Skip to content

IPsec Was a Good Idea. It Is Time to Turn It Off.

IPsec was right in 1995: encrypt below the application, bind the security association to the IP address, let every protocol inherit it. Then NAT arrived, carrier-grade NAT finished the job, and the fix was to wrap the whole thing in UDP and keep a timer running so a translation table would not forget you. This post shows how it falls down, diagram by diagram β€” the security association that cannot survive a rewritten header, the two translators every CGNAT line now has, the NAT64 standard that names IPsec as out of scope, the tunnel that cannot use a second link because ESP has no ports, the MTU nobody owns, and L2TP and PPTP as the two protocols that were never fit to be here. It carries the vendor documentation from Cisco, Juniper and Microsoft that admits every one of those, the eighteen pieces that call themselves an IPsec VPN including the two that were never standards at all, why the Fisher-Price OS has never truly interoperated with an open stack, a working method for diagnosing IPsec while you still run it, and the case for retiring the lot with dates.

13th September 2026 Β· 68 min Β· 16979 words Β· Damien Dye

We Never Ran Out of Addresses. We Ran Out of Effort.

IPv6 has been finished, free and switched on by default in every operating system for the best part of twenty years. The UK’s answer was carrier-grade NAT, a law about logging, and a Β£5 a month charge to give you back the address you used to have. I counted every UK network in the global routing table to find out who has actually turned IPv6 on β€” 1,200 of them have not, and 463 of those are sitting on address space they asked for and never used.

27th August 2026 Β· 69 min Β· 14518 words Β· Damien Dye