5 ms·
NAT like security for IPv6 is just dumb. We should always configure firewall for v4 and V6. NAT is not for security!! It has different purpose which is now bein
by quaintdev 6y ago
NAT like security for IPv6 is just dumb. We should always configure firewall for v4 and V6. NAT is not for security!! It has different purpose which is now being taken care by V6 and NAT should just die.
- franga2000 6y agoYes, BUT: for many many years, home networks have relied primarily on NAT for security. The firewall was only ever touched when doing something advanced and even people who were doing things like setting up home servers and such rarely had to deal with it. Every single tutorial on the topic is IPv4-specific and until IPv6 isn't more common, people will not write guides and tutorials with IPv6 in mind. So until the knowledge of proper security on open networks is common enough among home tinkerers, we should not be recommending people just throw everything straight onto the open Internet.
- mercora 6y agoi don't think the typical NAT setup differs too much from a typical filtering setup. That is, only allow return traffic from public interfaces. While that is kinda implicit using NAT the change to being explicit is trivial. somewhat simplified like this using iptables on linux: iptables -t nat -A POSTROUTING -o WAN -j MASQUERADE vs iptables -A FORWARD -i WAN -m state ! --state RELATED,ESTABLISHED -j REJECT
- kzrdude 6y agoSecurity has layers, no layer has to be perfect. What's wrong with having NAT as an obscurity layer?
- fogihujy 6y agoThe problem is that many people use NAT as the only line of defense, and that model fails utterly once IPv6 comes into the picture. There's nothing wrong in using NAT to increase the cost of attack as a part of a larger defence strategy.