4 ms·
Any such firewall will need to: a) Mask end-user addresses somehow. You wouldn't want everyone on your corporate network to get a globally unique, trackable ID
by otabdeveloper1 9y ago
Any such firewall will need to:
a) Mask end-user addresses somehow. You wouldn't want everyone on your corporate network to get a globally unique, trackable ID.
b) Allow outgoing connections in arbitrary ways but forbid random incoming connections.
c) Some sort of central, highly secured network node where your admins can configure this stuff.
At this point you're close to reinventing NAT, except crappier.
- zAy0LfpBZLC8mAC 9y ago> a) Mask end-user addresses somehow. You wouldn't want everyone on your corporate network to get a globally unique, trackable ID. Everyone on your corporate network has tons of globally unique, trackable IDs. They're called cookies. Also, there are IPv6 privacy extensions. > b) Allow outgoing connections in arbitrary ways but forbid random incoming connections. Just as with IPv4? > c) Some sort of central, highly secured network node where your admins can configure this stuff. That's called a firewall. You need one with IPv4 as well. > At this point you're close to reinventing NAT, except crappier. None of that has anything to do with NAT.
- Symbiote 9y agoa) Do you provide privacy plugins to users' web browsers, and require they use them? If not, the concern is close to irrelevant, but there are privacy-minded ways to assign IPv6 addresses. b) is a basic feature of the crappiest firewall (the free router from my ISP includes it) c) is a standard feature of a business-level firewall; secure network access (e.g. with a VLAN) is orthogonal to the choice of IP protocol.
- guelo 9y agoIPV6 firewalls can do NAT in the same way IPV4 ones can.
- p1mrx 9y agoNAT66 is possible, in the sense that the protocol won't stop you from implementing or using it. But in practice it's relatively rare, because once you have a nearly-unlimited supply of addresses, NAT typically has more drawbacks than benefits.
- mgbmtl 9y agoOn tracking: - You can use IPv6 privacy extensions to randomize your IP address. Your computer can have a dozen IP addresses at a given moment, using a different one to access different services, as addresses are being rotated. - Most corporate networks have static IPs. So while a specific IP might be shared with 100 devices, it's usually easy to fingerprint a visitor uniquely. - There are tons of other ways to track people, other than their IP. Besides, you want to track them across networks, as they move around. I'm also very sensitive to tracking, but I think at this point you have to start looking at how to improve your privacy with IPv6, sharing/encouraging good privacy-sensitive practices on IPv6.. not spreading FUD.