@Netzblockierer @mttaggart right, the “correct” way to do this would be to dynamically do a subdelegation, turn a /48 from your ISP into a /64 for your physical network and a different /64 for your VPN. in the cases where you only have the one /64 delegation though, sharing a /64 ought to be an *option* at least; a /64 is way bigger than an ipv4 /24
@Netzblockierer @mttaggart but the point is, the 16 bits in the middle are what describe the subnets, not the 48 at the beginning
@glyph @mttaggart Personally I'd NEVER EVER use a public #IPv6 address space, espechally when you don't 'own' it [aka. have a provider-independent allocation by an RIR] but only get it assigned from the #ISP(s)…
- The way I do it is #ULA¹ both #LAN|s & #VPN|s because #NAT & RFC1918-style addresses as well as #IPv4 are still de-facto mandated everywhere.
- In fact, I've yet to see any #IPv6only - Network in production because there's always the need to have IPv4 support as there's no mandatory IPv6 support around the world!
@Netzblockierer @mttaggart do you have a RIPE allocation at home? or would you typically request one for a 100-person office? I understand that IPv6 logistics *are* shit, I just don't want to accept that that's the inevitable future and that they will *always* be shit :)
@Netzblockierer @mttaggart like the whole point of this stuff was supposed to be that we could get public, privacy-protected IP addresses automatically and freely, that we could all have as many subnets as we need, that we could dispense with the complexity and inefficiencies of NAT. and like within the _spec_ that is possible, and I would like to live a little bit in the future where it could happen, but it seems that every networking vendor is actively invested in preventing me from doing that
@glyph @Netzblockierer Pardon my confusion, but I thought you wanted a ULA, which is by design not publicly addressable.
I do think you're right about the complexities of IPv6 provisioning writ large, but I also think none of that is Wireguard's fault?