On 9/19/15 9:46 AM, Nate Burke wrote:
I'm dual stacked at home, but it seems like I run into this issue about
once a week. Content hosts need to do the same monitoring of their IPv6
services as their IPv4 Services. Many times the IPv6 site will break
while the IPV4 site is fine. Like right now, www.icontact.com is
working from a V4 only box, but not a V4/v6 box, some sort of security
certificate problem. To a customer In a Dual stack environment, that =
'Your service isn't letting me view that site' (or as the wife yells
down the stairs, The internet is down because this 1 site won't load) I
can see this only multiplying headaches as dual stack is rolled out
across the network. People who are already doing widespread Dual Stack,
do you run into these issues? If so, how do you solve them. Disable V6
on a problem box? That kinda defeats the point then doesn't it.
I'm not at the office right now (dual stack since 2008) to check that
site with a GUI browser but with lynx I get:
SSL error:host(www.icontact.com)!=cert(CN<incapsula.com>)-Continue?
And that looks like their CDN provider is having an IPv6 malfunction
serving up the right cert. I might try reporting the IPv6 problem since
the mere mention of IPv6 makes it more likely than not to get bumped to
someone with more clue than the front line script monkeys.
But yeah from a "happy eyeballs" perspective disabling IPv6 "fixes" the
problem. Unfortunately not everyone has their shit together.
I've been running dual stack for a long time but I don't recall any
widespread issues, just stupid brokenness here and there but those have
been an exception. The biggest problems I ever had was Global Crossing
randomly null routing IPv6 prefixes with their buggy 6PE. With content
sites I've seen the opposite; like in the past when Facebook had outages
it only impacted their IPv4 site while accessing it via IPv6 kept working.
~Seth