Status of IPv6 support in OpenStreetMap

Some important OpenStreetMap servers do not run over IPv6, and are not reachable directly by IPv6-only clients (which must then use third-party proxies or establish IPv6-to-IPv4 tunnels, whose web sessions are frequently very limited in terms of privacy, response time, duration, volume, bandwidth, reliability and quality of service). This is now becoming a problem for many users, notably those connected on mobile networks.

There is an openstreetmap tile server for the Netherlands running over IPv6, and another one in France with worldwide coverage (including for HOT projects).

Accessibility of important OpenStreetMap servers over IPv6:

This information can be tested on http://ipv6-test.com/validate.php.

Some websites are not accessible over IPv6 from all locations. Notably, www.openstreetmap.org is not reachable from Hurricane Electric IPv6 network (as can be checked using their looking glass).

Implementation scenario

SixXS is no longer in service. In 2009, it was tested that an AYIYA tunnel from SixXS worked from UCL; this basically says that we were able to make a tunnel from UCL to a nearby tic server in London. The setup time for that was the time to apply at SixXS and the time to request a tunnel. From that point on a subnet can be requested that is (on layer 2) distributing IPv6 using radvd automatically. No setup required, only a IPv6 module loaded in the respectable kernel.

Most likely because we have static ip adresses, we don't want to tunnel over AYIYA out, but directly get a static IPv4 link, without heartbeat. We did not test that yet, but if tested and it works within UCL it would be the best method.

Security

Obviously IPv6 makes machines directly accessible like global IPs do. By putting a firewall on top of the router that is distributing the IPv6 adresses, we basically protect us against people trying to reach the machines by v6. Setting up again a port based match is transparent to IPv4 and IPv6; so theoretically if every system has a firewall now, it would already be protected.