3 ms·
That doesn't make any sense, because if you didn't want anybody from outside your network to route packets onto it, why not just not have the router? You actua
by Dagger2 3y ago
That doesn't make any sense, because if you didn't want anybody from outside your network to route packets onto it, why not just not have the router?
You actually do want your LAN devices to be routable from the outside, because you want them to be able to talk to Internet hosts and you want those hosts to be able to reply. That's the real reason you have the router.
What you probably don't want is for people outside your network to be able to initiate new connections to inside of it, and that's something you get with a firewall, running either on your devices or on the router.
NAT only comes in to any of this if your ISP can't issue you enough address space to use on your LAN, without which your network won't be routable even with a router in place. NAT is the big hack to try and get routing to work without sufficient ISP-assigned address space. It's not needed for anonymity or for getting a single point of control.
- otabdeveloper4 3y ago> You actually do want your LAN devices to be routable from the outside I do not. I certainly don't want the internet to know how many devices I have and what they are. Traffic to and from the LAN should be anonymous. As far as the internet is concerned, my LAN is a black box. > It's not needed for anonymity or for getting a single point of control. NAT used that way usually, because other solutions are lacking or too expensive, and because the people who invented IPv6 didn't bother trying to solve real problems.
- Dagger2 3y agoAt the very least then, you need it as a prerequisite for something else that you want. Or perhaps I'm assuming too much about your network here. Let me double-check: do you use NAT? You've said things about it, but do you use it on your network? NAT applies on top of routing, so you can't use it without routing. If you're using NAT, then you've made your devices routable. Whatever you say about not wanting to do that, you did do that, so it must have been preferable to you in some manner or another. I know this would contradict your claim that you only have a router to make your network unroutable, but that claim never made any sense in the first place. It's the job of a router to make a network routable. > NAT used that way usually, because other solutions are lacking or too expensive, and because the people who invented IPv6 didn't bother trying to solve real problems. Nobody is using it to get a single point of control. In order to NAT you need to set a router up, which means you already have a single point of control. There's no need to also do NAT and it won't help either, so it's not being used for this. It's not usually being used for anonymity either, because most people using it only have a single IP address in the first place and that's the one all their NATed connections appear to come from. They get no anonymity from NAT. The people who invented v6 did bother trying to solve real problems. But getting a single point of control was never a real problem and didn't need solving; the real problem was the lack of address space, which they did solve.