logoalt Hacker News

m463last Saturday at 9:50 PM1 replyview on HN

exactly.

ipv6 just gives you two configurations to maintain, two firewalls to write rules for and cross-leaks that are hard to understand.

I make my internal network ipv4 only, I have a lovable static config, one firewall to maintain. I also use vlans to separate into "can get out", "can only get out through a whitelist proxy", and "can't get out ever". and I am very happy.

I just don't understand how people can just plug every device they own into a promiscuous ipv4 and ipv6 router and contribute to profiling, television snooping, vacuum cleaner house mapping, data leaks, botnets and more...


Replies

preisschildlast Sunday at 1:30 AM

I do the opposite. IPv6-only in my LAN and Kubernetes Cluster and NAT46/NAT64 for external ipv4-only egress/ingress. Makes it much easier than both dualstack or IPv4 alone.