ipv6 revision 499b34cea04a46823d003d4c0520c8b03e8513cb
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de ReeperCopyright (C) 2000, 2001 Internet Software Consortium.
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de ReeperSee COPYRIGHT in the source root or http://isc.org/copyright.html for terms.
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reeper
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de ReeperCurrently, there are multiple interesting problems with ipv6
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reeperimplementations on various platforms. These problems range from not
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reeperbeing able to use ipv6 with bind9 (or in particular the ISC socket
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reeperlibrary, contained in libisc) to listen-on lists not being respected,
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reeperto strange warnings but seemingly correct behavior of named.
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reeper
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de ReeperCOMPILE-TIME ISSUES
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reeper-------------------
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reeper
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de ReeperThe socket library requires a certain level of support from the
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reeperoperating system. In particular, it must follow the advanced ipv6
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reepersocket API to be usable. The systems which do not follow this will
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reepercurrently not get any warnings or errors, but ipv6 will simply not
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reeperfunction on them.
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reeper
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de ReeperThese systems currently include, but are not limited to:
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reeper
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reeper AIX 3.4 (with ipv6 patches)
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reeper
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reeper
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de ReeperRUN-TIME ISSUES
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reeper---------------
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reeper
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de ReeperIn the original drafts of the ipv6 RFC documents, binding an ipv6
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reepersocket to the ipv6 wildcard address would also cause the socket to
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reeperaccept ipv4 connections and datagrams. When an ipv4 packet is
5c39d8f041417518a02ce2c941d96c2d33b2a364Mark de Reeperreceived on these systems, it is mapped into an ipv6 address. For
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reeperexample, 1.2.3.4 would be mapped into ffff::1.2.3.4. The intent of
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reeperthis mapping was to make transition from an ipv4-only application into
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reeperipv6 easier, by only requiring one socket to be open on a given port.
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reeper
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de ReeperLater, it was discovered that this was generally a bad idea. For one,
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reepermany firewalls will block connection to 1.2.3.4, but will let through
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reeperffff::1.2.3.4. This, of course, is bad. Also, access control lists
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reeperwritten to accept only ipv4 addresses were suddenly ignored unless
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reeperthey were rewritten to handle the ipv6 mapped addresses as well.
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reeper
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de ReeperIn bind9, we always bind to the ipv6 wildcard port for both TCP and
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de ReeperUDP, and specific addresses for ipv4 sockets. This causes some
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reeperinteresting behavior depending on the system implementation of ipv6.
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reeper
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reeper
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de ReeperIPV6 Sockets Accept IPV4, Specific IPV4 Addresses Bindings Fail
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reeper---------------------------------------------------------------
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reeper
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de ReeperThe only OS which seems to do this is linux. If an ipv6 socket is
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reeperbound to the ipv6 wildcard socket, and a specific ipv4 socket is
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reeperlater bound (say, to 1.2.3.4 port 53) the ipv4 binding will fail.
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reeper
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de ReeperWhat this means to bind9 is that the application will log warnings
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reeperabout being unable to bind to a socket because the address is already
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reeperin use. Since the ipv6 socket will accept ipv4 packets and map them,
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reeperhowever, the ipv4 addresses continue to function.
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reeper
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de ReeperThe effect is that the config file listen-on directive will not be
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reeperrespected on these systems.
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reeper
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reeper
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de ReeperIPV6 Sockets Accept IPV4, Specific IPV4 Address Bindings Succeed
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reeper----------------------------------------------------------------
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reeper
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de ReeperIn this case, the system allows opening an ipv6 wildcard address
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reepersocket and then binding to a more specific ipv4 address later. An
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reeperexample of this type of system is Digital Unix with ipv6 patches
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reeperapplied.
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reeper
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de ReeperWhat this means to bind9 is that the application will respect
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reeperlisten-on in regards to ipv4 sockets, but it will use mapped ipv6
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reeperaddresses for any that do not match the listen-on list. This, in
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reepereffect, makes listen-on useless for these machines as well.
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reeper
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reeper
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de ReeperIPV6 Sockets Do Not Accept IPV4
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reeper-------------------------------
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reeper
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de ReeperOn these systems, opening an IPV6 socket does not implicitly open any
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reeperipv4 sockets. An example of these systems are NetBSD-current with the
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reeperlatest KAME patch, and other systems which use the latest KAME patches
6406210b71fd4a97800f32f3613eea9b6a6a12ceMark de Reeperas their ipv6 implementation.
On these systems, listen-on is fully functional, as the ipv6 socket
only accepts ipv6 packets, and the ipv4 sockets will handle the ipv4
packets.
RELEVANT RFCs
-------------
2373: IP Version 6 Addressing Architecture
2553: Basic Socket Interface Extensions for IPv6
draft-ietf-ipngwg-rfc2292bis-01: Advanced Sockets API for IPv6 (draft)
$Id: ipv6,v 1.5 2001/01/09 21:50:27 bwelling Exp $