<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Ipv6 on Damien Dye&#39;s Blog</title>
    <link>https://blogs.damiendye.uk/en/tags/ipv6/</link>
    <description>Recent content in Ipv6 on Damien Dye&#39;s Blog</description>
    <generator>Hugo</generator>
    <language>en-GB</language>
    <lastBuildDate>Mon, 14 Sep 2026 15:00:00 +0100</lastBuildDate>
    <atom:link href="https://blogs.damiendye.uk/en/tags/ipv6/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>A VPN Out of Parts: PPP, Tap Devices and Netcat</title>
      <link>https://blogs.damiendye.uk/en/networking/a-vpn-out-of-parts-and-what-egress-really-is/</link>
      <pubDate>Mon, 14 Sep 2026 15:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/networking/a-vpn-out-of-parts-and-what-egress-really-is/</guid>
      <description>A VPN is a virtual link plus a carrier, and Linux ships a program for each: pppd or a tap device, and netcat. Building it both ways — over TCP, UDP, TLS and DTLS, with zstd compression — shows what a VPN is made of, and what egress really is: once an attacker has root and outbound is open, the tunnel is already installed.</description>
    </item>
    <item>
      <title>Your Firewall Takes Instructions From Strangers. Turn Off the Protocol Helpers.</title>
      <link>https://blogs.damiendye.uk/en/networking/protocol-helpers-turn-them-off/</link>
      <pubDate>Mon, 14 Sep 2026 09:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/networking/protocol-helpers-turn-them-off/</guid>
      <description>A NAT helper reads the inside of your packets and opens inbound ports on what it finds there. Anyone can write that text — a web page has been enough since 2010. How helpers work, how crafted packets turn them into a port-opening service for strangers, what IPsec pass-through does, why they fail Cyber Essentials, and how to switch the lot off.</description>
    </item>
    <item>
      <title>IPsec Was a Good Idea. It Is Time to Turn It Off.</title>
      <link>https://blogs.damiendye.uk/en/networking/ipsec-was-a-good-idea-turn-it-off/</link>
      <pubDate>Sun, 13 Sep 2026 09:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/networking/ipsec-was-a-good-idea-turn-it-off/</guid>
      <description>IPsec bound security to the IP address, then the industry took the address away. NAT, double NAT under CGNAT, NAT64 that will not carry it at all, no ports so no load balancing, the MTU tax, L2TP, PPTP and Windows interop — with diagrams, Cisco and Juniper documentation, a full diagnostic method, and the case for retiring it.</description>
    </item>
    <item>
      <title>Ping: The Diagnostic Tool That Opens a Whole Lot More</title>
      <link>https://blogs.damiendye.uk/en/networking/ping-the-diagnostic-tool-that-opens-a-whole-lot-more/</link>
      <pubDate>Tue, 01 Sep 2026 08:05:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/networking/ping-the-diagnostic-tool-that-opens-a-whole-lot-more/</guid>
      <description>Why ping — ICMP echo, not the rest of the protocol — is a liability: a channel every host must answer, so a network that &amp;#39;only allows ping&amp;#39; has a full VPN out. The threat, who can open one, three tunnels (Hans, icmptunnel, a Python one with AES-128), and the rule that shuts it: nftables, pf, Cisco, Junos, MikroTik and Windows.</description>
    </item>
    <item>
      <title>Is Your MSP Lying To You To Sell You Premium Products?</title>
      <link>https://blogs.damiendye.uk/en/random/is-your-msp-lying-to-you-part1/</link>
      <pubDate>Fri, 28 Aug 2026 18:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/random/is-your-msp-lying-to-you-part1/</guid>
      <description>Part 1 of 3. Some MSPs lie; most never have to, because the vendors whose products they recommend pay them and nobody must tell you. The tells that you are being sold to rather than engineered for: the free fix refused, requirements never written down, one option on the shortlist, no open source line, and the addresses you rent forever.</description>
    </item>
    <item>
      <title>The Firewall Is Eleven Hops Away</title>
      <link>https://blogs.damiendye.uk/en/networking/how-far-away-is-the-firewall/</link>
      <pubDate>Fri, 28 Aug 2026 09:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/networking/how-far-away-is-the-firewall/</guid>
      <description>A connection that times out tells you nothing about where it died. TTL does. Here is how to count the hops to whatever is eating your port, on Linux, macOS, the BSDs, Solaris and Redox, with a script that needs no root on Linux.</description>
    </item>
    <item>
      <title>We Never Ran Out of Addresses. We Ran Out of Effort.</title>
      <link>https://blogs.damiendye.uk/en/networking/we-never-ran-out-of-addresses/</link>
      <pubDate>Thu, 27 Aug 2026 18:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/networking/we-never-ran-out-of-addresses/</guid>
      <description>The UK has spent twenty years bolting workarounds onto IPv4 rather than turning on IPv6. I counted every UK network in the routing table to see who has actually done it, and the answer says this was never about money.</description>
    </item>
  </channel>
</rss>
