8 ms·
I'm probably missing something, but I think that, for home networks at least, NAT is wonderful because of how it requires some effort to make devices exposed on
by jfries 7y ago
I'm probably missing something, but I think that, for home networks at least, NAT is wonderful because of how it requires some effort to make devices exposed on the external network. If we were given an unlimited supply of IP addresses from the ISP and all devices were accessible externally, it seems security issues in would be a much larger problem.
- rohan1024 7y agoThe original purpose of NAT was to get additional devices connected to Internet since we had shortage of Ipv4 addresses. For security, we have firewalls. If we had not been dependent on NAT for security, firewalls would have been actually configured. We will have to configure firewalls with ipv6 anyway.
- dboreham 7y agoNAT arose long before any address shortage concerns. Rather it was a response to ISPs attempting to charge "per user" by associating a fee with each additional address (note this is long before residential ISP service we know today: Internet service was for businesses with retail subs only having ppp access via dialup). NAT allowed customers to work around the ISPs pricing model at the time.
- phate 7y agoWhen my family first got broadband via Comcast@home back in the early 2000s they had a proviso saying if you wanted more then one computer required a separate subscription. My dad and my bother quickly figured out we could get around this by using Windows Internet Connection Sharing. We eventually got a Linksys Router that did the same job and was faster. IIRC even most dial up ISPs did the same thing, if you wanted more then one computer online you had to use separate creds.
- TrueDuality 7y agoNAT is definitively not a security layer and was never intended as such. You can get better security with a simple stateful ingress firewall (block packets not associated with an established/related connection) which is what most people think of for security with NAT. The only slight benefit it has imparted is the privacy benefit of hiding multiple devices behind a single address, but they can usually be individually profile anyway.
- jfries 7y agoI've heard before that "NAT is not intended as security", but isn't the effect still the same, that an external device can't connect to a device behind NAT without explicit configuration allowing it?
- AmericanChopper 7y agoI find this argument to be completely ridiculous, and it’s become remarkably common among those who wish to justify some of IPv6s shortcomings. Whether it was designed to be a security control or not, it is one, and it’s an incredibly important one. Anything that controls how hosts are allowed to communicate with each other is a security control. The argument is so absurd that I literally can’t believe people go around parroting it.
- zAy0LfpBZLC8mAC 7y agoPlease explain how NAT without a stateful firewall provides security against what.
- AmericanChopper 7y agoIt allows you to connect a private network to any other network, including the internet, without allowing hosts on that network access to hosts on the private network. It’s a form of access control. What is your justification for saying that access control measures are not security controls? That is so incredibly contrived.
- zAy0LfpBZLC8mAC 7y ago> It allows you to connect a private network to any other network, including the internet, without allowing hosts on that network access to hosts on the private network. So, how does it do that? > What is your justification for saying that access control measures are not security controls? I am not saying that. It simply isn't an access control measure.
- kalleboo 7y ago> If we were given an unlimited supply of IP addresses from the ISP and all devices were accessible externally, it seems security issues in would be a much larger problem. Nearly 40% of US traffic is already IPv6. 40% in Germany, 30% in Japan. I haven't heard of any massive increase in security issues caused by every device getting its own IP address.
- Macha 7y agoIs that because there's still usually NAT at the users router or cell tower even with IPv6?
- Nextgrid 7y agoI’ve never seen NAT being used with IPv6. I don’t see the point, it would be more effort to use it than not.
- namibj 7y agoWell, it's a firewall that behaves like NAT.
- tjoff 7y agoYes, but it would be worth it. There is no need nor benefit to have a per-device unique address advertised to the world. If there is a desire for a certain device then absolutely, give it its own IP, but that is the exception.
- zAy0LfpBZLC8mAC 7y ago> There is no need nor benefit to have a per-device unique address advertised to the world. Yes, there is! But possibly more importantly: There is no benefit to assigning devices ambiguous addresses. It's as sensible as having all rooms in your business have "1" as their room number because you somehow have convinced yourself that that prevents people from entering your building.