[afnog] Network termination point

sm+afrinic at elandsys.com sm+afrinic at elandsys.com
Sat Jul 11 13:48:16 UTC 2026


Hi Jordi,
At 12:19 AM 11-07-2026, jordi.palet at consulintel.es wrote:
>If I recall correctly, one of the major 
>"offenders" recommending disabling IPv6 was 
>Ubisoft. I'm sure is easy to google for that and 
>see that other software/hardware vendors did 
>similar recommendations, while for example 
>Microsoft, clearly states that you should not do 
>that, even if you don't use/have IPv6 from your ISP.
>
>The reality is that most of the networking 
>stacks aren't "dual" but hybrid, and some local 
>functions or automatic Microsoft features, rely on IPv6 encapsulated in IPv4.

The information did not show up in the search 
results (please see my previous email).  The 
"disable IPv6" suggestion shows up a bit less 
than before.  I do it per site/network if I notice a connectivity problem.

>The other issue that is also easy to track with 
>google (or your preferred search tool) is users 
>and ISPs complaining since over 10 years ago, 
>that Sony PlayStation Network blocks entire IPv4 
>ranges used in NAT444 (CGN). Other service 
>provides did similar blockings, but PSN is the 
>major offender and the one that cause more 
>trouble. Up to now, once they block your ranges, 
>they are blocked forever, unless anything changed recently.

It is relatively common to come across sites 
which block the user if his/her connection is 
over IPv6.  I have not seen anyone around here 
complaining about not being able to play a game 
because of NAT444.  I mentioned previously that 
it may be different in other markets, e.g. 
https://gaming.locality.co.za/servers

>Regarding misinformation about IPv6 vs IPv4 with 
>NAT (including the false belief NAT=security), 
>and similar ones, there is the RFC4864 trying to 
>clarify that. This document is a bit old (2007) 
>and I volunteered to work on an updated version. 
>Probably I will be able to publish a first version next month.

I assume that you have heard of the usual excuse 
which is used when anyone brings that up in the 
relevant venue.  People do not read a book if 
they have never heard of it or they don't find it 
worth their time.  It's about the same for 
RFCs.  I would not be surprised to hear that the 
misinformation is part of a marketing campaign to promote some products.

>What is obvious is that IPv4 public addresses 
>are also globally routable, the difference is 
>that you have (typically) a single address for 
>your entire network because NAT, and that one 
>also reveals the location of the full network 
>and affiliation. Fingerprinting devices and 
>hints of who may be the user behind it, is 
>easier to do based on many other aspects than IP addresses.

I am not disagreeing with you on that.  If you 
scroll down the google.com page, you will see a 
location displayed.  Younger people would not be 
convinced by the "reveals network and 
affiliation" claim as they learned about that as 
part of their online activities.  Here's some 
information which can easily be used for 
fingerprinting a device: 
https://www.elandsys.com/r/69064  There is some 
information about ransomware at 
https://www.elandsys.com/r/75860 It happened even 
though the IPv4 addresses were not be globally 
routable, i.e. the network was using NAT.  There 
is an ongoing online fraud wave over here 
according to the local press.  Nobody claimed 
that it was happening because the persons' 
network location and affiliation were revealed through IPv6.

In my opinion, the issue, as viewed from my 
location, is not about gaming or what is claimed 
in the Masterspace Solutions' report.  What 
people are being told does not match with 
reality.  I took a quick look at what is 
advertised as being done in a country in South 
America with what people talk about over 
here.  The discussions in that country were about 
which products work and where they fail.  The 
discussions over here are generally corporate fluff.

There are 485 technical documents discussing 
IPv6.  A significant number of the documents 
(477) are for business scenarios.  The network 
termination point for the residential user 
shouldn't be a stumbling block as those documents 
were about IPv6 and businesses.

   $ grep -i ipv6 rfc-index.txt | wc -l
   485
   $ grep -il "enterprise" rfc*.txt | xargs grep -il "ipv6" | wc -l
   477
   $ grep -il "cpe" rfc*.txt | xargs grep -il "ipv6" | wc -l
   174

If someone were to tell me that IPv6 is in used 
somewhere, I would expect to see some technical 
details, e.g. which products were used, how did 
it actually work, etc.  I could not find that 
type of information in the IPv6 discussions.

Regards,
S. Moonesamy 




More information about the afnog mailing list