5 ms·
No. UDP is connectionless, which makes it harder to use with NAT.
by andreasvc 9y ago
No. UDP is connectionless, which makes it harder to use with NAT.
- xxpor 9y agoNot sure why you say that, UDP conntracking has been around for a long time.
- trav4225 9y agoI suspect that what andreasvc meant is that the default "NAT" configuration of most consumer-grade gear is such that it will block UDP (unless some other mechanism such as UPnP is used)...
- noselasd 9y agoBut it doesn't. Consumer gear NATs UDP pretty much as nice as it does TCP.
- trav4225 9y agoHmm, perhaps you are right... I switched from consumer gear to more "enterprise-y" gear a few years back, so my data points may be a bit outdated.
- testvox 9y agoI've been using normal consumer routers for NATed home connects since 2004 or so and I've never had an issue with outgoing UDP. It's required for basically every video game after all.
- lmns 9y agoThat's true for TCP as well. Almost all consumer-grade routers block all incoming connection attempts, not just UDP. From a stateful firewall's point of view both UDP and TCP have state.
- trav4225 9y agoRight. I was assuming that the context here was connections being initiated by the client (as most are).
- kelnos 9y ago... in which case blocking is not an issue. Consumer-grade NAT hardware will no more block client-initiated UDP than it'll block client-initiated TCP, at least not without extra configuration.
- deleted 9y ago[deleted]
- da_chicken 9y agoIf NAT blocked UDP, the DNS client on home computers would never work.
- icebraining 9y agoI think most routers set themselves as the DNS server, so NAT is not in effect (the computer only sends the request to a local address) unless you define a custom DNS server, which isn't common for home users. That said, I've never seen a router that didn't allow UDP packets to flow back to the origin client.
- da_chicken 9y ago> I think most routers set themselves as the DNS server DNS forwarders like dnsmasq are a relatively recent inclusion in home routers. Sure, they've been there for 10 years or so, but they weren't there for the 5+ years before that. Before Linux took over the embedded OS on home routers, the DHCP servers just passed the DNS configuration that the WAN port got from the ISP, and you can still do that now if you want. That's why nslookup.exe and dig still work on your workstation when you specify an external DNS server instead of the one your DHCP server on your home router gives you. > That said, I've never seen a router that didn't allow UDP packets to flow back to the origin client. Which is the point I was making.
- johncolanduoni 9y agoMost consumer-grade gear can easily handle two-sided NAT transversal with merely a STUN server (no UPnP or relaying required).
- mnd999 9y agoThen don’t use NAT, it’s a hack anyway. IPv6 is not exactly a new idea.
- noselasd 9y agoWhy does it matter that IPv6 is old, if your users are only using IPv4 ?
- gsich 9y agoWhich was maybe a problem 20 years ago. But probably not.
- andreasvc 9y agoTo clarify, what I meant is that with TCP, I can set up a two-way communication channel, even if I'm behind a NAT/firewall I don't control. As far as I understand, with UDP this is harder (i.e., does not work with all NAT types), because UDP does not establish a connection, and it does not provide a two-way communication channel. However, I am not up to date on NAT traversal techniques, so I might be wrong.