10 ms·
NAT still exists for IPv6
- slaymaker1907 4y agoSomething I'm a bit fuzzy on, but can WAN/LAN address separation be done without NAT? I think it can, but if it can't that seems like a good argument in favor of keeping some form of NAT even for IPv6. While it definitely shouldn't be the only defense, I think it is a reasonable layer of defense for home networking.
- zamalek 4y agoThe IPv6 answer is Network Prefix Translation, the article has more details on what it does.
- Arnavion 4y agoDepends on what you mean by "separation". My LAN devices have IPv6 addresses that would be reachable from the WAN if my router's firewall didn't block incoming packets to those addresses. For some of those devices that host public services, I enable traffic just for the relevant protocol and port to their IP, instead of bothering with port forwarding.
- gary_0 4y agoThis answer is what every argument about IPv6 and NAT boils down to: they say "NAT" but really mean "firewall". In my opinion, using NAT for IPv6 networks is just a false sense of security to make you think LAN nodes are more protected because their address numbers look different, when all you're really trying to say is "don't route to this node from outside".
- dopp0 4y agowhy it would be a 'false' sense of security if it's not exposed? I don't seem to get it as 'security through obscurity' at all. sincere question, I'm not a network guy.
- redblacktree 4y agoI'm not a networking guy. Do you think that approach would work for a device behind CG-NAT? (i.e. route the IPv6 address over the WAN, rather than port forwarding; which I can't do because of the CG-NAT)
- Arnavion 4y agoYou mean you have CGNAT for IPv4 but a publically routable IPv6 delegated subnet? If so, sure, what I wrote depends only on the IPv6 delegated subnet. How you get your IPv4 address is not relevant to it. What I'm saying is that if you can get, say, 2001:db8:1234::/48 delegated to your router, then: 1. You would configure your LAN to have the subnet 2001:db8:1234:1::/64 2. You would configure the webserver on your LAN to have a static IP like 2001:db8:1234:1::1 3. You would add a firewall rule in your router on the WAN interface to allow incoming TCP traffic with destination [2001:db8:1234:1::1]:443 . This rule would have higher precedence than the default rule that blocks all incoming traffic). At this point, anyone in the world who attempts to reach 2001:db8:1234:1::1 will reach your ISP, which will route it to your router's WAN interface (because the ISP delegated the prefix to your router), which will allow the packet to cross from WAN to LAN because of the firewall rule, which will then route it to your webserver.
- tenebrisalietum 4y ago> I think it is a reasonable layer of defense for home networking. Let's say Amazon won't deliver to your apartment number, just a central point at your apartment. - This is like thinking you can stop locking your door because your apartment number isn't public information. - It would be better if your apartment had a direct public address so you could get packages to your doorstep instead of having them wait in some common area. - Most people take regular, obsessive trips to application-level exchanges like "Facebook" to interact with others and are fine with it. Hopefully everything you ever want to do is OK with Facebook.
- jimcavel888 4y ago
- LeoPanthera 4y agoOf course. You use a firewall. Thinking of NAT as a firewall is a common misunderstanding. With IPv6 you will still want a firewall, which is often built into your external gateway/router.
- gerdesj 4y agoMy work network has a /64 for WAN (yes quite a lot of addresses for a point to point link) and a /48 for "internal use". So WAN is merely a few billion IPs and VLANS - gazillions of IPs. OK we also have six other WANs and allocations but that is another story. We have no need for NAT in the traditional IPv4 sense but NPT is handy for failover and that is why it was invented because IPV6's design lacked one crucial thing: telling the clients which internets are available so they can select which local address to start out from. Perhaps everyone should run BFD(v6) by default.
- throw0101a 4y ago> My work network has a /64 for WAN (yes quite a lot of addresses for a point to point link) […] Technical footnote: /127 addresses are supported (and were a thing for a short while) on inter-router links: * https://datatracker.ietf.org/doc/html/rfc6164 https://datatracker.ietf.org/doc/html/rfc6164 Technical technical footnote: you can just use link-local address for inter-router links because all the router cares about is the next next-hop, and you don't need a globally routable address for that. In an IPv6 network, it is possible to use only link-local addresses on infrastructure links between routers. This document discusses the advantages and disadvantages of this approach to facilitate the decision process for a given network. * https://datatracker.ietf.org/doc/html/rfc7404 https://datatracker.ietf.org/doc/html/rfc7404
- gerdesj 4y ago"Technical footnote: /127 addresses are supported" Yes they are but I want a shit load of stuff on my WAN available to the world and I don't want to piss around with NAT n that. The IPv6 address-space is big enough to deal with PtP links. It doesn't really matter, You could do a /127 for WAN and then I allocate a /64 from my /48 for WAN. Or you could use a recent RFC that enables a /64 or smaller to be used for WAN without a separate allocation.
- unethical_ban 4y ago"NAT as security" can be reframed. Instead of a router coming default with NO access control/firewall, and inbound connections being denied by the technical impossibility of addressing an inbound Internet packet to a private address, the industry should shift to "default ACL of allow all outbound, allow none inbound" and then have users craft inbound firewall rules as needed.
- mort96 4y ago> and then have users craft inbound firewall rules as needed Try explaining that to non-techies. There's a reason UPnP exists. We would ideally want something like NAT hole punching but more standardized.
- 1MachineElf 4y ago>Something I'm a bit fuzzy on, but can WAN/LAN address separation be done without NAT? Yes, it can. I used to work in a place that had so many public IPv4 addresses that they were using them for laptops and workstations. With a good firewall configuration it is certainly possible. However I agree with you that IPv6 NAT may be useful still.
- collegeburner 4y agohot take of the day: NAT is (mostly) a shitty idea. we can give everything a WAN ipv6 and a private LAN address. devices should maintain their own firewalls and if defense in depth is required, the router should maintain a firewall that blocks incoming by default but still give everything its own address.
- ipdashc 4y agoWhile I mostly agree, there's definitely the issue of readdressing if your ISP changes your IPv6 prefix. In NATted IPv4, you can maintain your own eternally consistent internal address scheme, regardless of what's going on "outside". But in IPv6, if your dynamic IP changes, all your devices get new addresses. I can definitely see the value in creating a stable internal address layout on IPv6, as this article says. Of course, I have no idea how often an ISP actually changes your IPv6 prefix. In an ideal world, it'd never change...
- staringback 4y agoULAs at least solve this problem for all networking that doesn't have to be internet facing
- anamax 4y agoPeople change ISPs....
- ipdashc 4y agoFor sure, but that's a predictable event that you can plan for and get ready to renumber your network / handle the renumbering. A dynamic IP change can just happen without much warning, and enjoy possibly spending an hour befuddled before you realize what happened.
- unethical_ban 4y agoThe article's main topic is on NPTv6, which would supercede NAT as the tool for maintaining internal addressing.
- LeoPanthera 4y agoI really want to love IPv6 but my ISP (Xfinity in California) will not provide a stable prefix. This doesn't matter with IPv4, because all my internal IPv4 addresses are NATed. But with IPv6, although each device on the network can receive a globally routable IPv6 address, the prefix keeps changing, and so the address keeps changing. This makes internal networking a nightmare, since the address of my devices is not under my control. I don't use NPT, but it would fix the problem, so people are going to continue using it until dynamic prefixes go away. Which will probably be never.
- zokier 4y agoAs I understand it, the idea is to use many addresses per host. I.e. you don't need to use same addresses for internal networking as global networking.
- nomel 4y ago> Which will probably be never. Wouldn't this be like static bluetooth IDs, where you could be tracked wherever you go? I imagine that's a rare desire, amongst the internet population. I could see requesting static IPs for particular devices, like you used to be able to do.
- unethical_ban 4y agoI'm not sure what the best current practices are for mobile, but for residential/business/etc., the most convenient behavior would be for the delegated prefix to be static unless it is requested to be changed. That tends to be the case already with ISPs who grant public IPv4 to customers - it's DHCP whose lease stays the same unless you forcibly change your MAC address or let the lease expire via turning off your modem, and so on. Talking about IPv4 with NAT, a "consumer" with zero server-hosting needs could get away with a changing public IP. Someone with any kind of server needs, like hosting their own Internet-accessible IoT portal, personal VPN, website, game server, etc. would want a stable public IP address. Yeah, that may lead to tracking, but it's the status quo, I suppose is the point. In case it isn't known, IPv6 has so many addresses and is designed in such a way, that it is expected each "network" (think home network) would be given a network prefix of 56 or 60 bits. The "host" portion of an IPv6 address is the final 64 bits of the address. Therefore, each network an ISP issues to a client should have room for something between 16 and 256 subnetworks, each with effectively unlimited client address space.
- atemerev 4y ago"Stateful packet filtering can provide the same level of security for IPv6" The keyword here is "can". The difference here is this: if your NAT is not configured properly, your network is not accessible, nothing works, the problem is obvious, and is going to be fixed ASAP. If your stateful firewall is not configured properly, everything works fine, except that your network is visible from places it wasn't supposed to be. It requires some dedicated checks to verify. So, the problem with NAT vs firewall security is not technical, it is psychological (but no less dangerous): when you have a working (but insecure) system by default, it is easy to miss the hardening step. The consequences can be catastrophic.
- throw0101a 4y agoSee also "IPv6 Multihoming without Network Address Translation": Network Address and Port Translation (NAPT) works well for conserving global addresses and addressing multihoming requirements because an IPv4 NAPT router implements three functions: source address selection, next-hop resolution, and (optionally) DNS resolution. For IPv6 hosts, one approach could be the use of IPv6-to-IPv6 Network Prefix Translation (NPTv6). However, NAT and NPTv6 should be avoided, if at all possible, to permit transparent end-to-end connectivity. In this document, we analyze the use cases of multihoming. We also describe functional requirements and possible solutions for multihoming without the use of NAT in IPv6 for hosts and small IPv6 networks that would otherwise be unable to meet minimum IPv6-allocation criteria. We conclude that DHCPv6-based solutions are suitable to solve the multihoming issues described in this document, but NPTv6 may be required as an intermediate solution. * https://datatracker.ietf.org/doc/html/rfc7157 https://datatracker.ietf.org/doc/html/rfc7157
- deleted 4y ago[deleted]
- juancn 4y agoThe lack of adoption of IPv6 over so many years, it makes me think that they should just have slapped a couple extra address bytes on IPv4 and call it a day.
- ronsor 4y agoBut that's basically what IPv6 is. Regardless of whether two bytes, twelve bytes, or twenty bytes are added to a IPv4 address, the complexity of implementation mostly remains the same.
- thedougd 4y agoI ran into the oddest thing after switching ISPs. IPv6 kept dropping out with my devices and I traced it back to the LAN side of my router accepting router advertisements from inside my network. Easy enough to fix, I flipped the flag to not accept router advertisements on the LAN interface. The weird part is that I traced the router advertisements as coming from an old Google Chromecast. It was advertising the prefixes of my old ISP. Bug or intended? If the latter, why?