8 ms·
I also found this weird, and this got me to check if it was enabled on my business firewall devices: turns out they don't even support UPnP. Is it just consumer
by deburo 6y ago
I also found this weird, and this got me to check if it was enabled on my business firewall devices: turns out they don't even support UPnP. Is it just consumer routers that support it nowadays? Shouldn't that feature just be nuked?
EDIT:
Well it sounds like a feature for pro users that know what they are doing and control all devices on the network. Even then, security appliances (eg. from SonicWall) don't support it. I don't know, this is probably a niche feature for a few occasions.
- my123 6y agoFar from only a feature for pro users. Notably, it is a must for VoIP (without going through a relay) and BitTorrent when you don't want to manually configure a firewall. (allows to create holes in a controlled way for a NATted network) Without UPnP, you specifically have to configure your NAT for this...
- nobody9999 6y ago>Without UPnP, you specifically have to configure your NAT for this... While I realize that configuring nftables/iptables is beyond most folks, there are many firewalls out there that have a GUI/webui which makes this dead simple. Not sure why this should be an issue in 2021, except for users' trained-in helplessness.
- hluska 6y agoUgh, users trained in helplessness. I just had an utterly annoying conversation with my cell phone provider whose reps have been trained in helplessness and thus fail to follow really simple security procedures. This phrase is a thing of nightmares now. Stay tuned for a really scary Haunted House full of users trained in helplessness...coming Halloween 2021.
- benlivengood 6y ago> Not sure why this should be an issue in 2021, except for users' trained-in helplessness. Kids hosting games on random ports (terraria, etc.) benefit from UPnP. I'd rather enable it than manually enter firewall rules for each game or give them admin access to the firewall. UPnP is only an additional risk if you have malware inside your network already and then it mostly allows malware to host services in a simpler way, but capable malware will be able to use TCP hole punching to establish arbitrary connections between infected networks.
- nobody9999 6y ago>UPnP is only an additional risk if you have malware inside your network already I'm not sure where you get that idea. Once a hole is poked (depending on the perimeter device/software in use), it stays poked and you've expanded your attack surface. I make sure that there's no dynamically defined external access to my network. Can you guarantee that no software in use on your network is free of vulnerabilities? I'm not talking about malware here, just your run-of-the-mill software bugs. If you think the answer is no, then why don't you share your network details with us and let's have a go? Then we'll see how much of an extra risk upnp might be. What's that? You'd prefer not to do so? If there's no risk, then it shouldn't be a problem, right? My suggestion is (obviously, I hope) an idle one and more intended as food for thought. >Kids hosting games on random ports (terraria, etc.) benefit from UPnP. I'd rather enable it than manually enter firewall rules for each game or give them admin access to the firewall. That may be a valid use case for you. However, claiming that it doesn't increase your attack surface/risk profile doesn't magically make it so. I'm not telling you what you should or shouldn't do, but I do disagree with your rationalizations about why allowing upnp to expose your perimeter doesn't increase your risk profile.
- benlivengood 6y ago> If you think the answer is no, then why don't you share your network details with us and let's have a go? Then we'll see how much of an extra risk upnp might be. The cheap and fast attacks are DDoS and they're trivial to aim at a cable modem. Avoiding becoming a target is at least 50% of security posture. There were already 4286 ssh login attempts today so I don't really need more attempts than the automated botnet scans provide. It's a risk/convenience tradeoff. I could probably package up a vpn.exe and force the kids' friends to run it before playing games, or force them to host games remotely. It's just not worth it. I'm also reasonably sure that there are plenty of 0-days in all networks, given their relatively frequent discovery. So, again, don't be more of a target than necessary, and keep offline backups current and tested.
- BlueTemplar 6y agoSince this is 2021, you should use IPv6, which doesn't need NAT.
- fogihujy 6y agoAlas, many ISP's don't offer it yet. Give it a few decades more and we might get that.
- BlueTemplar 6y agoAt some point the governments should forbid them from calling themselves "I"SPs. This has already started with the 5G.
- fogihujy 6y agoWhile there's always demand for more bandwidth, IPv6 isn't really something that people care about in the larger scheme of things. Many ISP's and carriers solved the IPv4 congestion issue with CGNAT and that'll keep things going until we run completely out of IPv4 addresses. Once that happens, there will be government action. Not before.
- BlueTemplar 6y agoWe'll never completely run out of IPv4 addresses. Meanwhile the top agencies distributing IPv4 blocks have ran out of them a decade ago. Recently it was the time for a lower level agency to run out - for Europe. There's a lot of things that people don't care about until it's too late. Governments are supposed to be able to plan decades in advance. And they do, for things like digital TV. (And I already gave an example of governments acting to push IPv6.) CGNAT is causing issues in that some protocols simply don't work properly through them. IPv6 also allows for simpler networking, since you don't have to add the extra abstraction layer that is NAT.
- fogihujy 6y agoPoliticians in Europe expects the market to take care of it. Businesses won't hurt their profit margins unless they have to (because IPv6 does mean additional costs). We need something that increases consumer demand for IPv6 if we wantbthis to be dealt with now.
- ShroudedNight 6y ago> Notably, it is a must for VoIP Wouldn't making STUN work be a better alternative?
- rubatuga 6y agoYes, it’s a feature supported by many VOIP clients, and this comments section is filled with UPnP apologists
- my123 6y agoAs I said, "without going through a relay". And TURN is one of those relays. (I host a STUN and TURN relay myself, because I had to for my personal VoIP server for enough people to be able to connect on it. Downside is more use of bandwidth.) edit: replaced STUN with TURN where appropriate, I did confuse both as they were provided as a single package.
- daniellarusso 6y agoWhat STUN relay software do you use, or is it a hardware device?
- my123 6y agoI use https://github.com/coturn/coturn https://github.com/coturn/coturn, provided as the coturn package on Ubuntu 20.04.
- deleted 6y ago[deleted]
- rubatuga 6y agoSTUN is not a relay.
- dasyatidprime 6y agoSTUN is not a relay, but TURN is, and STUN/TURN is a common combo for when STUN doesn't manage to holepunch reliably, falling back to the relay when the direct connection fails. What's also true, and what I think the GP was trying to get at, is that STUN requires an external coordination server. UPnP (I think—I am far less familiar with it) does not, because in UPnP you're negotiating the holepunching with the local router directly, whereas STUN is sort of using a loophole.