|
|
Breaking out from the (now closed) Swish Fibre megathread: has anyone heard any news about Swish Fibre's "IPv6 project"? Their lack of support for modern IP is by far my biggest bugbear.
Edited by behuk (Thu 08-Jun-23 21:06:50)
|
|
|
Not heard anything since it was mentioned on the mega-thread. Also saw that there are redundancies across the group that Swish is part of, presumably prior to a merger of the groups' various operations, so maybe it's dropped off their radar again.
|
|
|
I'd be interested to here why IPv6 would be of interest.
I had it on BT for years but never saw a use case TBH but I see it more of a privacy issue than a benefit.
OPNSense on Topton N100 - SWISH Fibre 900
PiHole/AdGuard home - Unifi for Wifi
My Broadband Ping
|
|
Register (or login) on our website and you will not see this ad.
|
|
|
I'd be interested to here why IPv6 would be of interest. Many newer ISPs don't have any IPv4 space, so they have to put you on CGNAT, which prevents inbound connections. This limits some internet usage, e.g. hosting games, or connecting remotely into your network via a VPN etc.
If the ISP supplies routed IPv6, then the CGNAT for IPv4 is less of an issue, for all other networks where v6 is available. (ie, not Virgin Media!).
23 years of broadband connectivity since 1999 trial - Live BQM
|
|
|
I'd be interested to here why IPv6 would be of interest. Many newer ISPs don't have any IPv4 space, so they have to put you on CGNAT, which prevents inbound connections. This limits some internet usage, e.g. hosting games, or connecting remotely into your network via a VPN etc.
If the ISP supplies routed IPv6, then the CGNAT for IPv4 is less of an issue, for all other networks where v6 is available. (ie, not Virgin Media!).
I think you can request a non CGNAT IP or pay a little more for a static address so they do offer perfectly reasonable alternatives which work.
OPNSense on Topton N100 - SWISH Fibre 900
PiHole/AdGuard home - Unifi for Wifi
My Broadband Ping
|
|
|
I think you can request a non CGNAT IP or pay a little more for a static address so they do offer perfectly reasonable alternatives which work. Some alt net ISPs have the options, but many charge a LOT more (monthly) for either a static, or public IPv4 as they have so few.
23 years of broadband connectivity since 1999 trial - Live BQM
Edited by jchamier (Sat 10-Jun-23 10:44:13)
|
|
|
Tailscale also works behind CGNAT I believe so there are always options to work around it but best option is to order a service that has the features you require rather than what is ‘coming soon’.
Swish static IP is only £3 pm so not a dealbreaker by any stretch and at least it is an option unlike BT residential services.
OPNSense on Topton N100 - SWISH Fibre 900
PiHole/AdGuard home - Unifi for Wifi
My Broadband Ping
|
|
|
Swish static IP is only £3 pm so not a dealbreaker by any stretch and at least it is an option unlike BT residential services. Great news for those in Swish coverage areas. My area is currently being built by two separate companies, neither are Swish, or Openreach. Its unclear what either charge for a static v4 address, but a quick look shows they both support public v6.
23 years of broadband connectivity since 1999 trial - Live BQM
|
|
|
I'd be interested to here why IPv6 would be of interest. Many newer ISPs don't have any IPv4 space, so they have to put you on CGNAT, which prevents inbound connections. This limits some internet usage, e.g. hosting games, or connecting remotely into your network via a VPN etc.
If the ISP supplies routed IPv6, then the CGNAT for IPv4 is less of an issue, for all other networks where v6 is available. (ie, not Virgin Media!).
I think you can request a non CGNAT IP or pay a little more for a static address so they do offer perfectly reasonable alternatives which work.
So yeah, a public IPv4 address is definitely helpful. But let's look at the maths... Swish have 9216 IPv4 addresses - assuming they sell them all to residential gigabit customers (each paying £50 + £3 per month), that limits their total annual revenue to ~£6m. Not bad, but I suspect a long way off the ambitions of Fern Fibre / Octopus Investments (I suppose they could buy more, but ~$40 per IP seems painfully expensive given the cost is avoidable). Obviously there are various incorrect assumptions here (e.g. they can't sell all the addresses as some will be required for infrastructure, some customers will buy cheaper packages, and some customers will be happy with CGNAT).
Thinking more broadly from a business perspective, I suspect a number of customers will have issues with CGNAT (e.g. performance, issues with gaming / P2P, etc.) and will write Swish off as opposed to paying for a public IP because most customers aren't hugely technical. Also, CGNAT appliances aren't cheap! IPv6 doesn't mitigate the need for CGNAT / NAT64 / some solution for accessing IPv4-only websites, but as IPv6 traffic increases fewer and fewer packets will need it.
|
|
|
Tailscale also works behind CGNAT I believe so there are always options to work around it but best option is to order a service that has the features you require rather than what is ‘coming soon’.
So from a technical perspective, I'd like IPv6 for a couple of reasons. Firstly I'd like to be able to connect to hosts using IPv6 (I use Mythic Beasts and Scaleway for hosting, and they both charge extra for public IPv4 addresses). Secondly, I'd like to be able to host from home using IPv6 -- e.g. experimentally using IPv6 for a k8s cluster. As you mention there are other solutions for inbound connectivity (e.g. tailscale, I personally use Cloudflare Tunnel for some use-cases) -- but IMO getting rid of RFC1918 addressing should be the long term goal (I appreciate this might be controversial, but let's not de-rail the thread!).
I could use a VPN / tunnel broker / etc. to get IPv6 connectivity, but it doesn't feel unreasonable to ask for native IPv6 in 2023, given the original IPv6 RFC was published over 26 years ago. As a techie, when I see a network cutting corners by not implementing IPv6, it makes me wonder what other corners they're cutting.
And yeah -- ideally I'd order symmetrical gigabit fibre with IPv6, but that's not yet available in my town (from Swish because their network doesn't yet support IPv6, or from Lightning Fibre because their build isn't ready yet). Overall I think Swish is the best option for me at the moment (symmetrical gigabit with a public IPv4 address is better than 80Mb down / 20Mb up with a /48 of IPv6, IMO).
|
|
|
Breaking out from the (now closed) Swish Fibre megathread: has anyone heard any news about Swish Fibre's "IPv6 project"? Their lack of support for modern IP is by far my biggest bugbear. Same here. It's not an absence of functionality it just begs the question of why any newcomer ISP wouldn't implement IPv6 from day one. Is it ignorance? Is it a lack of technical ability or resources? Or do they just not care enough about the service they are providing?
My own ISP - IDNet - has been offering dual stack IPv4/6 for nearly twenty years now. It's not a new protocol. Any ISP that doesn't currently offer and support it is a poor ISP. Even the excuse of a network needing to be upgraded or support staff being trained no longer washes for me.
My mail server is accessible via both IPv4 and IPv6 just like any proper server should be.
---
Andrue Cope
Brackley, UK
Edited by Andrue (Sun 11-Jun-23 10:39:31)
|
|
|
I've managed to get an update from Swish's customer service team:
Swish Fibre are currently in the process of merging with other Full Fibre ISP's under Fern Trading Group and at this stage, IPv6 works and testing has come to a halt at the time being. This does not mean this will not be worked on in the future, as once the necessary changes to streamline all of the companies network builds, equipment and departments are completed, there should be more scope and understanding as to when this will become available. In addition to this, Giganet (one of the companies we are merging with) currently offer IPv6 to their customers, which essentially brings us a step closer to implementing this on to our network once the merge is completed.
I wonder if Giganet's new network (which users on other forums have commented on) will be used by all of the Fern Fibre ISPs...
|
|
|
|
I'm at the point now where I will not spend time justifying why I need IPv6 - if people are curious about the advantages there are many written resources that explain the technology and presentations from the UK IPv6 council where its implementation is discussed. If I ask an ISP if they support IPv6 I want a yes or no answer (preferably a yes), but my requirements are not up for debate.
|
|
|
Breaking out from the (now closed) Swish Fibre megathread: has anyone heard any news about Swish Fibre's "IPv6 project"? Their lack of support for modern IP is by far my biggest bugbear. Same here. It's not an absence of functionality it just begs the question of why any newcomer ISP wouldn't implement IPv6 from day one. Is it ignorance? Is it a lack of technical ability or resources? Or do they just not care enough about the service they are providing?
The majority of altnets I've encountered have not got v6 support. Some of them have implemented CGNAT, but for whatever reason still not v6. It is alarmingly common.
|
|
|
From what has been discussed I can see it as a nice to have at least until the IPv4 addresses run out although this has been a topic for 20 years.
I was curious as I have never had a requirement to use it, I don't feel that not having it has restricted any internet usage and from a corporate perspective it is completely non-existent in our organisation, probably disabled for complexity or security reasons.
OPNSense on Topton N100 - SWISH Fibre 900
PiHole/AdGuard home - Unifi for Wifi
My Broadband Ping
|
|
|
From what has been discussed I can see it as a nice to have at least until the IPv4 addresses run out although this has been a topic for 20 years.
I was curious as I have never had a requirement to use it, I don't feel that not having it has restricted any internet usage and from a corporate perspective it is completely non-existent in our organisation, probably disabled for complexity or security reasons.
You are right: if you have an IPv4 connection, then the whole of the Internet is reachable, apart from a few insignificant hobby sites. You won't get to see any more with IPv6.
However if you're behind an IPv4 CGNAT, that does apply a lot of limits to what you can do with your Internet connection. Not only can you not receive *any* inbound connections at all, but you are sharing a public IP address with other people: so if one of them does something bad, Plod may come knocking at your door.
So in an ideal world:
1. All end users would get IPv6 in addition to IPv4, so that more and more of their traffic bypasses NAT/CGNAT
2. All web sites would make themselves available over IPv6 in addition to IPv4.
Then slowly, the need for IPv4 would drain away.
In practice, there's a chicken-and-egg problem. The end user ISPs feel the lack of IPv4 addresses acutely, but are forced to provide IPv4 access because without it, their customers wouldn't be able to reach most websites. However, the web sites know that the whole world can reach them over IPv4, so they have no incentive to spend time enabling IPv6.
Even major organisations like the BBC, who are both well-funded and traditionally recognised for their technical leadership, have not IPv6-enabled their sites.
Most websites are concerned about user tracking and advertising and monetising. I suspect that when they already have all that stuff working on IPv4, they are worried that it might not work properly on IPv6, and are not inclined to invest the time making sure that it does.
Also, websites are not worried about lack of availability of IPv4 addresses. They have been sharing IPv4 addresses for years - via virtual hosting, reverse proxies, and content delivery networks. The cost of an IPv4 address is trivial compared to the cost of a good domain name, and especially the cost of lost business if they weren't visible to the majority of Internet users.
|
|
|
You are right: if you have an IPv4 connection, then the whole of the Internet is reachable, apart from a few insignificant hobby sites. You won't get to see any more with IPv6.
If you insert the words English-language before "Internet" in the first sentance, and after more in the second sentance add "English-language internet" you will be correct.The Asia Pacific region had the least number of IPv4 addresses in the 1970s, which means companies that do business with AP often have to enable IPv6.
23 years of broadband connectivity since 1999 trial - Live BQM
|
|
|
Same here, my own servers are all available on IPv6 and I have IPv6 only systems for work that require me to have an IPv6 address.
The award for the company taking the most time to get their implementation of IPv6 working has to be Uno, as its been "coming soon" for a decade or more! They've lost at least one customer due to just not sorting it out.
If an ISP can't get IPv6 working this day and age then you have to question a) Just how good is their kit b) Just how good is their networking knowledge.
|
|
|
If an ISP can't get IPv6 working this day and age then you have to question a) Just how good is their kit b) Just how good is their networking knowledge.
Or also c) question whether there is any actual demand from their customers.
OPNSense on Topton N100 - SWISH Fibre 900
PiHole/AdGuard home - Unifi for Wifi
My Broadband Ping
|
|
|
If an ISP can't get IPv6 working this day and age then you have to question a) Just how good is their kit b) Just how good is their networking knowledge. Major popular ISPs such as Plusnet and Virgin Media don’t support IPv6… no demand and probably some cost they don’t see it worth incurring.
23 years of broadband connectivity since 1999 trial - Live BQM
|
|
|
If an ISP can't get IPv6 working this day and age then you have to question a) Just how good is their kit b) Just how good is their networking knowledge. Major popular ISPs such as Plusnet and Virgin Media don’t support IPv6… no demand and probably some cost they don’t see it worth incurring.
Yes, they are popular but neither are extolled for their technical excellence which rather makes my point.
---
Andrue Cope
Brackley, UK
Edited by Andrue (Thu 15-Jun-23 22:30:49)
|
|
|
However if you're behind an IPv4 CGNAT, that does apply a lot of limits to what you can do with your Internet connection. Not only can you not receive *any* inbound connections at all, but you are sharing a public IP address with other people: so if one of them does something bad, Plod may come knocking at your door.
Having Plod come knocking is perhaps a tad extreme. It would have to be pretty serious for them to go through all the ISP's routing tables to distinguish me from all the other concurrent users of that public IP, though I'm sure GCHQ could do that easily if they wanted to. But being behind CGNAT for the first time now, I do find:
1) there seems to be an increased incidence of those wretched reCaptcha things (pick all the squares with US style fire hydrants);
2) I have an issue with email non-delivery to some contacts, which is very hard to pin down as they just disappear completely, but I suspect has at least something to do with the reputation of someone/something else sharing my IPv4 address;
3) I'm not bothered about hosting games or websites locally, but I can't run a BQM.
Or also c) question whether there is any actual demand from their customers.
In Swish's case at least, this can not be the case, I have made my views very clear to them, as I know others have too. I don't see why I should pay extra for a static IPv4 to work around a glaring deficiency in their network. I have told them I will not recommend Swish to any friends or neighbours until they fix it. I would leave myself if I had an acceptable alternative.
|
|
|
Yes, they are popular but neither are extolled for their technical excellence which rather makes my point. But 5+ million customers don't leave/complain about the lack of v6, so its not impacting business. For technical excellence I would be with AAISP if I could have got 50/10 I would have, but OR wires and crosstalk didn't support.
23 years of broadband connectivity since 1999 trial - Live BQM
|
|
|
However if you're behind an IPv4 CGNAT, that does apply a lot of limits to what you can do with your Internet connection. Not only can you not receive *any* inbound connections at all, but you are sharing a public IP address with other people: so if one of them does something bad, Plod may come knocking at your door. The ISP will keep records of which customer has which internal IP and CGNAT mapping for RIPA compliance.
23 years of broadband connectivity since 1999 trial - Live BQM
|
|
|
...However if you're behind an IPv4 CGNAT, that does apply a lot of limits to what you can do with your Internet connection. Not only can you not receive *any* inbound connections at all...
I'm pretty sure the internet wouldn't work without *ANY* inbound connections
The takeaway is that you have to use a service that meets your requirements and CGNAT is perfectly acceptable for 99% of internet users who don't give a rodents behind about their ISPs 'technical ability' as long as it works for Netflix and Facebook.
For those that want self-hosting or VPNs etc then choose a service that supports it rather than moaning about it not but I agree that IF IPv6 was supported it would alleviate a number of edge cases and people like us using prosumer grade routers, BCM, separate APs etc are very much edge cases.
OPNSense on Topton N100 - SWISH Fibre 900
PiHole/AdGuard home - Unifi for Wifi
My Broadband Ping
|
|
|
I'm pretty sure the internet wouldn't work without *ANY* inbound connections  In firewall terms, "inbound" usually means unsolicited inbound, quite different to "replies" to requests that have gone out. Stateful firewalls and NAT tables etc. or connection-tracking as (conntrack) as Linux modules called it.
23 years of broadband connectivity since 1999 trial - Live BQM
|
|
|
I'm pretty sure the internet wouldn't work without *ANY* inbound connections  In firewall terms, "inbound" usually means unsolicited inbound, quite different to "replies" to requests that have gone out. Stateful firewalls and NAT tables etc. or connection-tracking as (conntrack) as Linux modules called it.
Thanks for mansplaining.
OPNSense on Topton N100 - SWISH Fibre 900
PiHole/AdGuard home - Unifi for Wifi
My Broadband Ping
|
|
|
Thanks for mansplaining. No need to be rude, and assuming gender. It was unclear from thread other knowledge.
23 years of broadband connectivity since 1999 trial - Live BQM
|
|
|
If an ISP can't get IPv6 working this day and age then you have to question a) Just how good is their kit b) Just how good is their networking knowledge. Major popular ISPs such as Plusnet and Virgin Media don’t support IPv6… no demand and probably some cost they don’t see it worth incurring.
The need for Plusnet and Virgin to adopt IPv6 is reduced because those ISPs are hording large amounts of IPv4 address space -- e.g. Plusnet have ~2.1 million addresses, and Virgin Media have ~9.4 million addresses. Avoiding Carrier-Grade NAT isn't the only reason why a consumer would want* IPv6, but I think it's the main one.
(* I suspect most consumers don't know what IPv6 is, but recognise the issues caused by Carrier Grade NAT such as poor IP reputation and issues with online gaming / other P2P applications)
|
|
|
Breaking out from the (now closed) Swish Fibre megathread: has anyone heard any news about Swish Fibre's "IPv6 project"? Their lack of support for modern IP is by far my biggest bugbear. Same here. It's not an absence of functionality it just begs the question of why any newcomer ISP wouldn't implement IPv6 from day one. Is it ignorance? Is it a lack of technical ability or resources? Or do they just not care enough about the service they are providing?
The majority of altnets I've encountered have not got v6 support. Some of them have implemented CGNAT, but for whatever reason still not v6. It is alarmingly common.
Yeh I think thats pretty bad, the likes of Virgin Media have the excuse they have millions of customers on a single stack network they risk disconnecting if they make a technical error, and of course all their customers have a public IP so its less if an issue for them anyway.
A brand new ISP that is utilising CGNAT should be designing their network with v6 bedded in from day 1, there is no excuse, they must have done a rush to market network build.
|
|
|
From what has been discussed I can see it as a nice to have at least until the IPv4 addresses run out although this has been a topic for 20 years.
I was curious as I have never had a requirement to use it, I don't feel that not having it has restricted any internet usage and from a corporate perspective it is completely non-existent in our organisation, probably disabled for complexity or security reasons.
Well they have ran out, in some parts of the internet getting IPv4 is either extremely difficult or very expensive, the only way that can be solved is a internet wide switchover, but the isp's that have hoarded ipv4 with a lack of local urgency dont do the switch and here we are.
Web masters on many web sites of course have also not deployed v6, because they dont need to do so to keep their website online and keep it on google, so many do the absolute minimum, SSL take up didnt increase until google made it a requirement for max SEO.
I think the situation wont ever be solved, these altnets will eventually be gobbled up by someone with loads of v4 at which point those customers will get moved of CGNAT.
Edited by Chrysalis (Wed 16-Aug-23 23:08:59)
|
|
|
The ISP will keep records of which customer has which internal IP and CGNAT mapping for RIPA compliance.
Yes, but if you have a number of customers all using the same public IPv4 address, the only thing which distinguishes them is the TCP/UDP port number. The far end (the receiver of the connection) is unlikely to keep a record of this in their logs - only the source IP address. Plod then has a list of possible users, and may knock on the wrong door.
A related issue is the geolocation assigned to an IP address, which Plod tends to follow blindly:
https://arstechnica.com/tech-policy/2016/08/kansas-c...
|
|
|
Yes, but if you have a number of customers all using the same public IPv4 address, the only thing which distinguishes them is the TCP/UDP port number. I assumed under RIPA and its successors that the ISP had to keep such mapping logs for at least 12 months.
The far end (the receiver of the connection) is unlikely to keep a record of this in their logs - only the source IP address. Plod then has a list of possible users, and may knock on the wrong door.
Yes, a website such as Thinkbroadband only gets to see the source IP, but if Plod is involved they go to the ISP and ask the ISP to map that back to the user. The ISP then has the hard work of trawling the CGNAT logs, in the same way they used to look at their DHCP logs.
A related issue is the geolocation assigned to an IP address, which Plod tends to follow blindly:
https://arstechnica.com/tech-policy/2016/08/kansas-c...
Geolocation is a complete mess; and worse in some countries than others.
23 years of broadband connectivity since 1999 trial - Live BQM
|
|
|
Yes, a website such as Thinkbroadband only gets to see the source IP
Actually, it gets to see the source port as well, but rarely would it bother to log it.
but if Plod is involved they go to the ISP and ask the ISP to map that back to the user. The ISP then has the hard work of trawling the CGNAT logs, in the same way they used to look at their DHCP logs.
Correct: but the point is, with CGNAT, at any given point in time *multiple users* will have been using that IP address. Not just one.
|
|
|
Correct: but the point is, with CGNAT, at any given point in time *multiple users* will have been using that IP address. Not just one.
Agreed, so the CGNAT system needs to log real user (internal IP) & public IP allocated & port and the time. Then at least some correlation can be done.
No real difference to how the mobile networks have been working for 10/15 years, almost all domestic users on a mobile (2G/3G/4G/5G) connection is behind CGNAT. Some corporate and special services provide public IP. (and some Three mobile broadband offerings).
23 years of broadband connectivity since 1999 trial - Live BQM
|
|
|
|
Adding my vote to this thread. I was very surprised that Swish doesn't support ipv6, incredible really.
|
|
|
A related issue is the geolocation assigned to an IP address, which Plod tends to follow blindly:
https://arstechnica.com/tech-policy/2016/08/kansas-c...
Geolocation is a complete mess; and worse in some countries than others.
There is a technical solution to this but it doesn't work because like all other technical solutions it requires people to follow it and nobody does:
https://geolocatemuch.com/
Instead of this simple Geofeed solution we have multiple different companies maintaining their own databases and selling this as a service to other companies which creates a whole mess and takes responsibility away from network operators.
|
|
|
|
Given the role of IP addressing in network routing an given the nature of the internet as a network, [not to mention the extension of the internet to mobile devices] geolocation is an extremely ill-conceived idea.
It deserves to fail.
|
|
|
Given the role of IP addressing in network routing an given the nature of the internet as a network, [not to mention the extension of the internet to mobile devices] geolocation is an extremely ill-conceived idea.
It deserves to fail.
It only has to be accurate enough to the city level. Providing the exact longitude/latitude or post code, etc, is absurd, but just the country and city is enough for Netflix to show you its UK catalogue and the BBC to deny you its catalogue you pay TV license for when you're abroad.
|
|
|
It only has to be accurate enough to the city level. Providing the exact longitude/latitude or post code, etc, is absurd, but just the country and city is enough for Netflix to show you its UK catalogue and the BBC to deny you its catalogue you pay TV license for when you're abroad.
Even at that level, it is absurd.
|