Hacker News new | past | comments | ask | show | jobs | submit login

One thing is thar length of IPv6 means it is hard to assign addresses manually so need system to automate it. Which makes easier to renumber if change ISP.

I didn’t think that ULA is deprecated, what is deprecated is NAT with ULA. The other thing is that can have multiples addresses. It makes sense to have hosts on public IP and servers have public IP and ULA. This is the zero trust approach.

The other approach is everything gets ULA and ULA is router on VPNs.




It's not that ULA is deprecated, but it discouraged, and this has led to implementation hurdles, like the fact that if you have a device with ULA addresses and GUA addresses, then your device will originate its requests, even to ULAs, from its GUA. So now your firewall rules need to specify the GUA in the source address field, for example, or you need to reconfigure every client directly.

(Also if you're running your services on the GUA, then the destination address also needs to reflect that in the firewall rule).




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: