4 ms·
Hole punching is nothing spectacular, let me explain simply: You're on your computer connected to a regular home router. You hit google.com in your browser. Wh
by dimman 11y ago
Hole punching is nothing spectacular, let me explain simply:
You're on your computer connected to a regular home router. You hit google.com in your browser. What happens is that you create an outgoing request towards google.com port 443 (TLS/HTTPS). The router opens up a temporary firewall rule allowing responses from google.com port 443. (Without it you wouldn't get any response)
Holepunching is simply using that fact, your device A and B shares their external IP:port with eachother (outside of STUN/TURN scope) and then does a simple connect() to eachothers external ip:port. When A does connect(B_IP:B_port) it opens up for B to respond to that channel, and since B is doing connect(A_IP:A_PORT) his request will be let through and they can connect to eachother. A direct connection, a P2P (peer to peer) connection between those two clients, no one else.
Imagine it as a temporary port forwarding that's most importantly limited to one specific IP and PORT that can use it: the other device.
(There's some technical limitations to this like the type of NAT/firewall you have, but for the simple home router the above usually works.)
- rufugee 11y agoI'm still not sure I follow you regarding how the above applies to my situation. I believe in your case, you mean to say that A is a local machine and B is a remote machine, and if they're complicit together, allowing A to connect outbound to B then allows B to communicate back to A, which could allow the two of them to do things you really don't want. However, if I have the cameras on a completely separate subnet and network interface on the firewall and block communication from this subnet to my regular lan and to the outside world, I should be immune to this, correct? A is in my DMZ, and can't communicate with the outside world based on my firewall rules, so A would never reach B.
- dimman 11y agoIf the device can't communicate outbound then no you're completely safe. There's no magic into this, hole punching is just a silly name for a simple technique. Hole punching works when both A and B are behind NAT. It also allows B to contact A if A is behind a NAT (no matter if B is behind one or not). If both A and B have public IP's then the hole punching is "already done", they can already connect to eachother.