Re: [93attendees] IETF Meeting NAT64 network

Diego Garcia del Rio <diego@nuagenetworks.net> Fri, 24 July 2015 09:39 UTC

Return-Path: <diego@nuagenetworks.net>
X-Original-To: 93attendees@ietfa.amsl.com
Delivered-To: 93attendees@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C371F1A885A for <93attendees@ietfa.amsl.com>; Fri, 24 Jul 2015 02:39:09 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.6
X-Spam-Level:
X-Spam-Status: No, score=-2.6 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_LOW=-0.7] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id JX4AdYggmhSY for <93attendees@ietfa.amsl.com>; Fri, 24 Jul 2015 02:39:07 -0700 (PDT)
Received: from mail-ig0-f182.google.com (mail-ig0-f182.google.com [209.85.213.182]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 53E781A8856 for <93attendees@ietf.org>; Fri, 24 Jul 2015 02:39:07 -0700 (PDT)
Received: by igbpg9 with SMTP id pg9so12325535igb.0 for <93attendees@ietf.org>; Fri, 24 Jul 2015 02:39:06 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:references:from:mime-version:in-reply-to:date :message-id:subject:to:cc:content-type:content-transfer-encoding; bh=peXOTxHT1d1R30r/cdfA/I4Tf6dLlGREx2XZlb+bUY4=; b=iyVfC13zmxxLUsdW4B2uzc7vsAsOZjl4D9WffsKXv1hJyD9XbHB8imfr+lD/vQlcUa npIONNNXzNwuaiZI1gxoc2+nSQNZzGIT7d+EWQ9mT25TilcvgAtWFHFbxpJ0nBo9rjrQ MvIF241285ucNxKtOwy54TmBBiz9RB1A+yLy3ieQRcS/gRZhVg8eudDpHuR+Z9yaN4fY mjVreOAStKiEXGYUh2JSEW5YHpzq0o6NA1MG43/u5GoOvuiW/PhUS9YI8OjX4ZkQRQIi BroQpao83RHyiUxwrdLW+RBqdVw/BtDT9tLm//82i2KLe0nhUVt1uMuJb63CCz4IJGQ7 tjWA==
X-Gm-Message-State: ALoCoQl3tjQI/HtVhYxcTfDenZuP+5pq28U4YiXNLeLDbYS+pgasZBYkRkwQdsf4nRE9dk/MMyz1
X-Received: by 10.107.150.1 with SMTP id y1mr20066998iod.108.1437730746781; Fri, 24 Jul 2015 02:39:06 -0700 (PDT)
References: <CAE501C3-2CA5-4317-AA5D-CBC27A6E3B25@stuartcheshire.org>
From: Diego Garcia del Rio <diego@nuagenetworks.net>
Mime-Version: 1.0 (1.0)
In-Reply-To: <CAE501C3-2CA5-4317-AA5D-CBC27A6E3B25@stuartcheshire.org>
Date: Fri, 24 Jul 2015 11:39:05 +0200
Message-ID: <3558295463922940016@unknownmsgid>
To: Stuart Cheshire <ietf15@stuartcheshire.org>
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable
Archived-At: <http://mailarchive.ietf.org/arch/msg/93attendees/TBxerwXVJuytQ_8oUVKCr0Bii44>
Cc: "93attendees@ietf.org" <93attendees@ietf.org>
Subject: Re: [93attendees] IETF Meeting NAT64 network
X-BeenThere: 93attendees@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Mailing list of IETF 93 attendees that have opted in on this list. " <93attendees.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/93attendees>, <mailto:93attendees-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/93attendees/>
List-Post: <mailto:93attendees@ietf.org>
List-Help: <mailto:93attendees-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/93attendees>, <mailto:93attendees-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 24 Jul 2015 09:39:09 -0000

I tried to revert to ietf-nat64 when the wifi went doesn't and
unfortunately encountered two issues. One was that for whatever
reason, the DNS resolution for one of our company's vpn endpoint was
being answered as an IPv4 record. Couldn't figure out the logo why to
be honest. The second was that even after configuring a manual host
entry, my ssl Vpn client would fail to finish the connection (has some
issues with routes it needed to install locally). That I blame on the
client. My other IPSec client refused to work over v6 but was at least
very clear. "IPv6 not supported". Oh well :(





> On Jul 24, 2015, at 11:08, Stuart Cheshire <ietf15@stuartcheshire.org> wrote:
>
> I’ve spent the entire week of this IETF meeting on the “ietf-nat64” network, on both my iPhone and my laptop. With just one exception, everything has worked fine and I have not had any problems (from what I’ve heard, the NAT64 network has actually been working *better* than the IPv4 network).
>
> The exception mentioned above was trying to pay my Amazon credit card bill on-line, which involves accessing www.onlinecreditcenter6.com. That domain name appears to have a broken DNS server, which doesn’t answer AAAA queries, and the failure to respond to AAAA queries results in the DNS64 engine returning a SERVFAIL error instead of synthesizing a AAAA record from the IPv4 address record that it does have:
>
> % host www.onlinecreditcenter6.com
> www.onlinecreditcenter6.com has address 216.74.188.135
> Host www.onlinecreditcenter6.com not found: 2(SERVFAIL)
>
> This seems like a fixable bug in the DNS64 engine. If a server has no IPv6 support, and a broken DNS server that also doesn’t know that IPv6 exists, that should not stand in the way of DNS64/NAT64 creating a communication path to the server’s IPv4 address.
>
> This is reminiscent of my 2008 talk at IETF 72 about the perils of blocking forever waiting for an IPv6 response that will never be coming: <http://www.stuartcheshire.org/IETF72/>
>
> Stuart Cheshire
>
> _______________________________________________
> 93attendees mailing list
> 93attendees@ietf.org
> https://www.ietf.org/mailman/listinfo/93attendees