3 ms·
As a sysadmin, if I had limitless IPv4 addresses, I'd still use NAT on servers and clients because it's a useful security layer. There's little reason that ind
by fps 10y ago
As a sysadmin, if I had limitless IPv4 addresses, I'd still use NAT on servers and clients because it's a useful security layer. There's little reason that individual devices need globally routable IP addresses.
- proactivesvcs 10y agoBut with an extra layer to configure and for a vendor to properly implement, surely that also means it's an extra security liability?
- pdkl95 10y ago> it's a useful security layer No, it's not. As a sysadmin, you should know the difference between NAT and a stateful firewall, and that NAT alone doesn't prevent packets from being routed to local addresses. > There's little reason that individual devices need globally routable IP addresses. NAT has been more damaging to the development of network software than any other factor. NAT breaks the development of true network software, such that entire categories of software haven't even been considered. NAT forces extremely complicated hacks[1] and centralized management of true peer to peer connections. The benefit of the internet has been that any peer has the capability to publish. NAT breaks that benefit, turning the internet back into cable TV, where most people need an imprimatur[2] to publish. [1] http://www.brynosaurus.com/pub/net/p2pnat/ http://www.brynosaurus.com/pub/net/p2pnat/ [2] https://www.fourmilab.ch/documents/digital-imprimatur/ https://www.fourmilab.ch/documents/digital-imprimatur/
- CountSessine 10y agoThis needs to be repeated everywhere. There are too many system admins with dangerously bad ideas about IPv6 and NAT. NAT needs to die in a fire and if you're rolling out NAT for IPv6 you're wasting your time and your company's money for a bag of nothing.