singtel ipv6 down?

xiaofan

High Supremacy Member
Joined
Sep 16, 2018
Messages
35,315
Reaction score
11,860
Now singtel 6rd ipv6 doesn't work even after I reboot ONT and router.

FYI I have no issues with both Singtel native IPv6 (start with 2402:d802) and 6rd (start with 2402:d803). I am using OpenWRT as the main router for both networks.
 

bert64

Senior Member
Joined
Jan 20, 2020
Messages
1,027
Reaction score
539
FYI I have no issues with both Singtel native IPv6 (start with 2402:d802) and 6rd (start with 2402:d803). I am using OpenWRT as the main router for both networks.
Previously there were some bugs whereby it would stop forwarding traffic, and you'd need to release/renew DHCP to get a new legacy address before it would forward traffic to you again. I'm not sure what triggered that.

The tunnel server also has a whitelist of legacy address space it will forward for (ie to prevent non customers from using it), it's possible that they haven't added everything so depending what address you get assigned you might not be able to use it.
 

fromnuaa

Member
Joined
Jan 28, 2008
Messages
140
Reaction score
15
Today Singtel call me and ask if ipv6 still not working.

Yes, IPv6 still not working.

Singtel says that most technicians don't know ipv6, so it's useless to send a technician to my home to check ipv6.

I am still waiting for next call from Singtel.
 

bert64

Senior Member
Joined
Jan 20, 2020
Messages
1,027
Reaction score
539
curious, but how does ipv6 so significant to you?
There are a lot of things online now which are IPv6-only, for a sample list of sites:
https://www.ev6.net/v6sites.php

IPv6-only hosting is cheaper.
Many users in other countries do not have public legacy IP, they can ONLY host via IPv6. There are lots of people in China, Thailand etc who have NAS devices and other things online only via v6.
There are quite a few tv streams online which are v6-only, especially from china.
Microsoft and Apple both recommend using v6.
p2p works better when everything has routable addresses - not just the likes of bittorrent, many things do p2p like voice calls in telegram/whatsapp and games.
 

HiHelloBye

Senior Member
Joined
Oct 8, 2010
Messages
1,353
Reaction score
400
There are a lot of things online now which are IPv6-only, for a sample list of sites:
https://www.ev6.net/v6sites.php

IPv6-only hosting is cheaper.
Many users in other countries do not have public legacy IP, they can ONLY host via IPv6. There are lots of people in China, Thailand etc who have NAS devices and other things online only via v6.
There are quite a few tv streams online which are v6-only, especially from china.
Microsoft and Apple both recommend using v6.
p2p works better when everything has routable addresses - not just the likes of bittorrent, many things do p2p like voice calls in telegram/whatsapp and games.
hmm interesting, thanks for sharing...

accessible via ipv6 only? this doesn't provide much flexibility for users, but more to a 'disruptive' approach...
reason being is, we still have/using ipv4

but nevertheless, from what i'm seeing, the ipv6 implementation in SG isn't so robust yet:s22:
 

bert64

Senior Member
Joined
Jan 20, 2020
Messages
1,027
Reaction score
539
hmm interesting, thanks for sharing...

accessible via ipv6 only? this doesn't provide much flexibility for users, but more to a 'disruptive' approach...
reason being is, we still have/using ipv4

but nevertheless, from what i'm seeing, the ipv6 implementation in SG isn't so robust yet:s22:
Other countries are far ahead - malaysia, vietnam, thailand, india, china etc...
A lot of users have no choice - ISPs in many countries use CGNAT by default but provide routable v6, so if they want to access anything they host at home it's either use v6 or use a third party service (likely to add cost, add latency, privacy concerns etc). On the list of v6-only hosts there are quite a lot of home nas deployments in china for instance.
 

sglandscape

Supremacy Member
Joined
Jan 30, 2023
Messages
6,064
Reaction score
2,922
Other countries are far ahead - malaysia, vietnam, thailand, india, china etc...
A lot of users have no choice - ISPs in many countries use CGNAT by default but provide routable v6, so if they want to access anything they host at home it's either use v6 or use a third party service (likely to add cost, add latency, privacy concerns etc). On the list of v6-only hosts there are quite a lot of home nas deployments in china for instance.

Those countries are far ahead because they have no choice, not because they want to be. They created the network likely with CGNAT as the backbone, and IPv6 if a publicly reachable IP is required. There were limited IPv4 blocks left, and they have a population that would have resulted in it being cost exorbitant to give a public IPv4 address.

Having said that, no reason why the rest of the world cannot catch up, except that there is minimal value to spend money on IPv6 that literally has 0 payback in the near term, and customers probably do not even care.
 

bert64

Senior Member
Joined
Jan 20, 2020
Messages
1,027
Reaction score
539
Those countries are far ahead because they have no choice, not because they want to be. They created the network likely with CGNAT as the backbone, and IPv6 if a publicly reachable IP is required. There were limited IPv4 blocks left, and they have a population that would have resulted in it being cost exorbitant to give a public IPv4 address.

Having said that, no reason why the rest of the world cannot catch up, except that there is minimal value to spend money on IPv6 that literally has 0 payback in the near term, and customers probably do not even care.
It's not just developing countries, there's other countries like the US, France and Germany where there is high deployment of v6, including 100% of mobile operators in these countries.

It's not that customers don't care, they simply don't know. Customers do care about things like latency, throughput and cost but they are not aware that v6 can improve these factors, and that the longer they stay with legacy networks the worse things will get.

On the infrastructure side it's also a monumental pain supporting legacy ip. You have to deal with address conservation, nat, logging and retention thereof so you have an audit trail of translated packets, log correlation between translated addressing schemes, address overlaps etc. It's a huge headache, which is why tech companies like microsoft and facebook moved to v6-only at the core years ago and relegated legacy ip to border load balancers solely to support legacy external users.
 
Last edited:

sglandscape

Supremacy Member
Joined
Jan 30, 2023
Messages
6,064
Reaction score
2,922
It's not just developing countries, there's other countries like the US, France and Germany where there is high deployment of v6, including 100% of mobile operators in these countries.

It's not that customers don't care, they simply don't know. Customers do care about things like latency, throughput and cost but they are not aware that v6 can improve these factors, and that the longer they stay with legacy networks the worse things will get.

On the infrastructure side it's also a monumental pain supporting legacy ip. You have to deal with address conservation, nat, logging and retention thereof so you have an audit trail of translated packets, log correlation between translated addressing schemes, address overlaps etc. It's a huge headache, which is why tech companies like microsoft and facebook moved to v6-only at the core years ago and relegated legacy ip to border load balancers solely to support legacy external users.

Would you know if latency is generally better on IPv6? In my experience in SG, HK and France, my experience has been quite the the opposite. Noticeable worse latency for IPv6 vs IPv4.

Choice of IP stack for the hyperscalers such as Microsoft and Facebook is not that relevant, if everyone else is not playing ball or decide to do the same, unfortunately.
 

bert64

Senior Member
Joined
Jan 20, 2020
Messages
1,027
Reaction score
539
Would you know if latency is generally better on IPv6? In my experience in SG, HK and France, my experience has been quite the the opposite. Noticeable worse latency for IPv6 vs IPv4.

Choice of IP stack for the hyperscalers such as Microsoft and Facebook is not that relevant, if everyone else is not playing ball or decide to do the same, unfortunately.
All else being equal latency on v6 will be slightly better due to slightly more efficient routing (eg not having to calculate a checksum every time a packet is forwarded, route aggregation etc).
If it takes a completely different path then latency could go either way, but then you have some redundancy at least.
If you have NAT in the way then v6 tends to pull ahead, sometimes significantly so.
There is old equipment which does legacy routing in hardware and v6 in software (eg cisco 3550/4000 series) but this is all eol and is a security risk for anyone still using it.

On my hosted boxes in germany, france and the uk (dual stack) latency on v6 is usually marginally better, but it's something like 1%. I also have some v6-only boxes because they're cheaper.
From Thailand it's a different story, i can only reach the box remotely via v6 because of CGNAT, and latency/throughput is significantly better over v6, and the gap widens a lot during peak times.

Tech companies migrate because they understand the benefits. Various governments (US, CZ, CN, IL etc) have similar policies.

There is also the security aspect, modern devices are v6 enabled by default and will communicate locally using v6 and prefer using v6 whenever available. If you've not implemented v6 then you're probably not monitoring it properly. I've done countless security tests where you could communicate between devices on the same VLAN using the link-local addresses and it went completely undetected by the NAC/IDS/etc systems.

What you have holding people back is fear of the unknown, and it's this lack of knowledge which leads to security holes. Once you deploy v6 and learn about it you start to realise how much better it is and how much hassle is avoided.
 

sglandscape

Supremacy Member
Joined
Jan 30, 2023
Messages
6,064
Reaction score
2,922
All else being equal latency on v6 will be slightly better due to slightly more efficient routing (eg not having to calculate a checksum every time a packet is forwarded, route aggregation etc).
If it takes a completely different path then latency could go either way, but then you have some redundancy at least.
If you have NAT in the way then v6 tends to pull ahead, sometimes significantly so.
There is old equipment which does legacy routing in hardware and v6 in software (eg cisco 3550/4000 series) but this is all eol and is a security risk for anyone still using it.

On my hosted boxes in germany, france and the uk (dual stack) latency on v6 is usually marginally better, but it's something like 1%. I also have some v6-only boxes because they're cheaper.
From Thailand it's a different story, i can only reach the box remotely via v6 because of CGNAT, and latency/throughput is significantly better over v6, and the gap widens a lot during peak times.

Tech companies migrate because they understand the benefits. Various governments (US, CZ, CN, IL etc) have similar policies.

There is also the security aspect, modern devices are v6 enabled by default and will communicate locally using v6 and prefer using v6 whenever available. If you've not implemented v6 then you're probably not monitoring it properly. I've done countless security tests where you could communicate between devices on the same VLAN using the link-local addresses and it went completely undetected by the NAC/IDS/etc systems.

What you have holding people back is fear of the unknown, and it's this lack of knowledge which leads to security holes. Once you deploy v6 and learn about it you start to realise how much better it is and how much hassle is avoided.
Thank you for sharing your experience. What I've found too in most corporate network even, firewalling for IPv6 is often poorly monitored and as you have pointed out link local connectivity is often overlooked too, especially if it's the same physical subnet.

In my limited experience, aside for having to deal with a dynamic prefix, setting up rules is a lot easier with IPv6 and there is no NAT to deal with. Logging is a ton easier too because the destination IP is what it is, without having to trace through the translation over NAT.
 

xiaofan

High Supremacy Member
Joined
Sep 16, 2018
Messages
35,315
Reaction score
11,860
One example of poor latency between local ISPs using IPv6 versus IPv4 is between SingTel and M1.

@Mach3.2 has done some analysis and the main culprit may be SingTel (M1 is also partially to be blamed). M1 has carried out some changes but I still see the problem over IPv6. No issues using IPv4.

It is a mixed bag for SingTel native IPv6 versus IPv4. Some routes using IPv6 get better and some get worse.

Not so sure about M1 and Starhub.
 

bert64

Senior Member
Joined
Jan 20, 2020
Messages
1,027
Reaction score
539
Thank you for sharing your experience. What I've found too in most corporate network even, firewalling for IPv6 is often poorly monitored and as you have pointed out link local connectivity is often overlooked too, especially if it's the same physical subnet.

In my limited experience, aside for having to deal with a dynamic prefix, setting up rules is a lot easier with IPv6 and there is no NAT to deal with. Logging is a ton easier too because the destination IP is what it is, without having to trace through the translation over NAT.

Typically most corporates think they don't have any v6 and ignore it completely, yet v6 is enabled by default on everything these days and in some cases cannot be disabled. This creates a big blind spot with the link-locals, and with portable devices like laptops that are moved to other networks. It's great fun during pentests.

Some places try to disable or block it, which is unsupported by vendors and often doesn't work or gets reverted by updates. The fact is if you're using anything made in the past 20 years you need awareness of IPv6, and IPv6-specific security measures wether you want to or not.

The only proper solution is to actually implement v6 properly, and ensure it's factored into your security plans. You see big players like MS, Google, Facebook and the US government doing exactly this.

And yes you're correct, v6 is much easier and cleaner to handle firewall rules and logging, and a dynamic prefix is a factor caused by a lousy consumer isp that doesn't follow recommendations. On a larger corporate scale you wouldn't have to worry about a dynamic prefix, and you'd have much bigger problems caused by legacy ip.

Consider the inconvenience of legacy nat/firewall rules on a small home network vs simple v6 rules, and then multiply this inconvenience when you're running a larger network with multiple sites. When you have a larger company which acquires smaller ones and tries to integrate networks you often find that they both use the same RFC1918 address space. If your business model involves interconnects between customer/supplier networks the same problem can occur - conflicting address space.

For very large companies it's also common to completely run out of RFC1918 address space, where such companies often just picked random legacy blocks that weren't in use at the time, only for those blocks to later be allocated to someone. For instance a company i deal with decided to use addresses starting 20.x, only now a lot of 20.x addresses are owned by MS and used for Azure so now they have sporadic issues where a site hosted on azure resolves to a 20.x address which then routes back internally.
 
Last edited:

bert64

Senior Member
Joined
Jan 20, 2020
Messages
1,027
Reaction score
539
One example of poor latency between local ISPs using IPv6 versus IPv4 is between SingTel and M1.

@Mach3.2 has done some analysis and the main culprit may be SingTel (M1 is also partially to be blamed). M1 has carried out some changes but I still see the problem over IPv6. No issues using IPv4.

It is a mixed bag for SingTel native IPv6 versus IPv4. Some routes using IPv6 get better and some get worse.

Not so sure about M1 and Starhub.
Yes, but this is caused by lousy peering on the part of the ISP, and not an inherent weakness of IPv6. You will find that the traffic takes a different route, or has asymmetric routing whereby it takes a different path back etc.

This is largely caused by singtel trying to sell peering, whereas all the other providers have open peering policies locally, and there are many cases of singtel having inefficient routing for legacy traffic too.

If traffic flows via the same dual stack peering, then v6 traffic will be slightly quicker (usually <1%). If you have factors like NAT in the mix then v6 traffic can be a LOT faster.

The hardware for switching v6 is also simpler because v6 was designed to be routed in hardware so you will also have lower power usage under heavy loads.
 
Last edited:

fromnuaa

Member
Joined
Jan 28, 2008
Messages
140
Reaction score
15
Here is the latest update:
1. Using Singtel Mesh Router, whether native ipv6 or 6rd ipv6, pc can obtain ipv6 address, but it has no internet connection. Singtel spend one week to check it and can't find root cause.
2. Using EA8100 router:
when using 6rd ipv6, pc can obtain ipv6 address and has internet connection, but it's not very stable, sometimes ipv6 internet connection is lost.
when using native ipv6, pc can obtain ipv6 address and has no internet connection. Sometimes it affect ipv4 internet connection, need to reboot ONT to restore ipv4 internet connection.
 

xiaofan

High Supremacy Member
Joined
Sep 16, 2018
Messages
35,315
Reaction score
11,860
Here is the latest update:
1. Using Singtel Mesh Router, whether native ipv6 or 6rd ipv6, pc can obtain ipv6 address, but it has no internet connection. Singtel spend one week to check it and can't find root cause.
2. Using EA8100 router:
when using 6rd ipv6, pc can obtain ipv6 address and has internet connection, but it's not very stable, sometimes ipv6 internet connection is lost.
when using native ipv6, pc can obtain ipv6 address and has no internet connection. Sometimes it affect ipv4 internet connection, need to reboot ONT to restore ipv4 internet connection.

Linksys EA8100v1 stock FW is known to have IPv6 problems as previously reported by Starhub users.

If you want, you can flash Linksys EA8100v1 with OpenWRT and try again. You can use either the latest 24.10.0 version or the old stable version 23.05.5.
https://openwrt.org/toh/linksys/ea8100_v1
 

fromnuaa

Member
Joined
Jan 28, 2008
Messages
140
Reaction score
15
Hi,

Can help on how to setup singtel ipv6 on EA8100 with Openwrt?

Any image to show how to config it?


Linksys EA8100v1 stock FW is known to have IPv6 problems as previously reported by Starhub users.

If you want, you can flash Linksys EA8100v1 with OpenWRT and try again. You can use either the latest 24.10.0 version or the old stable version 23.05.5.
https://openwrt.org/toh/linksys/ea8100_v1
 

xiaofan

High Supremacy Member
Joined
Sep 16, 2018
Messages
35,315
Reaction score
11,860
Important Forum Advisory Note
This forum is moderated by volunteer moderators who will react only to members' feedback on posts. Moderators are not employees or representatives of HWZ Forums. Forum members and moderators are responsible for their own posts. Please refer to our Community Guidelines and Standards and Terms and Conditions for more information.
Top