!tCyGickeVqkHsYjWnh:nixos.org

NixOS Networking

914 Members
Declaratively manage your switching, routing, wireless, tunneling and more.265 Servers

Load older messages


SenderMessageTime
24 Jun 2025
@emilazy:matrix.orgemilyI've only seen the setup where you run a loopback resolver and downstream applications trust the bit13:10:26
@hexa:lossy.networkhexaresolvers can use local and recursive options opportunistically13:10:57
@emilazy:matrix.orgemilywell I am assuming you have an outside resolver you can access over v6 here rather than doing full local recursive resolution yeah13:11:12
@emilazy:matrix.orgemily(but still doing the DNSSEC validation queries)13:11:27
@hexa:lossy.networkhexaI would really just stop doing DNS64 altogether13:11:59
@emilazy:matrix.orgemilyas in the setup "local resolver that validates DNSSEC and rewrites to DNS64 →v6 DoH3→ recursive resolver"13:12:06
@emilazy:matrix.orgemilysure. but then you have to "start" doing kernel v4 stack13:12:22
@hexa:lossy.networkhexaand I would also not switch off ipv4 from one day to anotherr13:12:27
@emilazy:matrix.orgemilywhich does negate some of the security/complexity advantages of v613:12:34
@emilazy:matrix.orgemilyeven if the packets never leave the machine13:12:47
@emilazy:matrix.orgemily anyway for desktop machines I would just do CLAT because ping 8.8.8.8 not working is too annoying and random software has dumb expectations 13:13:28
@emilazy:matrix.orgemilybut for servers I think local DNS64 can make sense13:13:42
@emilazy:matrix.orgemilysince you can eliminate the v4 stack entirely13:13:53
@hexa:lossy.networkhexa I would start by trying v6-only-preferred and pref64 13:13:55
@hexa:lossy.networkhexaand figure out what breaks13:14:03
@emilazy:matrix.orgemilywhich is after all the goal13:14:03
@hexa:lossy.networkhexa because sure enough a linux today will respect v6-only-preferred, not acquire an ipv4 address and not set up a translator 13:14:28
@emilazy:matrix.orgemilypretty sure I don't have any clients that require actual dual stack thankfully13:14:31
@emilazy:matrix.orgemily(but I am sure that will tragically change at some point)13:14:42
@hexa:lossy.networkhexahttps://git.darmstadt.ccc.de/mrmcd/infra/nixos-config/-/commit/376c9759a87362077ad6534c4823821150e3d06d13:14:56
@emilazy:matrix.orgemilyso I think I can skip v6-mostly for now13:15:01
@hexa:lossy.networkhexawe did that for an event and it broke SIP 😄 13:15:05
@emilazy:matrix.orgemilyI think networkd fixed that bug thankfully fwiw13:15:18
@hexa:lossy.networkhexayeah, but networkmanager?13:15:27
@hexa:lossy.networkhexadhcpcd?13:15:29
@hexa:lossy.networkhexanot too sure13:15:34
@emilazy:matrix.orgemilyactually I'm getting deja vu so maybe we talked about this before :)13:15:35
@emilazy:matrix.orgemilydoes NM do it too? silly13:15:43
@hexa:lossy.networkhexaprobably some version did 🙂 13:15:54
@emilazy:matrix.orgemilyit's a total misreading of the RFC to respect that flag without setting up CLAT13:15:55

Show newer messages


Back to Room ListRoom Version: 6