RE: https://mastodon.social/@geerlingguy/116712018499922166
I cannot relate. IPv6 has been on in my home network since ≈2010 and I can’t even remember the last time I encountered an IPv6-related bug.
But I guess statements like this is what Jeff means when he says “*Cosplaying* as a sysadmin”?
Because if you throw your hands in the air over IPv6 (in 2026!), you’re definitely not a sysadmin I would want to work with.
@zekjur I stopped relating to Jeff Geerling when I read his blog articles about how proud he was to assault people seeking help at planned parenthood.
I think the articles (early 2010s iirc) are still on his blog.
@morre @zekjur I researched this and I could not find a blog post mentioning assault, but I found this blog post from 2012 that he himself replied to in 2025 and did not have any critique on:
https://www.jeffgeerling.com/blog/2012/changes-nothing-contraception/
oh boy!
@zekjur Same, my home has been fully dual-stack since 2002 (!) and the only oddities I’ve ever seen are from Thread devices trying to reclaim the default IPv6 route. That’s easily fixable by blocking their RAs.
@morre @zekjur Thank you for pointing that one out. His posts are... vomit inducing. Not assault in this case but the blatant misogyny. I always am skeptical with people who start their characterization with "Father" because it mostly boils down to them being overly proud of having forced their sperm into some poor woman's womb, nothing else.
https://www.jeffgeerling.com/blog/2012/hhs-mandate-why-birth-control/
@ljrk @morre @zekjur same thing. Whenever I see "father" in a bio, it's an orange flag, and it turns out red most of the time once I dig too much.
Being a father myself, I know it's an *achievement* to actually raise kids, it's one of the hardest job I did. But it seems everytime for people to put the father in the bio, it's just they feconded some poor lady who has to handle all the hardship of being parent. Those first ones clearly are cosplaying being parents more than anything.
Thanks for the link. What an utter trash of a human.
@dolanor @morre @zekjur You nailed it. Raising children is an incredible endeavor and I respect those who "successfully" (for whatever that means) do that. And being a true father should entail that. Those who feel the need to put that first in their bio often coincide with those who do not fully understand the amount of responsibility fatherhood entails.
@zekjur It took a little learning about "what the fuck do I need to do so my ISP won't break stuff by >>helpfully<< doing weird stuff" but now it seems to work just fine.
On the other hand, I don't do much monitoring in my private network so shit might be horribly broken, I just don't know yet, lol
@Laird_Dave @zekjur Disabled IPv6 in my home network as well a while ago. Subnet delegation constantly broke thanks to the dial-up connection with changing IPv6 subnets, making the services hosted at home unavailable which preferred the (sometimes broken) IPv6 addresses over the (always working) NATed IPv4 addresses.
Also, Podman Rootless setups do have major issues with IPv6 when routing public IP addresses.
@zekjur Same. Even my bog-standard home/SOHO router from *that* German manufacturer has been v6-ing perfectly fine for many years.
My issues are pretty much the opposite. ISP uses v4 CGNAT, so VPN-to-home from v4-only networks does not work.
The rest is merely cosmetical, like for some reason, tvOS in 2026 still does not display the v6 address in the GUI.
@weizenspreu @zekjur yeah I just bought a static /56 from my ISP to avoid this kind of fuckery. And yes, it's annoying.
@zekjur for me it's the other way around. The CGN of my providers v4 is broken from time to time. So v6 does actually work better.
The times when v6 stopped working luckily are gone since 10 years, because back then ppls facebook&other v6 services were impacted and this most likely pressured ISPs to fix their shit.


@zekjur That's a bit harsh.
While I'm not encountering many IPv6 *bugs*, there are so many performance issues (i.e. terrible routing) I'm seeing with my ISP that I keep it disabled at home unless I'm specifically messing around with IPv6. Most relatably, cache.nixos.org is slow as shit over IPv6.
IPv4 (stays in Warsaw):
1. 10.95.0.1
2. war-bng1.neo.tpnet.pl
3. war-r21.tpnet.pl
4. win-b2-link.ip.twelve99.net
5. fastly-ic-364029.ip.twelve99-cust.net
6. 151.101.65.91
IPv6 (goes to Hamburg, I think? and there's a bottleneck somewhere in here):
3. 2a01:1000:0:576::1
4. 2a01:1000::48
5. hbg-b2-link.ip.twelve99.net
6. hbg-bb3-link.ip.twelve99.net
7. (waiting for reply)
8. fastly-ic-397856.ip.twelve99-cust.net
9. 2a04:4e42:200::347
@radex @zekjur you are directly going into 1299 and then fastly for that route. Unless there is a reverse route for the packets not visible that should be a good path as both are solid providers.
https://www.fastly-debug.com can help a wee bit with some details.
If that path is slow you'll have lots of issues, could be a link full to 1299 of course and many other issues, reach out to fastly and they will try to resolve.
@zekjur I agree, but could have done without the slight ad-hominem. But yes takes like this are frustrating, especially from a high profile person who built a reputation of digging into things. Hell, he probably could milk a blog post or video out of the badly behaved IPv6 devices.
@zekjur I have never encountered an IPv6 bug, I turned it on and the only difference was that I can now reach IPv6 services.
How does one induce IPv6 bugs, or what am I missing?
@zekjur 💯 I'm much sooner going to throw out some poor quality device with buggy firmware than I'm going to disable IPv6
@zekjur I totally agree there are many weird behaviors with IPv6 but most of them aren’t because of IPv6 but because of missing or unclear documentation (in my experience). But if the result is just to go 🤷 then we’ll never have really good and easy IPv6 support everywhere. My IPv6 setup at home has been very solid for many years now even with my weird special cases. Still considering going v6-only in the near future
@weizenspreu https://www.easybell.de/komplettanschluss/
Scroll down and you'll see a static /56 prefix offered for ~ 4€ per month
@zekjur It's frustrating. NAT, a workaround for IPv4's limitations, is now treated as a security feature. I've worked on networks at several major tech companies, and they all have IPv6 disabled internally. I had a job testing network devices, and only one test out of a suite of hundreds used IPv6 instead of IPv4.
I get the impression there's a mindset that IPv6 is treated like the metric system in the US: sure, you were taught it in school, but you shouldn't actually try to use it.
@zekjur They'd have problems in data centers with using up the RFC 1918 address space internally.
Gee, if only there were a way to assign IP addresses automatically from a practically unlimited address space.
@zekjur make that 1998.... and exactly what you say: if one disables IPv6 in 2026 one is just looking for clicks and demonstrating incompetence.
If one has problematic devices call them out, put them on a separate VLAN if needed, but with dual stack there really should not be any issues, we cut through the big ones a decade ago.
@zekjur i have a command in my shell to disable ipv6 temporary on my system, because my isp sometimes just drops ipv6 and i usually notice it when doing some dev work, eg pulling a git repo
living in germany btw
@zekjur For me having IPv6 enabled works fine all the time. The problems only start when you want to turn off IPv4…
@zekjur I've taken the same approach. There are tons of tools that don't handle IPv6 well. I have no need for it in my homelab, so its disabled everywhere. Less attack surface.
@weizenspreu @Laird_Dave @zekjur why not enable and use unique local addresses (ULA)? there is no dependance on global unique addresses (GUA) subnets whatsoever, it's essentially the same as an IPv4 subnet behind NAT
@witcher @weizenspreu @zekjur because I didn't want NAT stuff again
@Laird_Dave sorry if it's unclear, i was more replying to @weizenspreu because they were complaining about dynamic GUAs which broke stuff for them
@zekjur
@witcher @Laird_Dave @zekjur In what way do ULAs help me publicly host stuff via IPv6? I'm really interested in that logic.
@weizenspreu @Laird_Dave @zekjur I'm not sure about if you mean hosting locally for yourself, in which case ULAs are fine, or publicly. The latter ofc requires either a static IPv6 prefix or NAT, as does IPv4.
I'm just not sure how disabling IPv6 makes the problem go away, because we're right back at NAT anyway.
@witcher @Laird_Dave NATing with IPv4 is well-established and battle-tested. It works for dynamic IP addresses quite well. NATing with IPv6 is still in its infancy, though. Oftentimes, you need to manually define the public IPv6 subnet that should be delegated and/or NATed. This breaks as soon as you're assigned a new /64 by your ISP. That's what I had set up and it broke repeatedly. So I simply disabled it. Problem solved.
@weizenspreu @Laird_Dave Sure, but I was talking about NAT66 with a single public host, not an exposed subnet if that's what you mean? It's not a very well tested setup, though, as it misses the point of IPv6 anyway, so fair enough.
Sounds like you would benefit from a static IPv6 subnet, though, if you're still at all interested. I heard from friends you can get one for free at Vodafone if you ask nicely enough, but I rent one at easybell.
@witcher @weizenspreu @Laird_Dave @zekjur Or set a static interface token on your servers. Then you'll get a static globally routable IPv6 address (assuming your prefix is fixed) with no NAT or VPN required.
@mathew @witcher @Laird_Dave @zekjur Orrr… you don’t because German ISPs change assigned addresses from time to time as well as on reconnects.
@weizenspreu @witcher @Laird_Dave @zekjur So they give you a static IPv4 but not a static IPv6 prefix? That’s downright perverse.
@mathew @witcher @Laird_Dave @zekjur They don’t, but NAT for IPv4 is well-supported while NAT for IPv6 is not.