4] - the US is leading. Not much time for learning on the job now! Luckily Cloudflare [5] and Akamai offer at least a temporary patch by frontending the site with IPv6 and providing the X-Forwarded-For.
Later on, the use of CGN on IPv4 and NAT64 to reach the legacy IP sites will increase - now think of all these precious analytics they are missing because of CGNs hiding the individual users...
Anyway a /8 could become more valuable when the IPv4 routing table grows bad enough that the operators start to filter the routes more aggressively. This is the fun part in the whole game to catch the moment to cash out.
Sorry, this turned out to be quite a bit longer and more offtopic than I wanted, but hopefully might help some.
[1] http://www.bbc.com/news/technology-32826353
[2] https://www.arin.net/policy/proposals/2015_7.html
[3] http://6lab.cisco.com/stats/index.php?option=all
[4] http://www.worldipv6launch.org/measurements/
[5] https://www.cloudflare.com/ipv6
I think I see your problem.
Interesting idea, but my unsubstantiated feeling is that there's probably a solid market for sub-class C to maybe /23 or /22, a small but well funded market for blocks bigger than /12 or so, and very, very little in the middle. That is, there's a lot of business use cases where owning a modest sized, routeable network is a potential win (e.g. site redundancy via BGP), a couple of business plans where having a very large numbers of addresses is important (e.g. you're a Something-aaS company, or an ISP/hosting play), but what's the business that needs just 64k addresses? Yes, I know they're out there (I've worked with many), but in my experience many of those are either a) really, really inefficient with their address space or b) are tacking on whatever space they can scrounge because they started out with a too-small allocation. YMMV.
In fact IPv4 transfers are very common in RIPE servin region, there is official pace
https://www.ripe.net/manage-ips-and-asns/resource-transfers-...
So companies are buying IPv4 space
They really just need to set a date and say "okay guys, on 1 March 2017 we're all just going to drop IPv4 entirely, you have until then to get ready"
Yes, there will be casualties.
Yes, there will be casualties.
... and then "we" say "No." "They" lose credibility and political weight. Next time a decision has to be made, "others" will try to seize power, pointing at this event to show the threat to backwards compatibility that they present.
Politics are everywhere. Don't underestimate the energy necessary to shift the direction of an oil tanker.
Politics are everywhere. Don't underestimate the energy necessary to shift the direction of an oil tanker.
They should start by deciding when we're really out of IPv4. We exhausted IPv4 in 2011. And 2012. And 2013. And 2014. Every time somebody says "but this time we're really serious."
There are multiple RIRs who exhausted in various times.
RIPE already ran on the "1024 addresses for every new member and that's it" soft-landing policy for the past couple of years.
But ARIN does not have a nice policy like RIPE does, so it will be a bit more entertaining this time.
RIPE already ran on the "1024 addresses for every new member and that's it" soft-landing policy for the past couple of years.
But ARIN does not have a nice policy like RIPE does, so it will be a bit more entertaining this time.
None of which makes me care. From the beginning, the relevant question has been, when will I be unable to get an IP? And every time the answer is "real soon now". Yet the price of an extra IP on linode (for one example) has not budged from $1/month. You'll understand if this doesn't inspire much concern.
For the record, I make the same complaint every time. Always the same response. "Those were warning signs, but now the end is nigh!"
For the record, I make the same complaint every time. Always the same response. "Those were warning signs, but now the end is nigh!"
When you think of the size of the IPv4 space, you realize that $1/mo for an IP is by far the most profitable add-on they sell.
4.3 billion IPs x $12 per year = $51 billion. If the average cost to actually hold an IPv4 address was even $0.10/month, we would not be talking about IPv4 exhaustion.
My point is, as long as you're willing to spend $12/year just for the IP address, there will be a long line of people happy to sell one to you. But $1 per month for a routable address is at least two orders of magnitude more expensive than network architects are aiming for.
4.3 billion IPs x $12 per year = $51 billion. If the average cost to actually hold an IPv4 address was even $0.10/month, we would not be talking about IPv4 exhaustion.
My point is, as long as you're willing to spend $12/year just for the IP address, there will be a long line of people happy to sell one to you. But $1 per month for a routable address is at least two orders of magnitude more expensive than network architects are aiming for.
Exactly. And as the home speeds reach 1Gbps to the home, there will not be enough CGN boxes that will be able to sustain that load, so one of the two options:
1) more stateless mechanisms will be used (lw4o6, MAP) - which do not give the entire IPv4 address to residential users => so even if the service has an IPv4 address, the clients might have to go through the hurdles to get to it.
Service providers are planning to go IPv6-only, and content providers already note that IPv6 gives a double-digit performance increase compared to IPv4 [1]
2) The residential ISPs will debundle the IPv4 from the cost - given that a lot of the sites average consumer needs (google, facebook, youtube, netflix) are already IPv6-enabled. For this case, you will not be even able to see that something is "wrong". Just the users will click on the link, see it's not reachable, say "huh?" and move on.
[1] https://www.youtube.com/watch?v=EfjdOc41g0s - 1h12 well spent.
1) more stateless mechanisms will be used (lw4o6, MAP) - which do not give the entire IPv4 address to residential users => so even if the service has an IPv4 address, the clients might have to go through the hurdles to get to it.
Service providers are planning to go IPv6-only, and content providers already note that IPv6 gives a double-digit performance increase compared to IPv4 [1]
2) The residential ISPs will debundle the IPv4 from the cost - given that a lot of the sites average consumer needs (google, facebook, youtube, netflix) are already IPv6-enabled. For this case, you will not be even able to see that something is "wrong". Just the users will click on the link, see it's not reachable, say "huh?" and move on.
[1] https://www.youtube.com/watch?v=EfjdOc41g0s - 1h12 well spent.
There will be no abrupt end. Just the price per IP will slowly grow, and the usefulness of this IP will slowly fade.
There's no panic. The trick with IPv6 deployment is predicting two years in advance the moment will you need IPv6 "tomorrow" - because for a lot of orgs that's how long it takes.
I'll repost a link from the recent NANOG meeting here about the folks seriously discussing their plans of going IPv6-only:
https://www.youtube.com/watch?v=EfjdOc41g0s
By the way, if you're reading this from a smartphone in the US, try this link: http://test-ipv6.com/
I thoroughly enjoyed the moment when one networking pro (who dealt with IPv6 20 years ago and not since) was telling me he won't have IPv6 till he retires, realized he had his on his LTE connection and was using it for quite some time already! :-)
I repeat myself from another post:
One out of five users hitting google.com and facebook.com in the US today does so over IPv6.
There's no panic. The trick with IPv6 deployment is predicting two years in advance the moment will you need IPv6 "tomorrow" - because for a lot of orgs that's how long it takes.
I'll repost a link from the recent NANOG meeting here about the folks seriously discussing their plans of going IPv6-only:
https://www.youtube.com/watch?v=EfjdOc41g0s
By the way, if you're reading this from a smartphone in the US, try this link: http://test-ipv6.com/
I thoroughly enjoyed the moment when one networking pro (who dealt with IPv6 20 years ago and not since) was telling me he won't have IPv6 till he retires, realized he had his on his LTE connection and was using it for quite some time already! :-)
I repeat myself from another post:
One out of five users hitting google.com and facebook.com in the US today does so over IPv6.
> From the beginning, the relevant question has been, when will I be unable to get an IP? And every time the answer is "real soon now".
It's going to be a long time before you can't get an IPv4 address at all. But what is going to happen over time is the cost of an IPv4 address is going to go up, since demand will increase, but supply won't.
It's going to be a long time before you can't get an IPv4 address at all. But what is going to happen over time is the cost of an IPv4 address is going to go up, since demand will increase, but supply won't.
Actually, you may be right, in a way. I've seen some government organizations pull a trick to motivate change - they schedule a change for a certain date... a "hard stop" and everyone has to switch. From the outside this looks like insanity, boiling the ocean... panic!!
The trick comes in, they never had any intention for the change to be complete by that date, just to motivate people with the threat of impending required change. Many will scramble or work hard to meet that deadline, but there are always those who are left behind.
Then, to make it work, nearly before the deadline, the deadline is extended for special cases by a reasonable, margin to allow those that don't convert to catch up.
In any case, the goal is to give the illusion that there is a make it or break it deadline for real, and then address the consequences as they come up after the deadline.
The trick comes in, they never had any intention for the change to be complete by that date, just to motivate people with the threat of impending required change. Many will scramble or work hard to meet that deadline, but there are always those who are left behind.
Then, to make it work, nearly before the deadline, the deadline is extended for special cases by a reasonable, margin to allow those that don't convert to catch up.
In any case, the goal is to give the illusion that there is a make it or break it deadline for real, and then address the consequences as they come up after the deadline.
Who is 'they' ?
The organization from the linked site -- ARIN -- American Registry for Internet Numbers.
ARIN has no control over what protocols people use on their networks. They're only responsible for the allocation of new publicly-routable IP address ranges for North American customers.
They've been quite clear and vocal about the fact that they're rapidly running out of addresses and will soon be unable to fulfill requests. There was no urgency when ARIN received its last global /8 allocations four years ago, and there doesn't seem to be any urgency now that we're seemingly weeks away from entirely running out. I don't know what it will take to make people pull their heads out of the sand.
They've been quite clear and vocal about the fact that they're rapidly running out of addresses and will soon be unable to fulfill requests. There was no urgency when ARIN received its last global /8 allocations four years ago, and there doesn't seem to be any urgency now that we're seemingly weeks away from entirely running out. I don't know what it will take to make people pull their heads out of the sand.
IPv6 adoption is surprisingly slow. Shouldn't it happen faster?
It's a classic chicken and egg problem. IPv4 is still "good enough" as far as most people are concerned, so even with the squeeze on available addresses, there's just not quite enough need to come over the inertial against supporting IPv6. Because of that, there's no demand driving adoption from any particular side: ISPs can get away with giving people IPv4 addresses only because IPv4 space is where all the content is, hosting providers have no great impetus so long as they're not seeing much IPv6 traffic[1], their customers know IPv4 and the benefits of all the additional address space are either too abstract or too scary ('Oh, my! That IP address is huge!'), and there's still enough legacy networking equipment, both professional and home, that only supports IPv4 that it can be hard to make a business case to get rid of.
[1] Which is a pity, though not at all universal. The hosting company I work for takes pride in the fact that nearly our whole network, except for some colo boxes, some rapidly disappearing legacy boxes, and the like, is dual stack. Not all hosting providers think this way, and even when they do, they're customers often just ignore IPv6 because they know IPv4 and that's good enough for them. It doesn't help that an embarrassing number of ccTLD registries don't support IPv6 glue records.
[1] Which is a pity, though not at all universal. The hosting company I work for takes pride in the fact that nearly our whole network, except for some colo boxes, some rapidly disappearing legacy boxes, and the like, is dual stack. Not all hosting providers think this way, and even when they do, they're customers often just ignore IPv6 because they know IPv4 and that's good enough for them. It doesn't help that an embarrassing number of ccTLD registries don't support IPv6 glue records.
Few of the big cloud providers -- EC2, Azure, etc. -- support IPv6. That's the big bottleneck.
Fundamentally I think IPv6 itself is fine, but the transition was utterly botched. They should have unshelved 240.0.0.0/4 and mapped IPv6 onto it, allowing IPv4 applications to access select "early adopter" regions of IPv6. That would have been a start.
Fundamentally I think IPv6 itself is fine, but the transition was utterly botched. They should have unshelved 240.0.0.0/4 and mapped IPv6 onto it, allowing IPv4 applications to access select "early adopter" regions of IPv6. That would have been a start.
IPv4 to IPv6 mapping exists for a long time https://en.wikipedia.org/wiki/6to4
No, no no no. 6to4 as a mechanism is the worst mistreatment you can do to your users because of the way it works with asymmetric traffic paths traversing the gateways you can not control.
I think what you meant to post was this: https://en.wikipedia.org/wiki/NAT64
I think what you meant to post was this: https://en.wikipedia.org/wiki/NAT64
Neither of these are actually usable in the real world.
re. 6to4: agreed, and never will, see https://tools.ietf.org/html/rfc7526
re NAT64: not so agreed...
1. T-Mobile USA: they have few millions of IPv6-only subscribers using 464XLAT which has NAT64 as a component.
2. Starting from iOS9, every app submitted to App Store will have to work with IPv6 or across the NAT64 as a criterion for appstore submission:
http://www.internetsociety.org/deploy360/blog/2015/06/apple-...
3. my own anecdata from the IPv6-only default WiFi SSID at FOSDEM conference in Brussels this year is that ~40% of the total devices were able to use IPv6-only SSID behind NAT64 - up from about 15-20% last year. Will be interesting to see the numbers for the next year - with Android 5.0 shipping RDNSS and Apple's move with iOS, this number should go up noticeably.
re NAT64: not so agreed...
1. T-Mobile USA: they have few millions of IPv6-only subscribers using 464XLAT which has NAT64 as a component.
2. Starting from iOS9, every app submitted to App Store will have to work with IPv6 or across the NAT64 as a criterion for appstore submission:
http://www.internetsociety.org/deploy360/blog/2015/06/apple-...
3. my own anecdata from the IPv6-only default WiFi SSID at FOSDEM conference in Brussels this year is that ~40% of the total devices were able to use IPv6-only SSID behind NAT64 - up from about 15-20% last year. Will be interesting to see the numbers for the next year - with Android 5.0 shipping RDNSS and Apple's move with iOS, this number should go up noticeably.
A lot of SMB and even large-ish companies are in total denial mode, still. Most use IPv4 exclusively for all network connectivity. Some places disable IPv6 across the board, in other places it remains enabled by default but ignored.
Some devices won't work, people need retraining, security with less tested stacks is a concern, addresses are harder to remember. It's a nontrivial change to push on to an established network, with a horizon for payoffs beyond the standard political term.
A recent presentation [1] at RIPE conference highlighted that only 6 of the top 30 carriers in the world (based on customer value) are doing anything visible with IPv6. I suspect the rest have some IPv6 strategy cooking on the back burner, but are in no hurry to deploy until their hand is forced.
[1] https://youtu.be/hrEh40_H4r4?t=730
[1] https://youtu.be/hrEh40_H4r4?t=730
Seems like IoT would have much more to offer with IPv6. Currently you buy a "internet enabled" schlage deadbolt for your front door and it connects to cloud to enable remote lock/unlock. If you could count on a visible IP address products/services could skip such things.
Again it's a chicken and egg problem, nobody does anything cool assuming IPv6 because few have it. Few have it, because you can't do anything cool with it.
Again it's a chicken and egg problem, nobody does anything cool assuming IPv6 because few have it. Few have it, because you can't do anything cool with it.
World accessible devices is a pretty scary concept. If you have your garage door controlled by an ESP8266 it would take a single host to denial of service attack it, maybe even just one server to denial of service attack every garage door in the united states.
It's not because it's public addressable that it would be public accessible.
I feel lucky to have our little /27 colo block.
We added IPv6 support to our firewall product earlier this year and it was a big deal - lots of schema and code changes to deal with 128 bit wide addresses and address math. I'd encourage any devs working on new products to bake it in from v1 if you can.
We added IPv6 support to our firewall product earlier this year and it was a big deal - lots of schema and code changes to deal with 128 bit wide addresses and address math. I'd encourage any devs working on new products to bake it in from v1 if you can.
We put IPv6 in pfSense years ago.
Definitely worth all the work.
Definitely worth all the work.
HP doesn't need both those Class A blocks
Say everyone who doesn't "need" a LEGACY /8, by your estimation, gives them back. Then what do we do when those are gone?
Seriously, should we be bolting aftermarket mods on our Datsun to get it another fifty miles or should we just buy a new bus already and get it overwith? Yeah, not everyone fits in the new bus, and that's the problem, but we've been in this dire boat for a long time.
I've seen firsthand how Apple uses 17/8. Asking Apple to renumber that is completely futile. You might as well deploy IPv7, for as much effort it will take. Better to just advance the state of the art instead of squeezing another few days out of IPv4.
Seriously, should we be bolting aftermarket mods on our Datsun to get it another fifty miles or should we just buy a new bus already and get it overwith? Yeah, not everyone fits in the new bus, and that's the problem, but we've been in this dire boat for a long time.
I've seen firsthand how Apple uses 17/8. Asking Apple to renumber that is completely futile. You might as well deploy IPv7, for as much effort it will take. Better to just advance the state of the art instead of squeezing another few days out of IPv4.
Apple is starting to use those for "real" purposes now with their CDN, iMessages, iCloud, etc...
Apple has used them for "real" purposes since the dawn of the very first Internet services offered by the company. It's not recent.
Fortunately there is a market where they can sell the parts they don't need. It could make for a nice quarterly bump if they ever do it.
What happens to the private sector end nodes? Do routers perform NAT from IPV4 to IPV6?
No .. You'd think this was worked out before ipv6 was finalized. Nat64 and other related tech is a mess.
> NAT and other related tech is a mess.
FTFY
FTFY
There are many ways to do so, like dual stack of real IPv6 + RCF6598 for IPv4 - used by many ISPs in Europe where IPv4 space shortage is a real problem.
They continue doing IPv4. Anyone they want to reach needs to be reachable on IPv4 - at least via an IPv4 gateway/proxy