I remember reading about full IPv4-space scans showing some fairly massive blocks that were allocated but unused. As I recall it was well over 10% of the overall space that could theoretically be reclaimed and redistributed with a hand-wave.
Anything that gets IPv6 adoption to mainstream is a Good Thing, but more likely we'll just start seeing the $1/mo/IP become $2/mo/IP, and upward... The squeeze will just continue as people make more money off of it, and we'll still need IPv4 addresses for compatibility with people running Windows XP in 2020.
>I remember reading about full IPv4-space scans showing some fairly massive blocks that were allocated but unused.
Just because an IP doesn't answer to someone - especially coming from the general internet - doesn't mean it's not in use. This should be obvious to anyone even with the tiniest amount of understanding of TCP/IP networking and IT in general. Hence the authors of such a 'scan' aren't that credible to me. Unless 'scan' is something totally different.
If a machine doesn't answer to the Internet, it has no need of a public IPv4 address. A machine that only answers to other machines in the same organization should be assigned an address in the 10.0.0.0/8 range. If the organization is not large, even 192.168.0.0/16 would do. In fact, many people would argue that assigning public IP addresses to intranet resources is very bad for security.
Of course, some of these machines actually might have valid justification for squatting on a public IPv4 address. Perhaps their firewalls are configured to drop all packets except those from a handful of "trusted" IP addresses, so a random scanner on the Internet gets no response.
But I doubt that such cases account for the majority of "seemingly unused" IPv4 blocks. What's more likely is that some large organization was assigned a massive block of IPs 20-30 years ago and never found much use for them. IBM owns 9/8. Xerox owns 13/8. HP owns 15/8. Apple owns 17/8. Ford owns 19/8. Several pharmaceutical and chemical companies also own an /8 each, as do some universities. Do they really need 16.7 million public IPv4 addresses? Of course not. But I wouldn't be surprised if they started to sell bits and pieces of their blocks once the price per IP goes up enough.
A machine that only answers to other machines in the same organization should be assigned an address in the 10.0.0.0/8 range. If the organization is not large, even 192.168.0.0/16 would do. In fact, many people would argue that assigning public IP addresses to intranet resources is very bad for security.
That's a horrible hack and those people are wrong. Separate your concerns; addresses for addressing, firewalls for firewalling. Using private addresses adds extra complications; what if someone's home network uses the same range and they want to connect to your VPN? What if you merge with another company that's using the same range? What if you want to use FTP or SIP or any other protocol that uses the internet the way it was intended to connect to a server in a different office, are your packets going to make it through or not? You'll observe that private addresses have been deliberately left out of IPv6, for good reason.
B) I agree there are inconveniences and complications with using private addresses in ipv4. But it seems to be necessary thrift in the ipv4 world of rapidly expiring address space; using public routable ipv4 addresses for machines which do not communicate with the public internet is perhaps a luxury we can not afford, even in cases where to do otherwise is inconvenient or complicated.
These /8's have been historically been used internally there's no reason they should be handed back. Handing them back would just prolong the migration to IPv6 for limited benefit.
I imagine the only reason you would use a IPv6 private address is if you didn't have allocated global ones. It's just replacing no chance of collision with some chance of collision.
You are defending the broken windows fallacy. Wikipedia can explain better than I do, but the TLDR is simply : you are defending useless destruction of value, the end result is that everyone's poorer, nothing else.
No, just the opposite. There would be real costs for those companies that have /8s to move away from them. Meanwhile the gains would be minimal - at best it might allow some organizations to put off moving to IPv6 for a few months.
The squeeze will just continue as people make more money off of it, and we'll still need IPv4 addresses for compatibility with people running Windows XP in 2020.
Why? A router could still offer private IPv4 and encapsulate IPv4 packets in IPv6. The carrier can decapsulate IPv6 packets and perform NAT.
In fact, this is how my home cable connection works (per DS-Lite [1]). Our modem/router only gets an IPv6 address, but IPv4-only devices work fine.
I'm not sure if the OP referenced Win XP purely based on the IPv4->IPv6 discussion but Win XP is also extremely relevant for IP address space consumption due to not supporting TLS extension SNI [1].
SNI removes the requirement from HTTPS websites to host one domain per IP. This is done by having hostname part of the initial handshake.
Many websites or at least most (hopefully all) webapps these days serve over https, at least the ones that require user input like login. So there's the need for at least one public IP per site.
With SNI these could be all served from the same IP.
Now imagine CDN services like AWS CloudFront -- to support sites with SSL certificates you must use one IP per cert in EACH region or whatever the distribution granularity is.
Now this my friends is why AWS CloudFront asks $600/mo for each custom SSL cert domain and with SNI custom SSL it costs $0/mo.
As soon as all the 99.9% browsers/clients support SNI we'll be living in a better place with more free IPs. So we can finally distribute static content from CDN through custom SSL without the $600/mo pricetag.
It's naive to think everyone would go to SNI-based hosts with IPs shared with strangers but at least within the same datacenter for the same company IPs can be more easily conserved.
Yea, I should have been more specific. Chrome and Firefox DO have their own TLS with SNI and SNI is enabled for them in Win XP. The issue is relevant for all IE versions on WinXP.
10% wouldn't last us very long - that's less than two years at current growth rates, and growth is still accelerating. At some point the cost is higher than just getting on with switching to v6.
Yeah, IPv4 is pretty much empty. Lots of companies own a /8 all to themselves, like Xerox (13.0.0.0/8), Apple (17.0.0.0/8), USPS (56.0.0.0/8) and Ford (19.0.0.0/8) to name a few. None of them allocate even the tiniest portion of them.
There are usage requirements for IP addresses now. I have to substantiate the allocation.
I think if ARIN wanted to, they could give everyone a year to "substantiate their allocation" and set the policy something like "companies must return for reallocation any overallocations."
The risk of not returning an overallocation, well I'm not sure. ARIN certainly has teeth, and companies should simply be expected to correct these huge overallocations.
Just like the open source community comes together to solve serious problems, if we as a community enforced an ethical standard and some key people stood up raised this as an issue, I'm willing to bet ARIN could replenish a stockpile of IPv4 space.
So the question I'm asking is, since ARIN is empty, clearly they aren't interested in keeping a stockpile of addresses. Why not? I guess the more generous alternative is simply they have failed spectacularly at their stated goal.
I admit that I am not familiar with ARIN, but if it is anything like APNIC (Asia Pacific) then those big Class A Allocations are protected as legacy allocations. As such they are not required to give the legacy allocations up and its questionable if the RIR could even revoke them.
ARIN can go over the pool of post 1997 addresses they have allocated, but I think you would find much smaller unallocated blocks.
Take back those four and you can delay the v4 armageddon by about three months. Longer if you still apply the extra-strict rules used during the armageddon runup.
When the three months are up you can go looking for four more companies, and hire some more lawyers too.
There is no requirement for (historical) IP addresses allocations to be publicly routable. Unfortunately many companies own large allocations that they are quite rightly able to use for internal allocations.
The only way they are going to give them up is if the is worth their while financially.
You're right, the "Windows XP User on IPv4" is just an allegory of the critical mass of users that will keep us from dropping our IPv4 addresses many years into the future.
Put another way, what is the incremental value to provide access to your service to those IPv4 only users/devices? Whatever that value is, in theory you would be willing to pay a portion of that for access to IPv4 address space.
Luckily supply is not really constrained, so much as it is controlled. You can always get more IPs if you need them, but the cost associated I think will continue to increase... until enough people not only just support IPv6, but actually abandon their IPv4 addresses.
When the only devices that your software or service is designed to run on all support IPv6, then there's "no point" in having an IPv4 address. You almost have to get to the point where IPv4 is "not worth the trouble". And we are very, very far from that point I think. More to the point, more people are likely to think that it's IPv6 that is not worth the trouble.
Look at the other side of the coin though. If you have a service that only talks ipv6, you will be insulated from all the unsupported, unpatched, and trojan/virus laden XP machines for years to come!
My strongest incentive for implementing IPv6 at work is that Gmail is advertising MX hosts that have both IPv4 and IPv6 addresses. So on systems which are IPv6 capable, and where your OS either picks a random IPv4 or IPv6 address or prefers IPv6, you'll end up getting lots of noise when it tries IPv6 and fails and falls back to the next address if you don't have IPv6 connectivity set up.
Could of course just ignore that, but it's a good low pressure reminder to get around to sorting out IPv6...
10% gets us something like 6 months from memory - more than nothing, but not enough to hold off the inevitable!
Windows XP is a pain all right, the lack of SNI along with the limited v6 support means anyone using it really is stuck on v4.
Maybe the recent EOL for XP will cause a dramatic shift in the number of people continuing to use it? At least in the more well-off countries like the US, UK etc, opening the door for SNI :)
Comments
I remember reading about full IPv4-space scans showing some fairly massive blocks that were allocated but unused. As I recall it was well over 10% of the overall space that could theoretically be reclaimed and redistributed with a hand-wave.
Anything that gets IPv6 adoption to mainstream is a Good Thing, but more likely we'll just start seeing the $1/mo/IP become $2/mo/IP, and upward... The squeeze will just continue as people make more money off of it, and we'll still need IPv4 addresses for compatibility with people running Windows XP in 2020.
>I remember reading about full IPv4-space scans showing some fairly massive blocks that were allocated but unused.
Just because an IP doesn't answer to someone - especially coming from the general internet - doesn't mean it's not in use. This should be obvious to anyone even with the tiniest amount of understanding of TCP/IP networking and IT in general. Hence the authors of such a 'scan' aren't that credible to me. Unless 'scan' is something totally different.
If a machine doesn't answer to the Internet, it has no need of a public IPv4 address. A machine that only answers to other machines in the same organization should be assigned an address in the 10.0.0.0/8 range. If the organization is not large, even 192.168.0.0/16 would do. In fact, many people would argue that assigning public IP addresses to intranet resources is very bad for security.
Of course, some of these machines actually might have valid justification for squatting on a public IPv4 address. Perhaps their firewalls are configured to drop all packets except those from a handful of "trusted" IP addresses, so a random scanner on the Internet gets no response.
But I doubt that such cases account for the majority of "seemingly unused" IPv4 blocks. What's more likely is that some large organization was assigned a massive block of IPs 20-30 years ago and never found much use for them. IBM owns 9/8. Xerox owns 13/8. HP owns 15/8. Apple owns 17/8. Ford owns 19/8. Several pharmaceutical and chemical companies also own an /8 each, as do some universities. Do they really need 16.7 million public IPv4 addresses? Of course not. But I wouldn't be surprised if they started to sell bits and pieces of their blocks once the price per IP goes up enough.
That's a horrible hack and those people are wrong. Separate your concerns; addresses for addressing, firewalls for firewalling. Using private addresses adds extra complications; what if someone's home network uses the same range and they want to connect to your VPN? What if you merge with another company that's using the same range? What if you want to use FTP or SIP or any other protocol that uses the internet the way it was intended to connect to a server in a different office, are your packets going to make it through or not? You'll observe that private addresses have been deliberately left out of IPv6, for good reason.
A) As I understand it, IPv6 still has private addresses, although they contain a random element to attempt to minimize collision when private networks are merged. http://en.wikipedia.org/wiki/Private_network#Private_IPv6_ad...
B) I agree there are inconveniences and complications with using private addresses in ipv4. But it seems to be necessary thrift in the ipv4 world of rapidly expiring address space; using public routable ipv4 addresses for machines which do not communicate with the public internet is perhaps a luxury we can not afford, even in cases where to do otherwise is inconvenient or complicated.
These /8's have been historically been used internally there's no reason they should be handed back. Handing them back would just prolong the migration to IPv6 for limited benefit.
I imagine the only reason you would use a IPv6 private address is if you didn't have allocated global ones. It's just replacing no chance of collision with some chance of collision.
You are defending the broken windows fallacy. Wikipedia can explain better than I do, but the TLDR is simply : you are defending useless destruction of value, the end result is that everyone's poorer, nothing else.
http://en.wikipedia.org/wiki/Parable_of_the_broken_window
No, just the opposite. There would be real costs for those companies that have /8s to move away from them. Meanwhile the gains would be minimal - at best it might allow some organizations to put off moving to IPv6 for a few months.
Yes, but they were a late addition, postdating IPv6 by 10 years, and aren't meant to be used lightly.
IPv6 is designed for easy & automatic renumbering so there's less need to hold on to a specific prefix as an "island of stability".
I work for a company that regularly acquires smaller companies who all thought using 10/8 was a good idea. Merging N of these networks is a disaster.
What's the best green-field recommendation for said companies?
Just get real IP addresses even if you have to buy them. The cost should be minimal compared to the total IT cost.
Interesting, last time I did this was 1996 (and last time I wore the net admin hat) we had our own range for internal use.
Just gotta make sure OSPF, (E/I)BGP and L2/L3 drop these ranges though.
The squeeze will just continue as people make more money off of it, and we'll still need IPv4 addresses for compatibility with people running Windows XP in 2020.
Why? A router could still offer private IPv4 and encapsulate IPv4 packets in IPv6. The carrier can decapsulate IPv6 packets and perform NAT.
In fact, this is how my home cable connection works (per DS-Lite [1]). Our modem/router only gets an IPv6 address, but IPv4-only devices work fine.
[1] http://tools.ietf.org/html/rfc6333
I'm not sure if the OP referenced Win XP purely based on the IPv4->IPv6 discussion but Win XP is also extremely relevant for IP address space consumption due to not supporting TLS extension SNI [1].
SNI removes the requirement from HTTPS websites to host one domain per IP. This is done by having hostname part of the initial handshake.
Many websites or at least most (hopefully all) webapps these days serve over https, at least the ones that require user input like login. So there's the need for at least one public IP per site.
With SNI these could be all served from the same IP.
Now imagine CDN services like AWS CloudFront -- to support sites with SSL certificates you must use one IP per cert in EACH region or whatever the distribution granularity is.
Now this my friends is why AWS CloudFront asks $600/mo for each custom SSL cert domain and with SNI custom SSL it costs $0/mo.
As soon as all the 99.9% browsers/clients support SNI we'll be living in a better place with more free IPs. So we can finally distribute static content from CDN through custom SSL without the $600/mo pricetag.
It's naive to think everyone would go to SNI-based hosts with IPs shared with strangers but at least within the same datacenter for the same company IPs can be more easily conserved.
[1] http://en.wikipedia.org/wiki/Server_Name_Indication
Couldn't WinXP browsers (e.g. Chrome, Firefox) implement their own TLS with SNI?
At least Chrome 34 on Windows XP supports SNI; I strongly suspect that Firefox does as well (since they are both using the NSS library for SSL).
Firefox does, but only because it uses their own TLS library instead of using the one supplied by the OS.
Yea, I should have been more specific. Chrome and Firefox DO have their own TLS with SNI and SNI is enabled for them in Win XP. The issue is relevant for all IE versions on WinXP.
10% wouldn't last us very long - that's less than two years at current growth rates, and growth is still accelerating. At some point the cost is higher than just getting on with switching to v6.
For instance, T-Mobile is using the UK Ministry of Defense's 25.0.0.0/8 allocation to extend their private network address space.[1]
[1]: https://blog.wireshark.org/2010/04/t-mobile-clever-or-insane...
Yeah, IPv4 is pretty much empty. Lots of companies own a /8 all to themselves, like Xerox (13.0.0.0/8), Apple (17.0.0.0/8), USPS (56.0.0.0/8) and Ford (19.0.0.0/8) to name a few. None of them allocate even the tiniest portion of them.
There are usage requirements for IP addresses now. I have to substantiate the allocation.
I think if ARIN wanted to, they could give everyone a year to "substantiate their allocation" and set the policy something like "companies must return for reallocation any overallocations."
The risk of not returning an overallocation, well I'm not sure. ARIN certainly has teeth, and companies should simply be expected to correct these huge overallocations.
Just like the open source community comes together to solve serious problems, if we as a community enforced an ethical standard and some key people stood up raised this as an issue, I'm willing to bet ARIN could replenish a stockpile of IPv4 space.
So the question I'm asking is, since ARIN is empty, clearly they aren't interested in keeping a stockpile of addresses. Why not? I guess the more generous alternative is simply they have failed spectacularly at their stated goal.
I admit that I am not familiar with ARIN, but if it is anything like APNIC (Asia Pacific) then those big Class A Allocations are protected as legacy allocations. As such they are not required to give the legacy allocations up and its questionable if the RIR could even revoke them.
ARIN can go over the pool of post 1997 addresses they have allocated, but I think you would find much smaller unallocated blocks.
Take back those four and you can delay the v4 armageddon by about three months. Longer if you still apply the extra-strict rules used during the armageddon runup.
When the three months are up you can go looking for four more companies, and hire some more lawyers too.
Watch this clip to understand why fractional solutions wont save us : https://www.youtube.com/watch?v=F-QA2rkpBSY
Warning, its "Perhaps the most boring video you'll ever see, and definitely the most important."
There is no requirement for (historical) IP addresses allocations to be publicly routable. Unfortunately many companies own large allocations that they are quite rightly able to use for internal allocations.
The only way they are going to give them up is if the is worth their while financially.
I think XP has partial IPv6 support, though not installed by default.
You're right, the "Windows XP User on IPv4" is just an allegory of the critical mass of users that will keep us from dropping our IPv4 addresses many years into the future.
Put another way, what is the incremental value to provide access to your service to those IPv4 only users/devices? Whatever that value is, in theory you would be willing to pay a portion of that for access to IPv4 address space.
Luckily supply is not really constrained, so much as it is controlled. You can always get more IPs if you need them, but the cost associated I think will continue to increase... until enough people not only just support IPv6, but actually abandon their IPv4 addresses.
When the only devices that your software or service is designed to run on all support IPv6, then there's "no point" in having an IPv4 address. You almost have to get to the point where IPv4 is "not worth the trouble". And we are very, very far from that point I think. More to the point, more people are likely to think that it's IPv6 that is not worth the trouble.
Look at the other side of the coin though. If you have a service that only talks ipv6, you will be insulated from all the unsupported, unpatched, and trojan/virus laden XP machines for years to come!
My strongest incentive for implementing IPv6 at work is that Gmail is advertising MX hosts that have both IPv4 and IPv6 addresses. So on systems which are IPv6 capable, and where your OS either picks a random IPv4 or IPv6 address or prefers IPv6, you'll end up getting lots of noise when it tries IPv6 and fails and falls back to the next address if you don't have IPv6 connectivity set up.
Could of course just ignore that, but it's a good low pressure reminder to get around to sorting out IPv6...
10% gets us something like 6 months from memory - more than nothing, but not enough to hold off the inevitable!
Windows XP is a pain all right, the lack of SNI along with the limited v6 support means anyone using it really is stuck on v4.
Maybe the recent EOL for XP will cause a dramatic shift in the number of people continuing to use it? At least in the more well-off countries like the US, UK etc, opening the door for SNI :)
ARIN does not have the authority to reclaim the blocks allocated before ARIN existed.
This is the source of a lot of problems.