DS-Lite: Running IPv4 over an IPv6-Only Access Network - 夜莺博客

DS-Lite: Running IPv4 over an IPv6-Only Access Network

DS-Lite exists to answer a specific problem: an operator wants to move the access network to IPv6-only, but subscribers still need IPv4. The solution is to tunnel IPv4 inside IPv6 across the access network and perform carrier-grade NAT at the far end. It keeps the access network free of dual-stack complexity, multiplexes many subscribers onto one public IPv4 address, and lets IPv6 continue natively alongside. The architecture is two named roles — B4 at the subscriber and AFTR at the operator edge — and once you know what each side has to be told, the configuration is small.

The Architecture

  • B4 (Basic Bridging BroadBand) — a function on the customer gateway. It creates an IPv4-in-IPv6 softwire to the AFTR and forwards the subscriber's IPv4 traffic into it. It may also perform NAT44 itself in the Lightweight 4over6 variant.
  • AFTR (Address Family Transition Router) — the combination of the IPv4-in-IPv6 tunnel endpoint and an IPv4–IPv4 NAT on the same node, deployed at the IPv4/IPv6 border.
  • Softwire — the IPv4-in-IPv6 tunnel, standardised in RFC 2473 form.

The B4 needs exactly one DS-Lite-specific parameter: the IPv6 address of the AFTR. Its own IPv4 address is taken from the well-known range 192.0.0.0/29, which IANA allocated for exactly this purpose.

AFTR Configuration on Junos (MX with MS-MPC/MS-MIC)

# Interfaces: one facing the B4 (IPv6), one facing the internet (IPv4)
set interfaces ge-3/1/5 unit 0 family inet6 address 5001::1/64
set interfaces ge-3/1/0 unit 0 family inet address 203.0.113.1/30

# Service interface hosting the DS-Lite AFTR
set interfaces sp-0/0/0 unit 0 family inet
set interfaces sp-0/0/0 unit 0 family inet6
set interfaces sp-0/0/0 unit 0 service-domain inside
set interfaces sp-0/0/0 unit 1 family inet
set interfaces sp-0/0/0 unit 1 service-domain outside

# Softwire concentrator
set services softwire softwire-concentrator ds-lite ds-lite-1
set services softwire softwire-concentrator ds-lite ds-lite-1 softwire-address 5001::1
set services softwire softwire-concentrator ds-lite ds-lite-1 ipv4-address 192.0.0.2

# Route toward the B4's tunnel source
set routing-options static route 5002::1/128 next-hop 5001::2

# Service set: softwire + NAT44
set services service-set ds-lite-ss softwire-rules ds-lite-1
set services service-set ds-lite-ss nat-rules nat-44
set services service-set ds-lite-ss next-hop-service inside-service-interface sp-0/0/0.0
set services service-set ds-lite-ss next-hop-service outside-service-interface sp-0/0/0.1

Note the fixed IPv4 address 192.0.0.2 for the concentrator: RFC 6333 reserves 192.0.0.0/29 so operators can assign the same address to all AFTRs, which makes connectivity testing predictable from any B4.

B4 Side

# Customer gateway creates the softwire to the AFTR
set interfaces ip-0/0/0 tunnel source 5002::1
set interfaces ip-0/0/0 tunnel destination 5001::1
set interfaces ip-0/0/0 family inet mtu 1460
set routing-options static route 0.0.0.0/0 next-hop ip-0/0/0.0

The B4's tunnel source is typically a loopback address (5002::1/128 in the example) so the softwire survives a physical link change. How the B4 learns the AFTR address varies: manual configuration, DHCPv6 option (RFC 6334), or RADIUS (RFC 6519). Pick one and provision it consistently — a subscriber whose gateway was configured by a different mechanism than its peers is a support call waiting to happen.

MTU: The Detail That Breaks Real Deployments

Encapsulating IPv4 in IPv6 adds a 40-byte IPv6 header. If the access network MTU is fixed, the AFTR and B4 must support fragmentation and reassembly per RFC 6333 — and reassembly at the tunnel exit point is resource-intensive precisely because many B4s terminate on one AFTR. The preferred approach is to account for the overhead up front:

# Access network MTU 1500 -> subscriber payload MTU 1460
set interfaces ip-0/0/0 family inet mtu 1460
# Reduce TCP MSS on the AFTR to avoid fragmented TCP forever
set services service-set ds-lite-ss tcp-mss 1400

Setting TCP MSS is the single most effective mitigation: it stops hosts from negotiating a segment size that will always need fragmentation, and it removes most of the reassembly load.

Scaling the AFTR

The AFTR holds per-subscriber or per-flow state depending on the variant. In classic DS-Lite the binding table is a 5-tuple NAPT table (RFC 6333); in Lightweight 4over6 it is a per-subscriber 3-tuple of IPv6 address, public IPv4 address and restricted port set (RFC 7596), and the lwAFTR performs no NAPT at all. The lightweight variant scales further and makes ingress filtering simple, because the port set allocated to each subscriber is known and can be enforced exactly.

Practical AFTR hardening:

  • Restrict which source IPv6 prefixes the AFTR will accept softwires from — the access network should only originate from known prefixes.
  • Apply an ingress policy that drops encapsulated packets from unknown B4s, and log the rejects.
  • Offer a distinct IPv4 address for connectivity testing (the 192.0.0.0/29 convention) so NOC staff can ping and traceroute the AFTR without leaving the softwire.
  • Do not attempt to manage B4s over the softwire; reach them natively over IPv6 (for example via TR-069).

Testing

show services softwire statistics
show services service-sets statistics
ping 192.0.0.2 count 5                       # the standard AFTR test address
traceroute 8.8.8.8                           # should show the softwire hop, not drop
show services nat pool

Test from a subscriber line: an IPv4 ping to the AFTR's well-known address, a traceroute to a public destination, and an IPv6 ping to the AFTR do three different things and together isolate whether the failure is the access network, the softwire or the NAT.

DS-Lite or Something Else?

If subscribers can run pure IPv6 and only need to reach IPv4 servers, NAT64/DNS64 is simpler — no tunnel, no B4 software. If you need to preserve per-subscriber IPv4 addresses with no NAT state in the core, Lightweight 4over6 is the natural evolution of DS-Lite. If the access network is IPv4-only but you want to move to IPv6, DS-Lite is the wrong tool — that is what dual-stack is for.

Related Reading

Deeper dives on the same topics from our archive:

原文链接:https://www.juniper.net/documentation/us/en/software/nce/nce-ds-lite-ipv6-access/topics/example/nat-ds-lite-basic.html