4 ms·
Sometime, I felt force all IOTs devices, typical laptops, Phones, behind NAT is actually safer for internet as whole. Security via network segmentation. IM
by srcmap 9y ago
Sometime, I felt force all IOTs devices, typical laptops, Phones, behind NAT is actually safer for internet as whole.
Security via network segmentation. IMO, NAT gateway is good place to lock down and put in network security appliance to track/block all the unwanted connections.
- kazen44 9y agoexcept NAT does neither network segmentation or lock down the network. Those things are done by a router and firewall. Implementing proper security of IoT devices can be solved by A) writing more secure software for IoT devices and B) having a proper firewall solution with sane defaults. Using NAT as a tool to masquerade your IP addres is not secure. see NAT hole punching for example [1] NAT is terrible from a network engineering perspective, it was mostly a patchwork to deal with the rapid expansion of the internet and the shortage of IPv4 space. IPv6 brings a lot of cool technology to the table in, like MTU path discovery[2], header extensions[3] and proper anycast[4]. It also makes dealing with subnets and network segments a lot more sane and scalable. [1] https://en.wikipedia.org/wiki/Hole_punching_(networking) https://en.wikipedia.org/wiki/Hole_punching_(networking) [2] https://tools.ietf.org/html/rfc1981 https://tools.ietf.org/html/rfc1981 [3] https://www.cisco.com/en/US/technologies/tk648/tk872/technologies_white_paper0900aecd8054d37d.html https://www.cisco.com/en/US/technologies/tk648/tk872/technol... [4] https://en.wikipedia.org/wiki/Anycast https://en.wikipedia.org/wiki/Anycast
- CamperBob2 9y agoHas any security threat ever relied on NAT hole punching from the outside in? The only cases I can think of involve defective gateway firmware, and IPv6 is hardly a panacea for that. My guess is that IPv6 is the ISDN of the 21st century... an intermediate step between two networking paradigms, one being IPv4 and the other being something we haven't seen yet. IPv6 will appeal to specialists but will never, by itself, see wide adoption. The fact is that NAT works for 99.99% of users, and works very well.
- bluGill 9y ago> NAT is terrible from a network engineering perspective, it was mostly a patchwork to deal with the rapid expansion of the internet and the shortage of IPv4 space NAT is very useful to the network engineer. NAT lets you turn one network into a different one on a simple one-to-one translations basis. However NAP got mixed up with masquerading to the point where when someone says NAT they assume you also mean masquerading when in fact the two are different concepts. NAT when you are doing a many-to-one translations is a disaster in many ways, but it works just well enough (and face it, the alternatives don't exist)
- kazen44 9y agoah well, i should have been more clear in my comment. PAT especially is a disaster. One to One NAT translation is fine although it still breaks a lot of things, especially on the IPV6 side of things. (like MTU path discovery).