#arpnetworks 2012-09-10,Mon

↑back Search ←Prev date Next date→ Show only urls(Click on time to select a line by its url)

WhoWhatWhen
mercutionot to mention that average consumers are already happy with nat and wifi
they just want something "good enough"
[00:16]
Webhostbuddexactly
which sucks
my friends don't even mind shared internet that cuts out all the time
because they use some crappy nat router which ends up having too large a state table
so many bad things
the problem is that consumers today can still easily pick up brand new modems and routers which don't support ipv6
not to mention people still using windows xp
i wish there was a better way to incentivise people to upgrade but it would require some revolutionary new features
and the price would have to be right
[00:20]
mercutiomy modem doesn't support ipv6
ipv6 tends to slow down the net atm
so i'm not that keen on ipv6 myself yet
[00:26]
Webhostbuddoh really?
you mean it slows down ipv4 browsing?
[00:27]
mercutioi just use routed ip addresses
nah worse routing
[00:27]
Webhostbuddoh
i believe that
is there still a lot of backbone infrastructure that doesn't support it?
im guessing this isn't a fundamental problem
[00:28]
mercutiowell there's less peering of ipv6 than ipv4 [00:28]
Webhostbuddwell yea [00:28]
mercutioand cdn's that do ipv6 can have worse routes
i dunno, firewalling is my biggest concern with ipv6 for home users
[00:29]
Webhostbuddhow come?
it shouldn't be any worse than ipv4
[00:30]
mercutiowell nat saves a lot of people atm
a lot of people when they firewalls do ipv4 onyl firewalls
if they add ipv6 they don't necessarily add firewalls to ipv6
[00:31]
Webhostbuddbut no one plugs directly into ipv6
err
the internet
[00:32]
***Ehtyar has quit IRC (Quit: Never look down on someone unless you're helping them up.) [00:32]
mercutiopeople often use nat for security atm [00:32]
Webhostbuddbut a router that is ipv6 enabled is just as secure by default
and they only get nat on the router
[00:32]
mercutiothe router may be [00:32]
Webhostbuddany sane router manufacturer would be [00:33]
mercutiobut the hosts behind it get direct net access when they had nat'ed access before
on that note upnp isn't good :)
[00:33]
Webhostbuddi don't see how they could make such a novice mistake [00:33]
mercutiohmm, i haven't seen an ipv6 modem yet [00:33]
Webhostbuddplus, i see plenty of people dmz machines for no good reason [00:33]
mercutiobut in built firewalls on modems have never been great [00:33]
Webhostbuddsince when do modems incorporate a firewall?
i take that back, i completely disabled it last time i had one
because it's stupid
most people have wireless routers these days and you can be sure the manufacturers will put sane default firewall policies on those
people who work around them usually did so with ipv4 anyway
[00:34]
mercutioi dunno adsl is common here and all in one units
and people leave wps enabled
[00:36]
Webhostbuddyes, but those have built in firewalls
if they supported ipv6 they would also have default policies
[00:36]
mercutioenabled by default?
maybe
we'll see :)
it's prob a few years off anyway
[00:36]
Webhostbuddwell, if they don't then that company deserves to die [00:36]
mercutiothey all come from china
who don't even do reverse dns on their ip's
[00:36]
Webhostbuddthe firmware usually doesn't though? [00:37]
mercutiohmm
actually that's a point, it originally ocmes from broadcom etc
[00:37]
Webhostbuddyea [00:37]
mercutiomy modem started misbehaving last night with high pings [00:37]
Webhostbuddhonestly, i think manufacturers will get it right since they have seen what has happened in the past [00:37]
mercutioi tried to track down what was causing it and couldn't find aynthing
i rebooted and it was better
[00:37]
Webhostbuddprobably crap firmware [00:38]
mercutiorebooted modem that is [00:38]
Webhostbuddlol [00:38]
mercutioi was stumped
but i don't even have iptables
[00:38]
Webhostbuddyea, that's a problem [00:38]
mercutioyou have to disable the firewall by changing firewall=yes to firewall=no in the xml file [00:38]
Webhostbuddlol [00:38]
mercutioerr you download backup config file
and reupload
it doesn't seem to have anything on web interface to disable firewall
id unno why but connections die randomly otherwise
[00:38]
Webhostbuddthat sounds awful [00:39]
mercutioit's got 32mb of ram, so it hasn't really got an excuse
connection limit of around 3000 i think
[00:39]
Webhostbuddhahaha [00:39]
mercutiobut you don't need lots of connections for them to randomly die
like ssh would die if you don't type on it and go and make a coffee and come back
unless it's something like irc that receives a little bit of data often
[00:39]
Webhostbuddthat sucks [00:40]
mercutioyes
very annoying very quickly
[00:40]
Webhostbuddmy cable modems have been pretty stable actually
im quite pleased
[00:40]
mercutiothey're briding?
bridging?
[00:40]
Webhostbuddyea [00:40]
mercutioyeh that's safer [00:40]
Webhostbuddi don't use consumer crap as a gateway [00:40]
mercutioi use a virtual machine as a router [00:41]
Webhostbuddi actually know quite a few people who do that [00:41]
mercutioactually my desktop just goes direct [00:41]
Webhostbuddand i tried it for some time but it just doesn't make sense to me [00:41]
mercutiowifi goes through router
err through modem
with no nat
[00:41]
Webhostbuddi see
you get multiple ipv4's?
[00:41]
mercutiowell i'm transparently proxying wifi traffic
yeh
[00:41]
***sako has joined #arpnetworks [00:41]
Webhostbuddnow that sounds kinda awesome
can't do that on cable
[00:42]
mercutioi've only got a /29
i'm sure they could do it
[00:42]
Webhostbuddyea they could
actually
[00:42]
mercutiowell a /32 and a /29
the /29 routes to the /32
[00:42]
Webhostbuddi might be able to just grab 4 dhcp leases [00:42]
mercutioi'm wasting an ip really
eww dhcp
[00:42]
Webhostbuddyup [00:43]
mercutiocan't you get a statici ip? [00:43]
Webhostbuddnot without paying for business class service
with ipv6 i just treat it as static though
and take what i want
i don't give a fuck
[00:43]
mercutiohaha
and that works?
[00:43]
Webhostbuddyep [00:44]
mercutioso they cna't track you? [00:44]
Webhostbuddtheir routers don't enforce an ip per mac address
but they only assign one
the problem is that someone could get a lease over top of your arbitrarily allocated static block
but ill take that risk
i might do it with ipv4 but i don't know how well that would work
im sure the address space is pretty congested and hard to guess out
i don't really care much though, i just want to be able to use slaac on two interfaces for ipv6
so i need two /64's
however, comcast only allocates one
[00:44]
mercutiooh they assign a dynamic /64? [00:46]
Webhostbuddyes
they give the wan a /128 lease and then send it a /64 to allocate to the lan segment
[00:47]
***sako has quit IRC (Ping timeout: 260 seconds) [00:48]
Webhostbuddand that works, but i have multiple network segments
i usually have two different nat'd ipv4 segments
there isn't really a good way to do that with ipv6 unfortunately
i mean, i could do nat'd ipv6
but that's just rediculous
you need a /64 per network
which actually drives me a little crazy
i mean, yea we have 2^128 addresses now
but we are effectively limited to 2^64 gateways
it should really be 2^80
err
2^79
theoretically the space behind the gateway is only limited to mac addresses
and those are only 48 bits
of course they decided to expand that to 64 bits
which to me seems stupid
[00:49]
***Webhostbudd has quit IRC (Quit: Leaving) [01:07]
..... (idle for 21mn)
LT has joined #arpnetworks [01:28]
jlgaddis< mercutio> like ssh would die if you don't type on it and go and make a coffee and come back <-- that's due to TCP timeouts in your NAT setup, which can be changed (or you can setup keepalives in your SSH client). [01:40]
........... (idle for 54mn)
mercutiojlg: yeh but there's no way to fix it easily on the modem
it's "broken" behaviour
disabling iptables fixed tings
[02:34]
............... (idle for 1h12mn)
jlgaddisIt's your modem timing out the NAT translation due to no traffic... which keepalives will fix. But okay. [03:47]
..... (idle for 21mn)
mercutioyeh but the modem's meant to just route traffic
i wasn't using nat
[04:08]
............... (idle for 1h12mn)
***heavysixer has quit IRC (Quit: heavysixer) [05:20]
......... (idle for 41mn)
Guest52883 is now known as pjs [06:01]
..................... (idle for 1h40mn)
sako has joined #arpnetworks
ryk has joined #arpnetworks
[07:41]
teneightypea has quit IRC (Ping timeout: 250 seconds)
bGeorge has quit IRC (Ping timeout: 260 seconds)
mike-burns has quit IRC (Ping timeout: 260 seconds)
pjs has quit IRC (Ping timeout: 246 seconds)
up_the_irons has quit IRC (Ping timeout: 246 seconds)
kraigu has quit IRC (Ping timeout: 246 seconds)
twobithacker has quit IRC (Ping timeout: 260 seconds)
ix34 has quit IRC (Ping timeout: 246 seconds)
Guest69786 has quit IRC (Ping timeout: 246 seconds)
CaZe has quit IRC (Ping timeout: 260 seconds)
nukefree has joined #arpnetworks
CaZe` has joined #arpnetworks
CaZe` has quit IRC (Read error: Connection reset by peer)
bGeorge has joined #arpnetworks
ix34 has joined #arpnetworks
teneightypea has joined #arpnetworks
CaZe` has joined #arpnetworks
CaZe`_ has joined #arpnetworks
up_the_irons has joined #arpnetworks
ChanServ sets mode: +o up_the_irons
CaZe` has quit IRC (Remote host closed the connection)
pjs has joined #arpnetworks
twobithacker has joined #arpnetworks
CaZe` has joined #arpnetworks
pjs is now known as Guest59293
Guest59293 is now known as pjs
sako has quit IRC (Ping timeout: 252 seconds)
CaZe` has quit IRC (Read error: Connection reset by peer)
nukefree has quit IRC (Ping timeout: 246 seconds)
bGeorge has quit IRC (Ping timeout: 272 seconds)
CaZe`_ has quit IRC (Ping timeout: 240 seconds)
CaZe` has joined #arpnetworks
twobithacker has quit IRC (Ping timeout: 260 seconds)
bGeorge has joined #arpnetworks
up_the_irons has quit IRC (Ping timeout: 246 seconds)
nukefree has joined #arpnetworks
twobithacker has joined #arpnetworks
up_the_irons has joined #arpnetworks
ChanServ sets mode: +o up_the_irons
kraigu has joined #arpnetworks
[07:54]
..... (idle for 20mn)
sako has joined #arpnetworks [08:32]
sako has quit IRC (Ping timeout: 276 seconds) [08:38]
............ (idle for 55mn)
LT has quit IRC (Quit: Leaving) [09:33]
..... (idle for 20mn)
mike-burns has joined #arpnetworks
ChanServ sets mode: +o mike-burns
[09:53]
CaZe` is now known as CaZe
Webhostbudd has joined #arpnetworks
[10:06]
HighJinx has quit IRC (Quit: Computer has gone to sleep.) [10:21]
heavysixer has joined #arpnetworks
ChanServ sets mode: +o heavysixer
[10:28]
sako has joined #arpnetworks [10:33]
sako has quit IRC (Ping timeout: 245 seconds) [10:38]
HighJinx has joined #arpnetworks [10:46]
dferris has quit IRC (Quit: leaving) [10:59]
dan_ has joined #arpnetworks
dan_ has quit IRC (Client Quit)
dan_ has joined #arpnetworks
dan_ is now known as dferris
dferris has quit IRC (Client Quit)
dferris has joined #arpnetworks
[11:05]
.... (idle for 15mn)
mike-burns has quit IRC (Read error: Connection reset by peer)
mike-burns has joined #arpnetworks
ChanServ sets mode: +o mike-burns
[11:25]
jbum has joined #arpnetworks [11:32]
krazydad has joined #arpnetworks
krazydad has quit IRC (Client Quit)
jbum has quit IRC (Read error: Connection reset by peer)
[11:45]
beandog has joined #arpnetworks
beandog has quit IRC (Changing host)
beandog has joined #arpnetworks
[12:00]
beandog has left "Leaving" [12:13]
..... (idle for 21mn)
sako has joined #arpnetworks [12:34]
sako has quit IRC (Ping timeout: 260 seconds) [12:39]
.................. (idle for 1h26mn)
Webhostbudd_ has joined #arpnetworks
Webhostbudd has quit IRC (Ping timeout: 250 seconds)
[14:05]
...... (idle for 27mn)
sako has joined #arpnetworks [14:35]
sako has quit IRC (Ping timeout: 248 seconds) [14:40]
........................ (idle for 1h56mn)
sako has joined #arpnetworks [16:36]
sako has quit IRC (Ping timeout: 276 seconds) [16:41]
........... (idle for 50mn)
Ehtyar has joined #arpnetworks [17:31]
.............. (idle for 1h6mn)
sako has joined #arpnetworks
sako has quit IRC (Ping timeout: 240 seconds)
[18:37]
.... (idle for 17mn)
HighJinx has quit IRC (Quit: Computer has gone to sleep.) [18:58]
...... (idle for 29mn)
dj_goku has joined #arpnetworks
dj_goku has quit IRC (Changing host)
dj_goku has joined #arpnetworks
[19:27]
Webhostbudd_ has quit IRC (Read error: Connection reset by peer)
Webhostbudd_ has joined #arpnetworks
[19:32]
andolup_the_irons: In case you are around, my Arpnetworks VPS leto seems to have a bit of a problem talking IPv4 to another VPS of mine - http://paste.ubuntu.com/1197889/
(IPv6 on the other hand works just perfect.)
[19:39]
up_the_irons: Also did some tcpdumping, the other VPS halleck actually sees, and replies to, the packages from my Arpnetworks VPS leto. Let on the other hand doesn't see any packages from halleck. [19:45]
.......... (idle for 49mn)
***dj_goku has quit IRC (Read error: Connection reset by peer)
dj_goku has joined #arpnetworks
dj_goku has quit IRC (Changing host)
dj_goku has joined #arpnetworks
jbergstroem has quit IRC (Ping timeout: 265 seconds)
jbergstroem has joined #arpnetworks
sako has joined #arpnetworks
[20:34]
sako has quit IRC (Ping timeout: 260 seconds) [20:42]
........ (idle for 37mn)
andolup_the_irons: Well, kind of works as it should again now, so not sure if there are much to look at presently. [21:19]
.......... (idle for 47mn)
***HighJinx has joined #arpnetworks [22:06]
....... (idle for 33mn)
sako has joined #arpnetworks [22:39]
.... (idle for 16mn)
sako has quit IRC (Ping timeout: 252 seconds) [22:55]
...... (idle for 27mn)
sako has joined #arpnetworks [23:22]
sako has quit IRC (Ping timeout: 272 seconds) [23:32]

↑back Search ←Prev date Next date→ Show only urls(Click on time to select a line by its url)