Looking for a sponsoring LIR for my ASN.
I run a small non‑commercial network with a WireGuard uplink via Route64 and plan a second upstream (HE POP) for redundancy and BGP/IPv6 learning.
I can maintain IRR/RPKI. Any LIR willing to sponsor an ASN is welcome.

#BGP #ASN #IPv6 #Multihoming #HomeLab #NetOps #NetworkEngineering #RIPE #LIR #NOG #PLNOG #DENOG #NLNOG #UKNOF #Routing #Sysadmin #Route64 #HurricaneElectric

@tschaefer ich habe eher Bedarf nach #NAT46 in #Deutschland.

Does anyone know how to setup #NAT46 on #pfSense within a #LAN?

The Problem is that I want to provide #IPv6-connectivity on #WAN without having to deal with IPv6 in #LAN.

  • Right now I'm ponderig using fc:: /7 on #LAN with #DHCPv6 but the problem is that #Vodafone's shitbox connection is flaky af and the only #Fallback that I currently have is their shitty #LTE which is #IPv4only woth #CGNAT in #RFC1918 ( 10.0.0.0 /8) and no IPv6 connectivity, thus everytime shit flip-flops connectivity is completely gone on IPv6 and only #IPv4 is on that backup link.

So since I don't have a Provider-Independent IP space and my #ISP is so fucking incompetent that I hereby beg @BNetzA to finally seize their network and nationalize/socialize it I am basically stuck on IPv4 connectivity.

  • The only workarounds I know would necessitate using a #HurricaneElectric #GIF-Tunnel for IPv6 on fallback, which won't work because OFC Vodafone doesn't offer me a static IPv4 or even stazic IPv6-Subnet on their mobile network and I got #DualStack on #WAN on the primary network.

  • The problem re: routing exists for all #MultiWAN setups and I won't pay for #Vipritnet or setup my own #ASN and blow money on a @ripencc membership just to get PI Address Space and having to setup my own Gateway to VPN into through all my WAN & #WWAN connections.

Also the false premise of many sites to prefer IPv6 over IPv4 causes everything to break apart at the slightest disruption.

  • IPv6 really annoys me because unlike IPv4, it just doesn't work and everytime I have to deal with it it's a pain in the ass...
Kevin Karhan :verified: (@[email protected])

#IPv6 is a mistake! - Noone needs #128bit address space! - 21+ years of protocol existance, yet no mandatory & widespread adoption… - You want to have more than 1 PC per line? We have a solution for it, it's called #NAT! - IPs should not have variable lenghts and hexadecimal digits!!! #SLAAC? #RouterAdvertisement?? #6rd??? - These are real #IPv6only mechanisms deployed in the real world! *"Yes, I'd love to have all my devices loose their #IP assignments everytime my #WAN connection resets/disconnects/…!"* - They have played us for absolute fools! #meme #shitpost #IPv4 #Enshittification

Infosec.Space

At #denog17, the people behind #Netzbremse unveiled a new feature: a #speedtest using five different transit providers to (hopefully) uncover unfair peering practices of ISPs, in this case the #DeutscheTelekom #Telekom, but this is very likely helpful for other situations as well. I wanted to dig deeper and found that it uses five different IPv4 prefixes of #Cloudflare that are advertised to different transit providers. Using #HurricaneElectric’s BGP view we get:

I’m not deep enough into the BGP game to understand what transit provider is really pushed for in each prefix.

(unfortunately #IPv4only, I guess they didn’t want to dedicate five /48 prefixes as well for this project).

Link to the speedtest: https://netzbremse.de/speed/

Netzbremse - Die Telekom drosselt das Netz!

Wenn du Kund:in der Deutschen Telekom bist und manche Webseiten einfach nicht laden wollen, dann haben wir vielleicht die Lösung für dein Problem!

Proxy Services Feast on Ukraine’s IP Address Exodus – Krebs on Security

Proxy Services Feast on Ukraine’s IP Address Exodus – Krebs on Security

@landley @jschauma @ryanc @0xabad1dea yeah, the exhaustion problem would've been shoved back with a #64bit or sufficiently delayed by a 40bit number.

Unless we also hate #NAT and expect every device to have a unique static #IP (which is a #privacy nightmare at best that "#PrivacyExtensions" barely fixed.)

  • I mean they could've also gone the #DECnet approach and use the #EUI48 / #MAC-Address (or #EUI64) as static addressing system, but that would've made #vendors and not #ISPs the powerful forces of allocation. (Similar to how technically the #ICCID dictates #GSM / #4G / #5G access and not the #IMEI unless places like Australia ban imported devices.

I guess using a #128bit address space was inspired by #ZFS doing the same before, as the folks who designed both wanted to design a solution that clearly will outlive them (way harder than COBOL has outlived Grace Hopper)...

If I was @BNetzA I would've mandated #DualStack and banned #CGNAT (or at least the use of CGNAT in #RFC1918 address spaces) as well as #DualStackLite!

@openalt Tohle řeším taky. Vodafone modem mám v bridge modu, za ním #turris router s veřejnou statickou IPv4 a s tunelovanou IPv6 od #HurricaneElectric.
Dospěl jsem k tomu, že turris sám resolvuje DNS přes #kresd, a u ručně udržovaného seznamu adres odebírá IPv6 adresy z odpovědi a potlačuje DNSSEC.

#IPv6 household/home office subnetting day for me. I've used the free #HurricaneElectric #TunnelBroker for a few years for outbound access using a single routed /64 (because my ISP doesn't offer IPv6 and doesn't have a timeline to support it).

Time to divvy up that /48 into /64s (per physical or VLAN segment), and corral all the VMs per physical server within a /112 address space.

First project on IPv6? Setting up/testing mail servers on a few dormant domains I registered years ago - thanks to the #RYOMS book (technically the more aptly named "Ruin your mail by running it yourself, with insights from Darth Mailer" special edition by @mwl

I think the hardest part will be ignoring the 10.x.y.z IPv4 addresses I've used for years to remember specific servers/workstations, and relying on their DNS names instead.