This is Warren Kwok's Internet note pad, electronic diary, online rubbish journal, whatever you might name it ! It is an archive of my random thoughts in a chronological order. I am not good at reporting boring things and change them to lively. If you find this blog boring, sorry that it is your problem.
2011/06/23
Another way to look at IPv6 address space
I like to try to think of it in a dynamic way. If 1 million /64 subnets are assigned to people or electronic devices every second, then it would take 584,942 years to make the address space completely exhausted ((2 ^64 / (365*24*3600*10^6)). This is longer than the history of human civilization. Will IPv6 addresses be completely exhausted ? No way, no need to worry.
2011/06/22
ZSK rollover in Top Level Domains
com. – 1 weeks
org. – 3 weeks
asia. – 3 weeks
my. – 3 months
th. – 1 week
I can not locate any RFC related to this technical aspect. Intuitively, from a security angle, I incline to think 3 months is too long while 1 week ZSK will introduce heavy workload on the name servers. I tend to think 3 – 4 weeks is the best option.
2011/06/21
Assignment of two IPv6 addresses
Likewise, if a supermarket sells poor quality beef to customers, I have no choice but to assign this IPv6 address to the supermarket - 2001::bad:beef
2011/06/19
ipod battery
2011/06/18
Good news after World IPv6 Day
2011/06/17
APNIC’s new logo is fantastic
Well-done, APNIC.
2011/06/16
Chromebook disappointed me totally
Chromebook is no more than a thin client with the difference that the underlying OS is the Chrome browser. There might be arguments that it offers the benefits of fast boot-up (in a matter of less than 10 seconds), longer battery use, and better security (no virus software, sandboxing approach to protect end users). But are these benefits justified for the high cost ? I would rather add some money buy an ipad2 (US$629) or Android 3.0 tablet which offer me more functionalities, applications and computing powers.
2011/06/15
Windows 7 handling RA and RDNSS
Actually, I had some experience on a different scenario. During APRICOT-APAN 2011, I used a IPv6 only network and the v6 address assigned to my Window 7 machine was quite like auto-configuration but there was the assignment of v6 DNS resolvers. I was mindful that Windows 7 could not support RA with RDNSS and the question was where come the assignment of v6 DNS resolvers. The answer was that the network was using a DHCPv6 to assign DNS resolvers while there was a RADVD to accomplish the task of auto-config IPv6 address for clients. Up to this point, I should fire a bullet at Microsoft for not releasing patches to make RA working with RDNSS. This would save the unnecessary provision of a DHCPv6 server.
Luckily, I still keep a picture of the configuration for reference which is posted below.
2011/06/14
RFC 6106 - IPv6 Router Advertisement Options for DNS Configuration
In Linux, RADVD can have fully function of SLACC plus RDNSS. Just look at the following few lines in the config file :
interface name {
list of interface specific options
list of prefix definitions
list of clients (IPv6 addresses) to advertise to
list of route definitions
list of RDNSS definitions
};
RDNSS ip [ip] [ip] {
list of rdnss specific options
};
Just wonder if I have the time to configue one set of RADVD with RDNSS and then test the allocation of prefix and DNS resolvers to Windows 7 machines.
2011/06/13
Kidney for an ipad2
In China, a 17-year student sold his kidney for an ipad2. The news and interview can be found in the URL
http://www.wupia.com/2011/06/a-high-school-student-in-china-sold-his-kidney-for-an-ipad-2/
Apple will definitely release ipad 3, ipad 4, ipad 5 and so on. I am afraid that after two more rounds, the 17-year student has no more internal organs to sell.
My dear Almighty God, please tell me the meaning and value of life. Can human beings trade their internal organs with electronic devices ?
2011/06/12
Which iOS supports IPv6
Can readers please correct me if I am wrong. Thank you.
2011/06/11
World IPv6 Day is over, what’s next ?
2011/06/10
LISP Reliability Issue
http://warrenkwok.blogspot.com/2011/05/facebook-adopts-lisp-to-roll-out-ipv6.html
There is a degradation in reliability as compared to a single router. Assuming each of the three routers has a reliability of 99.9 %, if cascaded together, the overall reliability of the routing system drops to 99.7 %. The down time will be increased from 8.76 hours to 26.28 hours in a year.
Can Facebook and other early LISP adopters accept the degradation ?
2011/06/09
No IE9 for Windows XP
Isn't it fair ? Microsoft does not offer IE 9 for XP. I have tried IE9 on Windows 7. It is fast and has a good performance in loading grpahics and gives a very streamlined operation in tabbed browsing.
Frankly, we do not have many choice. IE 8 is buggy. Firefox now only gets bigger but also gets slower. Chrome has a cache problem especially when I post comments on other people's status on facebook. I urge Microsoft to re-consider developing an IE 9 version for current XP users.
2011/06/08
Absolutey amazing. All big content providers and organisations are on IPv6 today.
[warren@dnssec ~]# dig aaaa www.facebook.com +short
2620:0:1c18:0:face:b00c:0:3
[warren@dnssec ~]# dig aaaa www.google.com +short
http://www.l.google.com/.
2404:6800:8002::69
[warren@dnssec ~]# dig aaaa www.yahoo.com +short
fpfd.wa1.b.yahoo.com.
2001:4998:f011:1fe::3000
2001:4998:f011:1fe::3001
[warren@dnssec ~]# dig aaaa www.bing.com +short
ipv6.search.ms.com.edgesuite.net.
a1877.dscb.akamai.net.
2600:140e:3::3cfe:af33
2600:140e:3::3cfe:af38
[warren@dnssec ~]# dig aaaa www.xbox.com +short
http://www.gtm.xbox.com/.
msxbwsd.vo.llnwd.net.
2402:6800:720:11:230:48ff:fe8d:aa6e
2402:6800:720:11:230:48ff:fe8d:a992
[warren@dnssec ~]# dig aaaa www.cisco.com +short
v6day.cisco.com.akadns.net.
geo-v6day.cisco.com.akadns.net.
cisco-redir.v6day.akadns.net.
cisco.v6day.akadns.net.
2001:420:80:1:c:15c0:d06:f00d
[warren@dnssec ~]# dig aaaa www.youtube.com +short
youtube-ui.l.google.com.
2404:6800:8002::5b
2011/06/06
web-based v6 email autoreply tool
2011/06/05
Failed the test as a Hong Kong IPv6 website
The reason was that the ping rtt time was about 290 msec from a Hong Kong v6 node and the acceptance criterion is to have rtt < 10 msec. The site rides on a overseas proxy somewhere in Netherlands.
I have no bad feeling at all. The accepting criterion is fair and reasonable.
2011/06/04
Enable v6 access by web proxy approach
http://ipv6proxy.prolocation.net/
This is a web proxy approach. A website only has to enable AAAA record pointing to the v6 leg of the proxy server which is 2a00:d00:ff:131:94:228:131:131. When the proxy receives the http headers, it knows the domains name and can get the web content from v4 network and pass to the v6 visiting clients.
However, there are some limitations. No doubt end-to-end connectivity is broken so I can readily imagine that HTTPS and VPN can not be supported.
2011/06/03
CUHK opens its v6 Stratum 2 NTP Server for public
The Hong Kong Observatory will provide its v6 NTP Server by the end of 2011. For the time being, I still have to use the one offered by CUHK.
[warren@dnssec ~]# /usr/sbin/ntpdate -6 ntp.cuhk.edu.hk
3 Jun 21:09:58 ntpdate[31742]: adjust time server 2405:3000:3:b0:137:189:11:149 offset 0.008007 sec
[warren@dnssec ~]# /usr/sbin/ntpdate -6 ntp.cuhk.edu.hk
3 Jun 21:09:59 ntpdate[31743]: adjust time server 2405:3000:3:b0:137:189:11:149 offset 0.007619 sec
[warren@dnssec ~]# /usr/sbin/ntpdate -6 ntp.cuhk.edu.hk
3 Jun 21:09:59 ntpdate[31744]: adjust time server 2405:3000:3:b0:137:189:11:149 offset 0.007238 sec
[warren@dnssec ~]# /usr/sbin/ntpdate -6 ntp.cuhk.edu.hk
3 Jun 21:10:00 ntpdate[31745]: adjust time server 2405:3000:3:b0:137:189:11:149 offset 0.006820 sec
[warren@dnssec ~]# /usr/sbin/ntpdate -6 ntp.cuhk.edu.hk
3 Jun 21:10:02 ntpdate[31751]: adjust time server 2405:3000:3:b0:137:189:11:149 offset 0.005666 sec
[warren@dnssec ~]#
2011/06/02
What benefits of IPv6 apart from large address space and elimination of NAT
The protocol IPv6 is a boring thing. Frankly, I have no confidence to turn it into something interesting !
2011/06/01
SOA minimum to deal with the large number of queries for AAAA record for a website which only runs on IPv4
It is important to set the SOA minimum to a higher value like 1 hour (3600 sec) for protecting the authoritative name servers from overloading. As more and more users change to use Windows 7, the DNS traffic for asking non-existing AAAA record will boost. All DNS administrators have a role to play for the smooth and steady operations of the Internet.