5 ms·
> The number one complaint I hear (and have myself) is that maybe I don’t _want_ all devices on my LAN to have public IP addresses. This isn't a goal in itself
by redprince 5y ago
> The number one complaint I hear (and have myself) is that maybe I don’t _want_ all devices on my LAN to have public IP addresses.
This isn't a goal in itself. The formerly problematic and unwanted side effects of NAT, namely a broken peer to peer relationship of hosts on the internet, are now understood as a feature. Machines were forced by this technology to be clients and the initiators of all connections to the internet. Historically this has interfered greatly with several internet protocols (ftp, IRC DCC, p2p file sharing, ...) all mostly dead now or reworked to operate in a world full of NAT gateways.
IPv6 would reverse this state of affairs. If machines need to be denied the server role, this can be enforced by a firewall. As far as tracking of clients by IP goes, dynamic address assignment via DHCP or IPv6 privacy extension take care of that.
- imoverclocked 5y agoOne can still have intentionally unroutable addresses in IPv6.
- tsimionescu 5y agoSure, but then you're again on par with IPv4+NAT in the area of connectivity - no worse, but no better. So why switch?
- gumby 5y agoBecause you have all the overhead of NAT plus losing functionality that cannot operate through NAT. If all you want is to have addresses that done leave the local net, just do that. You’ll lose weight in a famine but nobody would suggest it as a diet plan.
- tsimionescu 5y ago> Because you have all the overhead of NAT What overhead does NAT add compared to a L4 firewall? > plus losing functionality that cannot operate through NAT. What functionality does NAT prevent that a L4 firewall doesn't?
- imoverclocked 5y agoYou can simply not route a specific range, no firewall needed. NAT, on its own, doesn't provide security. At best, it provides obscurity. At worst, it breaks security [2]. NAT needs a properly configured firewall to provide security [1]. In this sense, NAT vs a Firewall is a false dichotomy. [1] https://tailscale.com/blog/how-nat-traversal-works/ https://tailscale.com/blog/how-nat-traversal-works/ [2] https://www.computerworld.com/article/2556611/nat-traversal--nat-t--security-issues.html https://www.computerworld.com/article/2556611/nat-traversal-... edit: formatting
- tsimionescu 5y agoI wasn't claiming NAT is adding security. A combined IPv4 NAT/firewall will not necessarily be less performant than an IPv6 firewall - that was my claim. Also, GP claimed that certain services that don't work because of NAT would work on an IPv6 network. I was curious which services those might be, that don't work because of NAT but wouldn't be affected by a firewall.
- Dagger2 5y agoIf you're behind CGNAT then generally you won't be able to accept any inbound connections, so even things like a basic webserver aren't doable.
- gumby 5y agoThese stateful devices have to look at all the traffic and maintain connection data for every transaction. That takes space and time and is bounded in volume.
- tsimionescu 5y agoThe same is true of firewalls, so I don't get your point. Even in IPv6, your router-level firewall will need to know if a packet with dst_port=31536 is part of an existing connection or not, which means it has to monitor all traffic and maintain connection data for every transaction, no different from a NAT device.
- gumby 5y ago> The formerly problematic and unwanted side effects of NAT, namely a broken peer to peer relationship of hosts on the internet, are now understood as a feature A feature? I’ve never heard that. If you want to break the end to end nature of the net you can do that in your router, easily and more powerfully, without all the overhead of NAT. The net has turned back to the old mainframe days, and things like NAT make it hard to go the other way.
- DarylZero 5y ago> I’ve never heard that. It was in the parent comment!