This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Is IPv6 actually desirable? (rfcat_vk)

I've tried to follow rfcat_vk's excellent documentation of the current state of IPv6 in SFOS. And I've been feeling like I'm missing out that my ISP doesn't offer IPv6 (they've said "coming soon" for a year now, maybe more). But the more I look into it, the less benefit I see. I almost don't want it to drop at this point.

It avoids NAT, but NAT doesn't really slow things down and the only IPv4 workaround I'm familiar with that I need is SIP ALG (which in SOFOS appears to work well). With most all critical communications using TLS, it doesn't seem like IPv6 actually adds much for security. In fact, it seems like a security wash in some ways with ICMP becoming so critical to IPv6 working.

It provides a little tracking advantage with the ability to have different, changing IP addresses for each machine that communicates with the outside world. Which is cool.

But at a minimum, I'd have to run the XGS in dual-stack mode indefinitely. For example, I have a VPN and I may need to reach it from an area or an ISP that doesn't provide IPv6, so I'll need IPv4 for that pretty much until IPv4 is turned off in the Western Hemisphere.

My ISP will benefit from IPv6: smaller routing tables, etc. But it really doesn't feel like I have any real draw to get IPv6. An advantage here and there, a new adventure, but pretty much completely balanced out by disadvantages.

What am I not seeing? (Besides my ISP getting IPv6 and setting a deadline after which it won't support IPv4.)

Thanks!



This thread was automatically locked due to age.
  • Sorry to barge in but you seem the true expert on IPv6 with Sophos.
    With older versions of XG it was impossible to have IPv6 without masquerading so basically nullifying all the benefits of deploying it.

    Do you know if that's still the case with the new v19 release? I've tried searching for IPv6 info in the changelogs without any luck.

  • Hi Simone,

    Thank you for the compliment. The XG as of v19.0.1 mr-1 and previous versions only provide IPv6 with a MASQ/NAT. Does not provide IPv6 FQDN resolution or creation. Does not support IPv6 DDNS registration.

    Ian

    XG115W - v20 GA - Home

    XG on VM 8 - v20 GA

    If a post solves your question please use the 'Verify Answer' button.

  • Thank you for your reply.
    It's kind of disappointing to see that Sophos basically made no progress in the last years.
    IPv6 is becoming more and more prominent with the exhaustion of IPv4.
    The waiting list for LIRs to obtain a /24 IPv4 subnet has never been bigger for the RIPE region.
    Even bigger ISPs that are just launching their services are focusing on IPv6 and using transition technologies like MAP-T, MAP-E or 4in6to allow customers to reach IPv4 only services/websites.

  • Does it not support IPv6 DDNS or does it not support simultaneous IPv4 and IPv6 DDNS? I thought it was the latter.

  • Hi Wayne,

    XG does not support IPv6 FQDNs, as a result the DDNS will not work, you cannot select IPv6 from my testing. Though I have not tested with the recent t releases.

    I checked the DDNS settings wen trying to add a new service.

    Ian

    No option for IPv6.

    Ian

    XG115W - v20 GA - Home

    XG on VM 8 - v20 GA

    If a post solves your question please use the 'Verify Answer' button.