<?xml version="1.0" encoding="utf-8" ?>

<rss version="2.0" 
   xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
   xmlns:admin="http://webns.net/mvcb/"
   xmlns:dc="http://purl.org/dc/elements/1.1/"
   xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
   xmlns:wfw="http://wellformedweb.org/CommentAPI/"
   xmlns:content="http://purl.org/rss/1.0/modules/content/"
   >
<channel>
    
    <title>Andrew's blog (Entries tagged as ipv6)</title>
    <link>https://blog.etc.gen.nz/</link>
    <description>This is a blog, it is it is.</description>
    <dc:language>en</dc:language>
    <admin:errorReportsTo rdf:resource="mailto:blog@etc.gen.nz" />
    <generator>Serendipity 2.4.0 - http://www.s9y.org/</generator>
    <pubDate>Wed, 08 Jun 2011 00:58:57 GMT</pubDate>

    <image>
    <url>https://blog.etc.gen.nz/templates/2k11/img/s9y_banner_small.png</url>
    <title>RSS: Andrew's blog - This is a blog, it is it is.</title>
    <link>https://blog.etc.gen.nz/</link>
    <width>100</width>
    <height>21</height>
</image>

<item>
    <title>Wolrd IPv6 Day - Catalyst</title>
    <link>https://blog.etc.gen.nz/archives/120-Wolrd-IPv6-Day-Catalyst.html</link>
            <category>catalyst</category>
            <category>family</category>
    
    <comments>https://blog.etc.gen.nz/archives/120-Wolrd-IPv6-Day-Catalyst.html#comments</comments>
    <wfw:comment>https://blog.etc.gen.nz/wfwcomment.php?cid=120</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>https://blog.etc.gen.nz/rss.php?version=2.0&amp;type=comments&amp;cid=120</wfw:commentRss>
    

    <author>andrew@etc.gen.nz (Andrew Ruthven)</author>
    <content:encoded>
    Excellent, due to a little hack we now have the &lt;a onclick=&quot;_gaq.push([&#039;_trackPageview&#039;, &#039;/extlink/www.catalyst.net.nz&#039;]);&quot;  href=&quot;http://www.catalyst.net.nz&quot;&gt;Catalyst website&lt;/a&gt; up on IPv6.  Thanks David!&lt;br /&gt;
&lt;br /&gt;
This is using the same method that we used to get another large NZ site IPv6 enabled for World IPv6 Day.&lt;br /&gt;
&lt;br /&gt;
Funnily enough we&#039;ve discovered there is a NZ company that is providing a commercial solution using the same method we&#039;re using.  Even though it is dirty, and is really, &lt;b&gt;really&lt;/b&gt; the wrong way to do it.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Note:&lt;/b&gt; It is worth noting that Catalyst&#039;s email server has been IPv6 enabled for several years now, as have our DNS servers. 
    </content:encoded>

    <pubDate>Wed, 08 Jun 2011 00:39:21 +0000</pubDate>
    <guid isPermaLink="false">https://blog.etc.gen.nz/archives/120-guid.html</guid>
    <category>catalyst</category>
<category>family</category>
<category>geek</category>
<category>ipv6</category>

</item>
<item>
    <title>World IPv6 Day</title>
    <link>https://blog.etc.gen.nz/archives/119-World-IPv6-Day.html</link>
            <category>catalyst</category>
            <category>family</category>
    
    <comments>https://blog.etc.gen.nz/archives/119-World-IPv6-Day.html#comments</comments>
    <wfw:comment>https://blog.etc.gen.nz/wfwcomment.php?cid=119</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>https://blog.etc.gen.nz/rss.php?version=2.0&amp;type=comments&amp;cid=119</wfw:commentRss>
    

    <author>andrew@etc.gen.nz (Andrew Ruthven)</author>
    <content:encoded>
    In the vein of &lt;a onclick=&quot;_gaq.push([&#039;_trackPageview&#039;, &#039;/extlink/worldipv6day.org&#039;]);&quot;  href=&quot;http://worldipv6day.org&quot;&gt;World IPv6 Day&lt;/a&gt;, I&#039;ve finally re-enabled IPv6 for the etc.gen.nz mailserver and for our &lt;a onclick=&quot;_gaq.push([&#039;_trackPageview&#039;, &#039;/extlink/www.etc.gen.nz&#039;]);&quot;  href=&quot;http://www.etc.gen.nz&quot;&gt;main website&lt;/a&gt; (and my &lt;a onclick=&quot;_gaq.push([&#039;_trackPageview&#039;, &#039;/extlink/git.etc.gen.nz&#039;]);&quot;  href=&quot;http://git.etc.gen.nz&quot;&gt;git repo&lt;/a&gt;).&lt;br /&gt;
&lt;br /&gt;
These services used to have IPv6 enabled, but when I moved them from my home server to one hosted in a data centre we lost IPv6 support.  However in the last few months, our hosting company has deployed IPv6 support to their hosting facility, and I finally found time to finish setting it up on the server.&lt;br /&gt;
&lt;br /&gt;
So, we&#039;re back on IPv6, just in time for World IPv6 Day! 
    </content:encoded>

    <pubDate>Tue, 07 Jun 2011 21:30:58 +0000</pubDate>
    <guid isPermaLink="false">https://blog.etc.gen.nz/archives/119-guid.html</guid>
    <category>catalyst</category>
<category>family</category>
<category>geek</category>
<category>ipv6</category>

</item>
<item>
    <title>IPv6 Steering Group Technical SIG - Announcement/Invitation</title>
    <link>https://blog.etc.gen.nz/archives/87-IPv6-Steering-Group-Technical-SIG-AnnouncementInvitation.html</link>
            <category>catalyst</category>
    
    <comments>https://blog.etc.gen.nz/archives/87-IPv6-Steering-Group-Technical-SIG-AnnouncementInvitation.html#comments</comments>
    <wfw:comment>https://blog.etc.gen.nz/wfwcomment.php?cid=87</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>https://blog.etc.gen.nz/rss.php?version=2.0&amp;type=comments&amp;cid=87</wfw:commentRss>
    

    <author>andrew@etc.gen.nz (Andrew Ruthven)</author>
    <content:encoded>
    Here&#039;s an email I&#039;ve just received about a new IPv6 group in New Zealand, if you have an interested in the future of IPv6 in New Zealand, please join:

&lt;pre&gt;
A workshop at held at InternetNZ on the 28 November in Wellington
saw the formation of a New Zealand IPv6 Steering Group. This group includes
representatives from telecommunications carriers, internet service
providers, ICT vendors, and industry and user associations. The members of this
steering group consist of invited senior representatives from the following organisations:

InternetNZ
TUANZ
ISPANZ
Telecommunications Carriers Forum
Digital Development Forum
Telecom
TelstraClear
WorldXChange
Orcon
FX Networks
REANNZ
Canterbury Development Corporation
Kordia
Cisco
Vodafone
Juniper Networks
Alcatel Lucent
Braintrust


This steering group will primarily be concerned with high level discussion
regarding the deployment of IPv6 within New Zealand. The steering group
will not necessarily be a place where technical discussion takes place.

As with so many things these days, a combination of business and
technical expertise must be bought together to solve a given problem.
To this end at the same workshop a Technical Special Interest Group
(TechSIG) was also established.

The goals of this group are:

. To act as a central point for IPv6 technical discussion within the
    New Zealand Internet community.
. To identify to the IPv6 Steering Group any business related barriers
    to IPv6 deployment which have been identified by the SIG&#039;s
    technical contributors.
. To comment and provide potential solutions to technical related barriers
    identified by members of the IPv6 Steering Group.
. To stimulate the production of relevant technical documentation.

The co-conveners of this group are

Andy Linton
Nathan Ward
Brian Carpenter
Dean Pemberton

A mailing list has been created and membership is open to all interested
parties.  Subscription details can be found at the link below;
http://listserver.internetnz.net.nz/mailman/listinfo/ipv6-techsig

I would encourage anyone who has an interest in the deployment and growth
of IPv6 to join and contribute to the list.

Please do not feel that this is a &#039;Networking Specialist Only&#039; list. The
deployment of IPv6 (and depletion of IPv4) has just as significant an
impact on system administrators and content/application providers as it
does on network administrators. I welcome all technical viewpoints onto the list.


Thank you for your time.

Dean Pemberton
(Co-convener, IPv6 Steering Group Technical SIG)
&lt;/pre&gt; 
    </content:encoded>

    <pubDate>Thu, 18 Dec 2008 20:15:47 +0000</pubDate>
    <guid isPermaLink="false">https://blog.etc.gen.nz/archives/87-guid.html</guid>
    <category>catalyst</category>
<category>geek</category>
<category>ipv6</category>

</item>
<item>
    <title>The Day the Routers Died</title>
    <link>https://blog.etc.gen.nz/archives/73-The-Day-the-Routers-Died.html</link>
            <category>catalyst</category>
    
    <comments>https://blog.etc.gen.nz/archives/73-The-Day-the-Routers-Died.html#comments</comments>
    <wfw:comment>https://blog.etc.gen.nz/wfwcomment.php?cid=73</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>https://blog.etc.gen.nz/rss.php?version=2.0&amp;type=comments&amp;cid=73</wfw:commentRss>
    

    <author>andrew@etc.gen.nz (Andrew Ruthven)</author>
    <content:encoded>
    A fantastic &lt;a onclick=&quot;_gaq.push([&#039;_trackPageview&#039;, &#039;/extlink/www.youtube.com/watch?v=_y36fG2Oba0&#039;]);&quot;  href=&quot;http://www.youtube.com/watch?v=_y36fG2Oba0&quot;&gt;song&lt;/a&gt; from the &lt;a onclick=&quot;_gaq.push([&#039;_trackPageview&#039;, &#039;/extlink/www.ripe.net/ripe/meetings/ripe-55/&#039;]);&quot;  href=&quot;http://www.ripe.net/ripe/meetings/ripe-55/&quot;&gt;RIPE 55&lt;/a&gt; Meeting.&lt;br /&gt;
&lt;br /&gt;
I&#039;ll try the embedded thing as well...&lt;br /&gt;
&lt;br /&gt;
&lt;object width=&quot;425&quot; height=&quot;355&quot;&gt;&lt;param name=&quot;movie&quot; value=&quot;http://www.youtube.com/v/_y36fG2Oba0&amp;rel=1&quot;&gt;&lt;/param&gt;&lt;param name=&quot;wmode&quot; value=&quot;transparent&quot;&gt;&lt;/param&gt;&lt;embed src=&quot;http://www.youtube.com/v/_y36fG2Oba0&amp;rel=1&quot; type=&quot;application/x-shockwave-flash&quot; wmode=&quot;transparent&quot; width=&quot;425&quot; height=&quot;355&quot;&gt;&lt;/embed&gt;&lt;/object&gt; 
    </content:encoded>

    <pubDate>Tue, 30 Oct 2007 19:17:22 +0000</pubDate>
    <guid isPermaLink="false">https://blog.etc.gen.nz/archives/73-guid.html</guid>
    <category>catalyst</category>
<category>geek</category>
<category>ipv6</category>

</item>
<item>
    <title>No Google juice for us</title>
    <link>https://blog.etc.gen.nz/archives/64-No-Google-juice-for-us.html</link>
            <category>catalyst</category>
            <category>family</category>
    
    <comments>https://blog.etc.gen.nz/archives/64-No-Google-juice-for-us.html#comments</comments>
    <wfw:comment>https://blog.etc.gen.nz/wfwcomment.php?cid=64</wfw:comment>

    <slash:comments>3</slash:comments>
    <wfw:commentRss>https://blog.etc.gen.nz/rss.php?version=2.0&amp;type=comments&amp;cid=64</wfw:commentRss>
    

    <author>andrew@etc.gen.nz (Andrew Ruthven)</author>
    <content:encoded>
    We normally see quite a few people finding this blog via Google.  It can be quite amusing to see what search terms led to us.&lt;br /&gt;
&lt;br /&gt;
Earlier this month I decided to check it out again, there were no hits from Google.  At all.  This was kinda odd, as the googlebots (both for the search engine and for &lt;a onclick=&quot;_gaq.push([&#039;_trackPageview&#039;, &#039;/extlink/reader.google.com&#039;]);&quot;  href=&quot;http://reader.google.com&quot;&gt;reader&lt;/a&gt;) normally hit us quite often.&lt;br /&gt;
&lt;br /&gt;
Looking back through the logs the last time Google hit us was the 14th of March.  Which is quite some time ago.&lt;br /&gt;
&lt;br /&gt;
I cruised over to Google and checked Reader, and sure enough the most recent article from our blog is dated the 14th of March.  I then tried telling Google to index blog.etc.gen.nz using the WebMaster tools.  No dice, it says:&lt;br /&gt;
&lt;br /&gt;
  General HTTP error: Domain name not found&lt;br /&gt;
&lt;br /&gt;
Two things happened on that day:&lt;br /&gt;
&lt;ol&gt;&lt;br /&gt;
  &lt;li&gt; I moved from &lt;a onclick=&quot;_gaq.push([&#039;_trackPageview&#039;, &#039;/extlink/www.dyndns.org&#039;]);&quot;  href=&quot;http://www.dyndns.org&quot;&gt;DynDNS&lt;/a&gt; to &lt;a onclick=&quot;_gaq.push([&#039;_trackPageview&#039;, &#039;/extlink/afraid.org&#039;]);&quot;  href=&quot;http://afraid.org&quot;&gt;FreeDNS&lt;/a&gt;,&lt;br /&gt;
  &lt;li&gt; I added AAAA (IPv6) records to some of my hosts, which is why I moved to FreeDNS.  DynDNS doesn&#039;t support that.&lt;br /&gt;
&lt;/ol&gt;&lt;br /&gt;
It appears that one of those changes caused Google to start ignoring us.  And in fact, it is the change to FreeDNS.&lt;br /&gt;
&lt;br /&gt;
Damn.&lt;br /&gt;
&lt;br /&gt;
I think it is finally time to bite the bullet and start running my own nameserver.  Which I want to do anyhow to start using DNSSEC...&lt;br /&gt;
&lt;br /&gt;
Some further investigations with the help of a mate (you know who you are) I&#039;ve discovered that FreeDNS is rejecting DNS queries from Google.  I&#039;m &lt;a onclick=&quot;_gaq.push([&#039;_trackPageview&#039;, &#039;/extlink/leon.info.tm/tags/freedns-afraid-org&#039;]);&quot;  href=&quot;http://leon.info.tm/tags/freedns-afraid-org&quot;&gt;not the only one&lt;/a&gt; to have encountered this problem.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;Update:&lt;/b&gt; The issue is FreeDNS.  Updated entry to reflect that.&lt;br /&gt;
&lt;b&gt;Update 2:&lt;/b&gt; Okay, the FreeDNS maintainer is now allowing Google to access our DNS entries again, so we&#039;re back in Google.  But still, bizarre. 
    </content:encoded>

    <pubDate>Fri, 20 Jul 2007 03:02:46 +0000</pubDate>
    <guid isPermaLink="false">https://blog.etc.gen.nz/archives/64-guid.html</guid>
    <category>catalyst</category>
<category>dns</category>
<category>family</category>
<category>geek</category>
<category>google</category>
<category>ipv6</category>

</item>
<item>
    <title>IPv6 .nz name servers</title>
    <link>https://blog.etc.gen.nz/archives/57-IPv6-.nz-name-servers.html</link>
            <category>catalyst</category>
    
    <comments>https://blog.etc.gen.nz/archives/57-IPv6-.nz-name-servers.html#comments</comments>
    <wfw:comment>https://blog.etc.gen.nz/wfwcomment.php?cid=57</wfw:comment>

    <slash:comments>2</slash:comments>
    <wfw:commentRss>https://blog.etc.gen.nz/rss.php?version=2.0&amp;type=comments&amp;cid=57</wfw:commentRss>
    

    <author>andrew@etc.gen.nz (Andrew Ruthven)</author>
    <content:encoded>
    The IPv6 .nz name servers and whois server are now up and running.  The announcement from &lt;a onclick=&quot;_gaq.push([&#039;_trackPageview&#039;, &#039;/extlink/www.nzrs.net.nz&#039;]);&quot;  href=&quot;http://www.nzrs.net.nz&quot;&gt;.nz Registry Services&lt;/a&gt; sent to NZNOG:&lt;br /&gt;
&lt;hr /&gt;&lt;br /&gt;
&lt;tt&gt;NZRS is today pleased to announce that the .nz name servers are now operating&lt;br /&gt;
with IPv6 connectivity in what can be regarded as the first phase of the .nz&lt;br /&gt;
IPv6 rollout. The name servers are named ns8.dns.net.nz and ns9.dns.net.nz, and&lt;br /&gt;
are located in Wellington and Albany repsectively.&lt;br /&gt;
&lt;br /&gt;
Both are connected to the NZ IPv6 Internet Exchange and there is a .nz Whois&lt;br /&gt;
server accessible at whois.ipv6.srs.net.nz.&lt;br /&gt;
&lt;br /&gt;
NZRS thanks Open Contributors Corporation for Advanced  Internet Development&lt;br /&gt;
(&lt;a onclick=&quot;_gaq.push([&#039;_trackPageview&#039;, &#039;/extlink/www.occaid.net/&#039;]);&quot;  href=&quot;http://www.occaid.net/&quot;&gt;OCCAID&lt;/a&gt;) and US telco &lt;a onclick=&quot;_gaq.push([&#039;_trackPageview&#039;, &#039;/extlink/www.sprintv6.net/&#039;]);&quot;  href=&quot;http://www.sprintv6.net/&quot;&gt;Sprint&lt;/a&gt; for providing the IPv6 tunnels, and thanks &lt;a onclick=&quot;_gaq.push([&#039;_trackPageview&#039;, &#039;/extlink/www.citylink.co.nz&#039;]);&quot;  href=&quot;http://www.citylink.co.nz&quot;&gt;Citylink&lt;/a&gt;&lt;br /&gt;
for help in connecting to the &lt;a onclick=&quot;_gaq.push([&#039;_trackPageview&#039;, &#039;/extlink/v6ix.nzix.net/&#039;]);&quot;  href=&quot;http://v6ix.nzix.net/&quot;&gt;NZ IPv6 Internet Exchange&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
.nz Registry Services is responsible for the operation of the register of domain&lt;br /&gt;
names and the Domain Name System (DNS) in the .nz domain name space.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
For further information contact:&lt;br /&gt;
&lt;br /&gt;
support&lt; at &gt;nzrs.net.nz&lt;/tt&gt;&lt;br /&gt;
&lt;hr /&gt;&lt;br /&gt;
There might be a few more tweaks to the setup, but otherwise, it is looking good.&lt;br /&gt;
&lt;br /&gt;
If anyone is using IPv6 in New Zealand but are not peering with the &lt;a onclick=&quot;_gaq.push([&#039;_trackPageview&#039;, &#039;/extlink/v6ix.nzix.net&#039;]);&quot;  href=&quot;http://v6ix.nzix.net&quot;&gt;v6ix&lt;/a&gt; then please contact Andrew Ruthven at Catalyst (puck in catalyst.net.nz) to talk about tunnels or other peering arrangements. 
    </content:encoded>

    <pubDate>Wed, 13 Jun 2007 23:09:48 +0000</pubDate>
    <guid isPermaLink="false">https://blog.etc.gen.nz/archives/57-guid.html</guid>
    <category>catalyst</category>
<category>geek</category>
<category>ipv6</category>

</item>
<item>
    <title>Virus Scanners harmful for IPv6 adoption?</title>
    <link>https://blog.etc.gen.nz/archives/54-Virus-Scanners-harmful-for-IPv6-adoption.html</link>
            <category>catalyst</category>
    
    <comments>https://blog.etc.gen.nz/archives/54-Virus-Scanners-harmful-for-IPv6-adoption.html#comments</comments>
    <wfw:comment>https://blog.etc.gen.nz/wfwcomment.php?cid=54</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>https://blog.etc.gen.nz/rss.php?version=2.0&amp;type=comments&amp;cid=54</wfw:commentRss>
    

    <author>andrew@etc.gen.nz (Andrew Ruthven)</author>
    <content:encoded>
    Everybody thinks that running a virus scanner on a Windows box is a good thing, right?&lt;br /&gt;
&lt;br /&gt;
Well, it seems that it can be bad if you want to have working IPv6.&lt;br /&gt;
&lt;br /&gt;
I spent several hours at a customers site yesterday working on IPv6 enabling their Windows XP workstations, but was having issues.  I did the usual trick of turning off any and all Windows firewalls and the virus scanner, but we still had issues.&lt;br /&gt;
&lt;br /&gt;
The behaviour was that IPv6 addresses were being allocated, we could ping and tracert6 to IPv6 hosts, we could telnet to port 80 on them, but neither Internet Explorer or Firefox wanted to work.  Going to an IPv6 website would cause the browser to just hang.  Looking in a network dump I could see an initial connection being made to the server, but then no actual requests.&lt;br /&gt;
&lt;br /&gt;
I decided to blame the virus scanner, on the basis that they quite often interfere with the normal flow of events.  Even though it was turned off, it might still be interfering.  After actually uninstalling it (and rebooting, uninstalling it caused Internet Explorer to crash), everything worked!&lt;br /&gt;
&lt;br /&gt;
Moral of the story, if you&#039;re using a virus scanner (in this case &lt;a onclick=&quot;_gaq.push([&#039;_trackPageview&#039;, &#039;/extlink/www.eset.com&#039;]);&quot;  href=&quot;http://www.eset.com&quot;&gt;NOD32 from ESET&lt;/a&gt;) and you&#039;re having issues using IPv6, uninstall the virus scanner! 
    </content:encoded>

    <pubDate>Tue, 05 Jun 2007 20:33:14 +0000</pubDate>
    <guid isPermaLink="false">https://blog.etc.gen.nz/archives/54-guid.html</guid>
    <category>catalyst</category>
<category>geek</category>
<category>ipv6</category>

</item>
<item>
    <title>IPv6 BitTorrent</title>
    <link>https://blog.etc.gen.nz/archives/52-IPv6-BitTorrent.html</link>
            <category>catalyst</category>
    
    <comments>https://blog.etc.gen.nz/archives/52-IPv6-BitTorrent.html#comments</comments>
    <wfw:comment>https://blog.etc.gen.nz/wfwcomment.php?cid=52</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>https://blog.etc.gen.nz/rss.php?version=2.0&amp;type=comments&amp;cid=52</wfw:commentRss>
    

    <author>andrew@etc.gen.nz (Andrew Ruthven)</author>
    <content:encoded>
    The guys at &lt;a onclick=&quot;_gaq.push([&#039;_trackPageview&#039;, &#039;/extlink/www.sixxs.net&#039;]);&quot;  href=&quot;http://www.sixxs.net&quot;&gt;SixXS&lt;/a&gt; have added a new tool to their treasure trove of IPv6 tools.  A BitTorrent tracker available only via IPv6.&lt;br /&gt;
&lt;br /&gt;
Go and check out the &lt;a onclick=&quot;_gaq.push([&#039;_trackPageview&#039;, &#039;/extlink/www.sixxs.net/tools/tracker/catalog/&#039;]);&quot;  href=&quot;http://www.sixxs.net/tools/tracker/catalog/&quot;&gt;catalog&lt;/a&gt; for some installation CDs and whatever else they throw up there. 
    </content:encoded>

    <pubDate>Sun, 27 May 2007 22:35:53 +0000</pubDate>
    <guid isPermaLink="false">https://blog.etc.gen.nz/archives/52-guid.html</guid>
    <category>catalyst</category>
<category>geek</category>
<category>ipv6</category>

</item>
<item>
    <title>IPv6 Enabled</title>
    <link>https://blog.etc.gen.nz/archives/44-IPv6-Enabled.html</link>
            <category>catalyst</category>
    
    <comments>https://blog.etc.gen.nz/archives/44-IPv6-Enabled.html#comments</comments>
    <wfw:comment>https://blog.etc.gen.nz/wfwcomment.php?cid=44</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>https://blog.etc.gen.nz/rss.php?version=2.0&amp;type=comments&amp;cid=44</wfw:commentRss>
    

    <author>andrew@etc.gen.nz (Andrew Ruthven)</author>
    <content:encoded>
    Our blog is now accessible via the IPv6 Internet.  While I&#039;ve had the network IPv6 enabled for few months now, I&#039;ve finally taken the plunge and changed Dynamic DNS providers, which means I can make our addresses available via DNS.&lt;br /&gt;
&lt;br /&gt;
I used &lt;a onclick=&quot;_gaq.push([&#039;_trackPageview&#039;, &#039;/extlink/www.dyndns.org&#039;]);&quot;  href=&quot;http://www.dyndns.org&quot;&gt;DynDNS&lt;/a&gt; for many years, but unfortunately they don&#039;t support AAAA records.  I&#039;m now using &lt;a onclick=&quot;_gaq.push([&#039;_trackPageview&#039;, &#039;/extlink/www.afraid.org&#039;]);&quot;  href=&quot;http://www.afraid.org&quot;&gt;FreeDNS&lt;/a&gt;.  They allow a domain name to have a static AAAA record and then dynamic updating of an A record.  Which is exactly what I need! 
    </content:encoded>

    <pubDate>Thu, 15 Mar 2007 08:31:33 +0000</pubDate>
    <guid isPermaLink="false">https://blog.etc.gen.nz/archives/44-guid.html</guid>
    <category>geek</category>
<category>ipv6</category>

</item>
<item>
    <title>IPv6 Firewalling</title>
    <link>https://blog.etc.gen.nz/archives/43-IPv6-Firewalling.html</link>
            <category>catalyst</category>
    
    <comments>https://blog.etc.gen.nz/archives/43-IPv6-Firewalling.html#comments</comments>
    <wfw:comment>https://blog.etc.gen.nz/wfwcomment.php?cid=43</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>https://blog.etc.gen.nz/rss.php?version=2.0&amp;type=comments&amp;cid=43</wfw:commentRss>
    

    <author>andrew@etc.gen.nz (Andrew Ruthven)</author>
    <content:encoded>
    Firewalling IPv6 on Linux seems to be a vaguely documented topic, and most of that documentation seems to be out of date as it is a fast moving target.  I&#039;ve spent a bit of time over the last couple of days working on improving my firewalling situation and thought I should write up what I&#039;ve found.&lt;br /&gt;
&lt;br /&gt;
After a bit of digging I found that while IPv6 connection tracking was merged in 2.6.16, the configuration options are somewhat hidden.  Up until yesterday I was running 2.6.19.x on my firewall and I discovered that while ip6tables allowed me to configure a stateful firewall, it wasn&#039;t actually doing anything!&lt;br /&gt;
&lt;br /&gt;
I looked around for the required nf_conntrack_ipv6 module and couldn&#039;t find it.  I looked in my running kernels config and couldn&#039;t find it.   In fact I couldn&#039;t find any option for enabling IPv6 connection tracking at all.  After some digging (grep&#039;ing the Kconfig files helps) I found that I needed to change over to the new (experimental) Layer 3 Independent Connection tracking support.&lt;br /&gt;
&lt;br /&gt;
The catch here is that if you have the old school Connection tracking (CONFIG_IP_NF_CONNTRACK) enabled you&#039;ll never see the new independent method (CONFIG_NF_CONNTRACK) in menuconfig.  Which is why I&#039;d never seen it before.  So I disabled CONFIG_IP_NF_CONNTRACK (in IP: Netfilter Configuration), enabled (the now visible) CONFIG_NF_CONNTRACK (in Core Netfilter Configuration) went into both the IP and IPv6 Netfilter Configuration menus and selected support for the connection tracking option.&lt;br /&gt;
&lt;br /&gt;
Compiled, installed and rebooted.  Suddenly I had IPv6 connection tracking working.  w00t!  But no IPv4 NAT.  Damn.  It turns out that IPv4 NAT support was only ported to the new Layer 3 Independent Connection stuff in 2.6.20.&lt;br /&gt;
&lt;br /&gt;
So I downloaded 2.6.20.3, jumped into the IP: Netfilter  Configuration menu and found &quot;Full NAT&quot;.  That&#039;s what I want.  Compiled, installed and rebooted.&lt;br /&gt;
&lt;br /&gt;
Now I have my old IPv4 NAT working, &lt;b&gt;and&lt;/b&gt; a full stateful IPv6 firewall (with no NAT!).&lt;br /&gt;
&lt;br /&gt;
Oh, if you are using IPv6 stateful firewalling with Linux then you want to upgrade to 2.6.20.3, it fixes an issue with incorrectly classifying IPv6 fragments as ESTABLISHED and letting them through.  Oops.  Also, 2.6.20 moves the config options around again... 
    </content:encoded>

    <pubDate>Wed, 14 Mar 2007 22:02:10 +0000</pubDate>
    <guid isPermaLink="false">https://blog.etc.gen.nz/archives/43-guid.html</guid>
    <category>ipv6</category>
<category>kernel</category>
<category>linux</category>
<category>software</category>

</item>

</channel>
</rss>
