4 ms·
In theory. I very much want IPv6 to take over, but a firewall does not provide the same level of security as a NAT when a bug is found. If a bug is found in a
by PowerBar 6y ago
In theory. I very much want IPv6 to take over, but a firewall does not provide the same level of security as a NAT when a bug is found.
If a bug is found in a non-NAT firewall that prevents it from blocking a packet for some reason, you have a routable address from the outside that you can send packets to. If a bug is found in a NAT firewall that prevents it from blocking a packet, it's very difficult to tell the router which internal address to route the packet to since the IP header only holds 1 "TO" address and by necessity, that's the public address of the NAT firewall.
There are of course some edge cases (double-headers, being on the same L2 network as the firewall, etc), but for most cases, the fact that the internal network is on IP addresses that won't route to their public interface (the NAT firewall) is in and of itself a layer of protection.
Personally, I think this trade-off is worth it in the long run, but it's simply not correct to claim they are equivalent when router firmware bugs are still discovered on a regular basis and consumer network equipment rarely gets security updates (and it's even rarer for consumers to install them).
- silon42 6y agoCouldn't one implement NAT for IPv6 too? Is there a reason why not?