Commonly used IPv6 networks » History » Version 15
Nico Schottelius, 06/26/2021 01:52 PM
| 1 | 1 | Nico Schottelius | h1. Commonly used IPv6 networks |
|---|---|---|---|
| 2 | |||
| 3 | 3 | Nico Schottelius | h2. By ungleich |
| 4 | |||
| 5 | 1 | Nico Schottelius | Assuming that you have a /48 per location/site, there are some specific /64 sub networks that we usually use at ungleich. |
| 6 | 4 | Nico Schottelius | As an example let's take **2001:db8:a::/48**, then the we often use these networks: |
| 7 | 1 | Nico Schottelius | |
| 8 | 11 | Nico Schottelius | h3. Typical IPv6 plan from ungleich |
| 9 | |||
| 10 | 14 | Nico Schottelius | * Assuming 2001:db8:a::/48 as a base network |
| 11 | |||
| 12 | 1 | Nico Schottelius | | Network | Description | |
| 13 | 6 | Nico Schottelius | | 2001:db8:a::/64 | The network 0 is usually internal | |
| 14 | 8 | Nico Schottelius | | | For netboot, untrusted equipment, IPMI and co. Usually firewall for no incoming traffic at all | |
| 15 | | 2001:db8:a:1::/64 | Servers, sensible equipment: stuff we trust ssh is safe | |
||
| 16 | 7 | Nico Schottelius | | | For accessing servers, usually only port 22 (ssh) or an alternative SSH port (222,2202,2222) open | |
| 17 | 9 | Nico Schottelius | | 2001:db8:a:8::/64 | Transfer network | |
| 18 | 10 | Nico Schottelius | | | For routing, might contain /124 or smaller sub networks for "point to point" | |
| 19 | 5 | Nico Schottelius | | 2001:db8:a:a::/64 | DNS network: houses DNS servers in the network. | |
| 20 | 1 | Nico Schottelius | | | Regular DNS servers are usually 2001:db8:a:a::a and 2001:db8:a:a::b | |
| 21 | | | DNS64 enabled servers are usually 2001:db8:a:a::64 and 2001:db8:a:a::65 | |
||
| 22 | 6 | Nico Schottelius | | 2001:db8:a:bee::/64 | LAN network: usually wifi/coworking | |
| 23 | 7 | Nico Schottelius | | | "bee" is something people can easily pronounce; ssh open from outside | |
| 24 | 6 | Nico Schottelius | | 2001:db8:a:cafe::/64 | LAN network: usually wired/regular clients | |
| 25 | 9 | Nico Schottelius | | 2001:db8:a:d::/64 | Downstream network: routing to physically present downstreams | |
| 26 | | 2001:db8:a:d::/80 | Static IP addresses OUR side | |
||
| 27 | | 2001:db8:a:d:1::/80 | Static IP addresses DOWNSTREAM | |
||
| 28 | 6 | Nico Schottelius | | 2001:db8:a:7ea::/64 | LAN network: Usually 2nd wifi network | |
| 29 | 2 | Nico Schottelius | | 2001:db8:a:b00::/96 | Incoming NAT64 prefix: mapping IPv4 islands: 2001:db8:a:b00::192.168.1.1 is IPv6 reachable | |
| 30 | 13 | Nico Schottelius | | 2001:db8:a:c00::/96 | 2nd Incoming NAT64 prefix: use this if one of them is stateful, the other one is stateless | |
| 31 | 2 | Nico Schottelius | | 2001:db8:a:c001::/96 | Outgoing NAT64 prefix: mapping the IPv4 Internet, allowing IPv6 only hosts to reach the IPv4 Internet | |
| 32 | 15 | Nico Schottelius | | 2001:db8:a:x::10::/79 | Kubernets cluster 1 | |
| 33 | | 2001:db8:a:x::10::/108 | Kubernets pod sub network 1 | |
||
| 34 | | 2001:db8:a:x::11::/108 | Kubernets service sub network 1 | |
||
| 35 | | 2001:db8:a:x::12::/79 | Kubernets cluster 2 | |
||
| 36 | | 2001:db8:a:x::12::/108 | Kubernets pod sub network 2 | |
||
| 37 | | 2001:db8:a:x::13::/108 | Kubernets service sub network 2 | |
||
| 38 | | 2001:db8:a:x::14::/79 | Kubernets cluster 3 | |
||
| 39 | | 2001:db8:a:x::14::/108 | Kubernets pod sub network 3 | |
||
| 40 | | 2001:db8:a:x::15::/108 | Kubernets service sub network 3 | |
||
| 41 | 3 | Nico Schottelius | |
| 42 | 11 | Nico Schottelius | h3. IPv6 address guidelines |
| 43 | |||
| 44 | * /124s are nice to read as they cut off the last byte |
||
| 45 | * When using a /96 to access from or to the IPv4 Internet, reserve the whole /64 |
||
| 46 | 12 | Nico Schottelius | * When sub dividing a /64 on a VM/server, use /80's (nibble boundaries) |
| 47 | 11 | Nico Schottelius | * */64: When in doubt, take a /64* |
| 48 | * /48's work great per location or customer |
||
| 49 | ** No need to use a bigger network, even if you have space |
||
| 50 | * VPN concentrators / routers usually need /40 or /32 to redistribute /48's |
||
| 51 | |||
| 52 | 3 | Nico Schottelius | h2. In other places |
| 53 | |||
| 54 | * "Address plan from Peter H. Jin":https://www.peterjin.org/wiki/Peterjin.org:IP_Addressing_Plans |
||
| 55 | 11 | Nico Schottelius | * "IPv6 addressing plans (from a RIPE meeting)":https://meetings.ripe.net/see2/files/IPv6%20Addressing%20Plans.pdf |