5 ms·
IPv6 not having NAT doesn’t make it incompatible with stateful firewalls. You can still have routers doing drop inbound by default.
by johnnyapol 4y ago
IPv6 not having NAT doesn’t make it incompatible with stateful firewalls. You can still have routers doing drop inbound by default.
- deleted 4y ago[deleted]
- mnd999 4y agoAnd ISP supplied devices generally are. I don’t really know why people think this is an issue.
- yonz 4y agoMight have learned something today, I always replace the stock router from ISPs. Easy to test, can someone on a cable box try to reach an open port on their host on IPV6 vs IPV4. My belief is that a majority of setups (maybe not HN hackers) will able to hit a host's open port on v6 and fail on v4. NAT is definitely an added layer though.
- Symbiote 4y ago> Might have learned something today Yet you continue to speculate about it and spread baseless FUD. Consumer ISPs supporting IPv6 provide routers blocking inbound access by default. The interface to open IPv6 ports is usually labelled "IPv6 Pinholes" or similar, and you'll find hundreds of web pages on ISP websites describing the functionality -- just as they have pages on IPv4 port forwarding. The extraordinary claim that ISPs are supplying routers with such a dangerous default configuration requires evidence.
- yonz 4y ago> extraordinary claim that ISPs are supplying routers with such a dangerous default configuration requires evidence Its a legitimate expectation and potentially the norm to expect that I can ssh to my desktop with IPv6 w/o configuring my router. The pitfall comes as a side effect of NAT inadvertently making port access rare. I am looking for data, inbound blocked ipv6 seems unlikely but I only have anecdotal evidence.
- jiggawatts 4y agoThat's not even an anecdote. You are literally just assuming something is true, then arguing vocally with people giving you evidence to the contrary.
- roamerz 4y agoIt goes beyond that. With IPV4 you have the further protection of private subnets not even routing across the public internet - it’s broke by default, no configuration necessary. Your attack surface is primarily your firewall which admittedly might be an easy target - but not as easy as an unprotected Windows box.
- yonz 4y agoExactly! Duplicating my point in a thread below to drive your point home: NAT was an added layer on top of firewall rules because inbound ports had to be mapped to a particular host and port since the router would not know which host to send to. This created a default opt out experience because for a port on your machine to get accessed, a packet must pass inbound rules and match a port map table entry.
- throw0101c 4y agoNAT was created for one reason only: because there weren't enough IPv4 addresses to go around. Port mapping and connection tracking firewalls were invented in 1989,[1][2] while network translation was created in 1994. [3][4] The private address space was only reserved in 1996.[5] The Firewalls book was published in 1994 (which meant that it was being written in the 1992-3 timeframe).[6] People were protecting networks before NAT. [1] https://en.wikipedia.org/wiki/Firewall_(computing)#Connection_tracking https://en.wikipedia.org/wiki/Firewall_(computing)#Connectio... [2] https://en.wikipedia.org/wiki/Circuit-level_gateway https://en.wikipedia.org/wiki/Circuit-level_gateway [3] https://www.rfc-editor.org/rfc/rfc1631 https://www.rfc-editor.org/rfc/rfc1631 [4] https://en.wikipedia.org/wiki/Cisco_PIX https://en.wikipedia.org/wiki/Cisco_PIX [5] https://www.rfc-editor.org/rfc/rfc1918 https://www.rfc-editor.org/rfc/rfc1918 [6] https://en.wikipedia.org/wiki/Firewalls_and_Internet_Security https://en.wikipedia.org/wiki/Firewalls_and_Internet_Securit...
- whoopdedo 4y agoPrivate address ranges are a human convention and there have been instances in the past of upstream routers passing them on.[1] Relying on other people to do your filtering for you is a bad idea. I'm going to put the rules in my own router, whether those addresses are (potentially) globally routable or are designated as private. The use of small private pools has even helped attackers who would inject browser scripts probing the well-known prefixes.[2] [1] https://serverfault.com/questions/374126/private-ip-getting-routed-over-internet https://serverfault.com/questions/374126/private-ip-getting-... [2] https://www.bleepingcomputer.com/news/security/new-behave-extension-warns-of-website-port-scans-local-attacks/ https://www.bleepingcomputer.com/news/security/new-behave-ex...