Re: [v6ops] FYI: Microsoft's latest on CLAT

Vasilenko Eduard <vasilenko.eduard@huawei.com> Mon, 11 March 2024 06:49 UTC

Return-Path: <vasilenko.eduard@huawei.com>
X-Original-To: v6ops@ietfa.amsl.com
Delivered-To: v6ops@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EE52EC14F695 for <v6ops@ietfa.amsl.com>; Sun, 10 Mar 2024 23:49:44 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.904
X-Spam-Level:
X-Spam-Status: No, score=-6.904 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=unavailable autolearn_force=no
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id RCyOklSOci1P for <v6ops@ietfa.amsl.com>; Sun, 10 Mar 2024 23:49:41 -0700 (PDT)
Received: from frasgout.his.huawei.com (frasgout.his.huawei.com [185.176.79.56]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id F1214C14F5ED for <v6ops@ietf.org>; Sun, 10 Mar 2024 23:49:40 -0700 (PDT)
Received: from mail.maildlp.com (unknown [172.18.186.31]) by frasgout.his.huawei.com (SkyGuard) with ESMTP id 4TtS765btKz6JB37; Mon, 11 Mar 2024 14:49:22 +0800 (CST)
Received: from mscpeml500003.china.huawei.com (unknown [7.188.49.51]) by mail.maildlp.com (Postfix) with ESMTPS id 099111404F4; Mon, 11 Mar 2024 14:49:37 +0800 (CST)
Received: from mscpeml500004.china.huawei.com (7.188.26.250) by mscpeml500003.china.huawei.com (7.188.49.51) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1258.28; Mon, 11 Mar 2024 09:49:36 +0300
Received: from mscpeml500004.china.huawei.com ([7.188.26.250]) by mscpeml500004.china.huawei.com ([7.188.26.250]) with mapi id 15.02.1258.028; Mon, 11 Mar 2024 09:49:36 +0300
From: Vasilenko Eduard <vasilenko.eduard@huawei.com>
To: Ole Troan <otroan=40employees.org@dmarc.ietf.org>, Jen Linkova <furry13@gmail.com>
CC: "v6ops@ietf.org" <v6ops@ietf.org>, Tommy Jensen <Jensen.Thomas@microsoft.com>
Thread-Topic: [v6ops] FYI: Microsoft's latest on CLAT
Thread-Index: AQHacMnFaOJLqIV7YEak9TIRapOnzbEtBCiAgAB7pgCAABeEAIAADg+AgAR3kxA=
Date: Mon, 11 Mar 2024 06:49:36 +0000
Message-ID: <b03cd464974b4f2cb9319ee8eff71914@huawei.com>
References: <SJ0PR00MB1348781EB81293E8A0521F23FA202@SJ0PR00MB1348.namprd00.prod.outlook.com> <CAKD1Yr1GgOBR+Y5x4-+BCzQFp3usPwd_CM05nfwgM6pT5wef1Q@mail.gmail.com> <884F5E11-364C-4D42-B199-B8FEF33C59C4@employees.org> <CAFU7BAQn-EgpL0mukUUnsBt916UA0P9Qw8KYtC5E5vG3ZMOW7w@mail.gmail.com> <10EF7C0B-0690-4AC0-BD7D-4DAB03C23E76@employees.org>
In-Reply-To: <10EF7C0B-0690-4AC0-BD7D-4DAB03C23E76@employees.org>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [10.199.56.41]
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
Archived-At: <https://mailarchive.ietf.org/arch/msg/v6ops/hhUXDO7b3XHC9_ia0ppgrMBIzFY>
Subject: Re: [v6ops] FYI: Microsoft's latest on CLAT
X-BeenThere: v6ops@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: v6ops discussion list <v6ops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/v6ops>, <mailto:v6ops-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/v6ops/>
List-Post: <mailto:v6ops@ietf.org>
List-Help: <mailto:v6ops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/v6ops>, <mailto:v6ops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 11 Mar 2024 06:49:45 -0000

IPv6-mostly looks good because it permits to have IPv6-only and IPv4-only on the same subnet. It is a smooth transition.

But "CLAT" means that somewhere should be PLAT:
- double NAT translation for IPv4 to IPv4 traffic -> definitely more difficult to troubleshoot.
- PLAT is 30% more expensive than NAT44 (look to any vendor for scalability numbers)

IMHO: IPv6-mostly would not be enough incentive to improve Enterprise miserable IPv6 adoption.
DHCP absence on the most popular OS would still block IPv6 progress in the Enterprise.

Eduard
-----Original Message-----
From: v6ops <v6ops-bounces@ietf.org> On Behalf Of Ole Troan
Sent: Friday, March 8, 2024 16:29
To: Jen Linkova <furry13@gmail.com>
Cc: v6ops@ietf.org; Tommy Jensen <Jensen.Thomas@microsoft.com>
Subject: Re: [v6ops] FYI: Microsoft's latest on CLAT

>> I’m also a fan of IPv6-mostly.
>> Isn’t it too early to state that it has lower operational cost than dual-stack (or IPv4 only)?
> 
> It may be for people who haven't deployed it yet.

Definitely. That was my point. It “may be”. We don’t quite know yet.

> 
>> What I mostly(sic) like about it, is that it provides a clearer path towards IPv6 only than dual stack.
>> 
>> But I would imagine at least for the short term there are going to be quite a few operational wrinkles to sort out.
> 
> When you find a new technology which doesn't have that problem, please 
> let me know ;)

Of course not. It’s an interesting technology. My point was to not oversell it. It has the _potential_ to become a good option.


> 
>> It’s likely harder to troubleshoot IPv4 problems too.
> 
> It's not my experience. Actually troubleshooting is much easier.
> For IPv6-only devices it's just one protocol. For dual-stack devices 
> nothing has changed compared to a dual-stack setup.

Cool! I would just imagine get a few issues with PMTUD discovery, traceroute not working and so on.


> 
>> And I don’t think it even works on my DHCPv6 single address assigned network at all (yet to be tested).
> 
> Nor would IPv6-only.

Why not?


> When you made the decision to assign a single IPv6 address per device, 
> I assume you did evaluate pros and cons.
> It doesn't make the  designs which are incompatible with your choice bad ones.

IPv6 mostly in itself is not incompatible with a single IPv6 address.
That’s an implementation choice. I haven’t had time to test implementations yet.
Documentation isn’t exactly where Apple shines, but interesting to see where Microsoft lands on this one.

Best regards,
Ole


> 
>> 
>>> On 8 Mar 2024, at 04:52, Lorenzo Colitti <lorenzo=40google.com@dmarc.ietf.org> wrote:
>>> 
>>> Great to hear! I think this means that all the major platforms will support the "IPv6-mostly" operational model that v6ops has been working on for the past few years. That's super important, because it means that any network can use this model with confidence that all their clients will work.
>>> 
>>> Hopefully this will really help adoption of this model in enterprise networks. Dual-stack is expensive to operate, but if IPv6-only works, then any enterprise that wants to support IPv6 in some form can simply skip directly from IPv4-only to IPv6-mostly without having to worry about the costs of dual-stack at all.
>>> 
>>> On Fri, Mar 8, 2024 at 5:05 AM Tommy Jensen <Jensen.Thomas=40microsoft.com@dmarc.ietf.org> wrote:
>>> Good day v6ops,
>>> 
>>> As a general IPv6 FYI, I'll share Windows' announcement to bring 
>>> CLAT to general networking interfaces which went live today: 
>>> https://techcommunity.microsoft.com/t5/networking-blog/windows-11-pl
>>> ans-to-expand-clat-support/ba-p/4078173
>>> 
>>> Looking forward to seeing everyone in Brisbane and talking about CLAT recommendations, the draft Jen and I are coauthoring, as Windows will be an implementor!
>>> 
>>> Thanks,
>>> Tommy
>>> _______________________________________________
>>> v6ops mailing list
>>> v6ops@ietf.org
>>> https://www.ietf.org/mailman/listinfo/v6ops
>>> _______________________________________________
>>> v6ops mailing list
>>> v6ops@ietf.org
>>> https://www.ietf.org/mailman/listinfo/v6ops
>> 
>> 
>> _______________________________________________
>> v6ops mailing list
>> v6ops@ietf.org
>> https://www.ietf.org/mailman/listinfo/v6ops
> 
> 
> 
> --
> Cheers, Jen Linkova



_______________________________________________
v6ops mailing list
v6ops@ietf.org
https://www.ietf.org/mailman/listinfo/v6ops