11 ms·
How does Linux NAT a ping?
- jjoonathan 3y agoNAT is such a trashy abstraction. IPv4 needs to die.
- trustingtrust 3y agoYou'll hate CG-NAT even more then.
- lorenzo95 3y agoheh ... It's all IPv6 ULA here with Nat66
- i80and 3y agoThe first time I encountered CGNAT was such a rude shock. I don't think it should be legal to market it as "internet" to consumers
- sgt 3y agoIf your ISP gives you CGNAT, then the best thing you can do is to request a static public IP address. Will probably cost a little bit more but well worth it.
- kazinator 3y agoYou need NAT (or something else that is worse in some respects, like port forwarding) in any situation in which your subnet is given only one address upstream, even if it is an IPv6 address.
- xxpor 3y agoIf your ISP doesn't do PD with v6, their implementation sucks. Even my crappy 6rd setup from CenturyLink gives me iirc an entire /48.
- midasuni 3y agoMany ISPs suck. That’s not controversial. We have to deal with the world we live in, not the world we’d like.
- pantalaimon 3y agoThat's why variable length SLAAC has been proposed https://datatracker.ietf.org/doc/draft-mishra-6man-variable-slaac/08/ https://datatracker.ietf.org/doc/draft-mishra-6man-variable-...
- yrro 3y agooh no
- growse 3y ago> Many ISPs suck. That’s not controversial. > We have to deal with the world we live in, not the world we’d like. No we don't. Some choose to just put up with shittiness, others enact change.
- kazinator 3y agoOP here. Your "ISP" is a sysadmin at work who gives you one address to your cube. You otherwise like the work and the team, and the compensation is fine. Now what?
- growse 3y ago> Now what? You advocate for change. You make the case. You might not win the battle, but you're by no means forced to accept the status quo. The more who fight the battle, the more win. The more win, the faster progress, which benefits us all.
- kazinator 3y agoI set up NAT, I move on. If you can solve a problem technically, without involving people, that is best.
- paulddraper 3y agoYeah, but there's no reason to do that with IPv6
- midasuni 3y agoI have a few devices on my home internet, on a handful of 192.168 subnets The other week I moved my ISP. The AS my house belonged to obviously changed to the new ISP, and I got a new v4 IP All I had to do was update my Wan router to forward trafffic from the new Ip. Instead with ipv6 I would have to change every node on my network, update my internal DNS. Now in theory I could have my own /48 which I take with me. That relies on my new ISP being willing to advertise it (which my current one does) but it’s not particularly common. However a week ago my phone line was cut. I got a 5g mifi out and moved my wan connectivity through that until the cable was fixed. Again a nice simple masquerade on that interface and all was good (well not that good - very poor signal where I live) But the elephant in the room is of course all that ipv6 stuff aside, I still need to run a dual stack (or use trashy nat abstractions). It increases my work for no benefit. But taking about work, how about there? I have a fleet of vehicles on internal 172.16/12 subnets, they plug together and route to each other, and route from where they are via a variety of vpn connectivity (hoping that at least one method will work, as there’s rarely a signal in the basements these park) If I moved them to ipv6 then again I’m back to having to move my /48s. Except these vehicles get internet from various sporting venues - most of which struggle to turn off MITM/443 or unblock UDP, that’s just not going to work in a world where they turn up at 10am Saturday morning and need to be working 2 hours later. What business benefit is there for me to double the workload and double the risk by moving to dual stack?
- pixl97 3y agoI do believe there is some kind of 1:1 NAT with IPv6 these days, which is way better than 1:Many of IPv4. There are so many potentially useful applications that are DOA because of v4 NAT being everywhere.
- midasuni 3y agoThose applications are DOA because of firewall administrators that barely allow tcp/443 through.
- deleted 3y ago[deleted]
- 3y ago
- mindslight 3y agoIs there a better way to not unnecessarily leak addressing metadata to adversarial remote nodes and middle boxes? IPv6 with assigning end users a whole /64 and end-devices continually churning through privacy addresses is a start. But even then some form of NAT is still required to nimbly use source prefixes from different horizon providers - eg to avoid spilling your geographic location or opening yourself up to low-effort legal shakedowns. An example: on my local network I've got an everyday web browsing VM and a torrent VM. They each have static 192.168.x.x addresses, both so I can ssh in for administration and also to control their view of network services. They each see a completely different Internet horizon through the router - the web browsing goes out from a rotating datacenter IP, and the torrent one goes out from a consumer VPN. Each of those outgoing horizons uses NAT - any of my hosts using that rotating data center IP appears the same, and any of my host using the consumer VPN appears the same as every other customer using that same VPN node. What is the no-NAT equivalent of this? Make that rotating data center IP and VPN external IP into subnet allocations, somehow feed that addressing information back to the hosts that are using it, and dual-home each VM with two routable addresses? For equivalent mixing on the consumer VPN there would also need to be some ARP-like protocol that let me continually rotate the address.
- jandrese 3y agoWhy not just use a VPN in both cases? That’s more or less what your NAT solution is doing, except without the encryption to the data center.
- mindslight 3y agoIt is a wireguard tunnel to the data center, but my comment was focused on the addressing.
- 3np 3y ago> What is the no-NAT equivalent of this? At least for web-browsing and other HTTP/TCP use-cases: Cut off internet from your hosts and use centralized local proxies for all outgoing connections. Presumably you already have reverse proxies in place for the incoming. There is no need for NAT if all the traffic is taken care of in higher layers. This reduces your consideration to the internet-facing forward- and reverse-proxies only. Sounds like you already have bittorrent figured out via VPN (Wireguard I guess? Well there we have one more UDP exit-point to consider). BTW, I largely agree with your sentiment: Benefit of (especially migrating to) IPv6/DS for individual networks is often unclear or questionable and metadata privacy is a valid consideration where I believe correct solutions are not readily available and understood even by your well-intentioned and seasoned senior admins. Maybe globally the number of people who will get this right ranges in the 1000s? 10,000s if we're lucky? How many networks do we need to migrate again for "IPv4 to die"? I guess the only way forward is for more people to do that migration and share their findings and solutions, though ;)
- riffic 3y agobe mindful of the Lindy effect, an observation on the future longevity of non-perishable things like technology or an idea being proportional to their current age, ipv4 due to its age will likely be around for quite some time to come. https://en.wikipedia.org/wiki/Lindy_effect https://en.wikipedia.org/wiki/Lindy_effect
- littlecranky67 3y agoNot sure IPv6 will fix this. Technically, yes it does. But major providers only assigning a /64 to a home user (and charging hefty fees for "buisness use" /48) already leads to IPv6 NAT or segmenting the /64 further - which shoulnt be done.
- lazide 3y agoMost seem to have stopped and are handing out /48’s in my experience. Do you know any not doing that still?
- littlecranky67 3y agoI'm with one of the biggest german internet providers (o2 Telefonia) and they are not even providing any IPv6 at all (at least not in all regions, and without calling support to enable this feature individually).
- lazide 3y agoThanks for the correction! Hopefully they get their act together soon.
- mike_hock 3y agoWhy would anyone need /64 if not to segment it further.
- littlecranky67 3y agoWell ask the IETF, the RFCs say that sub-segmenting a /64 shouldn't be done. Yet people do, and the result is - well - here be dragons depending on the implementations.
- zamadatix 3y agoSo nobody ever again needs to think "what size end user subnet is in use". It's /64, it's always /64. It doesn't matter if you're embedding MAC addresses, using random assignment, using multiple assignments, have 1 device, have 1 trillion devices. It's a /64.
- jaimex2 3y agoIPv6 needs to die also. It had more than enough time to become dominant and has just floundered.
- sgjohnson 3y agohttps://www.google.com/intl/en/ipv6/statistics.html https://www.google.com/intl/en/ipv6/statistics.html 45% (and growing) of all traffic to Google is IPv6. Hardly "floundered". It's just that most major ISPs in the developed world have so many IPv4 addresses they don't care that much about IPv6 yet. Now, try starting a new ISP without CGNAT (which will lead to a garbage experience for everyone) or IPv6. You'll have to spend literal tens (if not hundreds) of millions just on IP addresses alone.
- commandersaki 3y ago25 years and we've only got 45% We should've been at 95% decades earlier if they came up with an actual transition plan.
- sgjohnson 3y ago"25 years" is not fair. There was no immediate need for IPv6 for anyone 10 years ago, so it should be no surprise that it's not at 95% currently. Now there is.
- commandersaki 3y ago20 years ago DJB called it [0]. The same problems exist. The only place IPv6 has gained any success is in the mobile market since handsets tend to be homogeneous and therefore configurable, which does allow a decrease in load of CGNAT for carriers. However, this success is not replicated in the broadband realm and probably never will be for all same reasons outlined by DJB. IPv6 is a second class network. [0]: https://cr.yp.to/djbdns/ipv6mess.html https://cr.yp.to/djbdns/ipv6mess.html
- 3y ago
- backendanon 3y agoIPv6 needs to die. IPv4 using NAT ensures a moderately high level of privacy. IPv6 with privacy extensions does not.
- commandersaki 3y agoYou mean the unsung hero of the Internet.
- nanmu42 3y agoGood post. Coincidently, I was struggling with Netfilter this weekend to enable transparent proxy on my OpenWRT router. For the curious, the go-to resources for Netfilter are: 1. https://wiki.nftables.org/wiki-nftables/index.php/Main_Page https://wiki.nftables.org/wiki-nftables/index.php/Main_Page 2. https://www.netfilter.org/projects/nftables/manpage.html https://www.netfilter.org/projects/nftables/manpage.html
- viopq 3y agoIt's refreshing to see a "how does" which actually drills down through layers of abstraction all the way to the source code. Nicely explained and very informative!
- peter_l_downs 3y agoI came here to write this. Routing and networking is still confusing for me and all the writing about it is usually very "abstract" to me. A hands-on example like this one is really appreciated. Nice work, OP. I'll try to do it myself and follow along. EDIT: one of the only other posts about this stuff that has made much sense to me is this one from Tailscale. It contains lots of "worked out examples" that really make it clear how everything fits together. https://tailscale.com/blog/how-nat-traversal-works/ https://tailscale.com/blog/how-nat-traversal-works/
- mindslight 3y agoIME if you're digging into the finer points of netfilter, you eventually run up against the limits of published documentation and have to dig into the source code to figure some things out.
- kazinator 3y agoSince there is no port in ICMP, NAT doesn't have to deal with the problem of sending the ICMP echo reply back to the correct port. ICMP echo requests have an ID, and that's effectively the same as a source port number. Correct NAT handling of ICMP echo has to remap the ID in both directions, the same way that correct handling of UDP remaps the source port. Reason being, if the machine behind NAT is being pinged at the same time by two different hosts, and they happen to use the same request numbers, then it is ambiguous. Another possibility is not to rewrite the identifiers, but keep a list of remote machines associated with each ID. When there is a clashing ID, the list contains two or more entries (remote IP addresses). So then, when a reply is received from the machine behind the NAT gateway, the NAT chooses one of the entries in the list (say, the least recently added one) and sends the reply to that machine. Then removes the entry.
- throwawaymaths 3y agoTl;Dr (but do read it, it's very good): there's an id field in the icmp packet and netfilter is aware of icmp packets? Frames? as a "special case".
- Beinglis23 3y agoWhen a ping is sent from a device on a local network to a device on the internet, the router performing NAT rewrites the source address of the ping to its public IP address and rewrites the ID field of the ICMP packet to a unique value. When the response is received, the router uses the unique ID value to forward the response to the correct device on the local network.
- baq 3y agoTaking this thought just a tiny bit further, this is changing a stateless protocol to a stateful one.
- littlecranky67 3y agoIs or was a thing with NAT. Linux also comes with stateful modules (ip_conntrack*) to track and rewrite higher level protocols, such as FTP control connections.
- starfallg 3y agoAny NAT that is not statically mapping IP addresses or ports 1-to-1 will require connections to be tracked and hence makes it stateful on the side after the translation (usually outside). Hence you do need state syncing between firewalls in order for NAT connections to failover correctly, unless it's a statically mapped, one-on-one, one range onto another range, for example.
- devman0 3y agoThis isn't really specific to NAT either, connection tracking is required for most firewalls as well even if NAT isn't in play just to implement the most basic ALLOW related,estabalished rule even, and especially, what would normally be connectionless protocols.
- starfallg 3y agoYes, tracking the state of connections (e.g. TCP) is needed enforce rules on OSI layers 4 - 7. That's kinda the typically scenario when we think of connection tracking and stateful enforcement of rules. I was just pointing out when NAT also requires connection tracking (i.e. when the NAT table needs to be built dynamically, as opposed to statically mapped).
- zackmorris 3y agoI wonder if ping could be abused to send short messages for p2p networking over UDP without a central server to handle NAT busting. Looks like someone figured the message part out: https://stackoverflow.com/questions/31857419/how-to-send-a-message-with-ping https://stackoverflow.com/questions/31857419/how-to-send-a-m... Unfortunately ping is handled by the OS so apps on the peer IPs wouldn't be able to read the messages. I wonder if it's time to provide hooks to some of these services in user space to make true p2p under double-ended NAT possible. At least a readonly event stream or something. It just feels like the barriers preventing that are entirely artificial now.
- Bluecobra 3y agoAs IPv6 gains more and more adoption this should become less as an issue if everyone has a publicly routable IP and can avoid NAT altogether.
- riffic 3y agoping is icmp not udp
- throwawaymaths 3y agoIt's super confusing because you can use udp to read icmp packets (but not send, iirc), and i might be wrong, but i remember seeing tuts that did this!!
- throwawaymaths 3y agoGetting downvoted, so: https://stackoverflow.com/questions/13087097/how-to-get-icmp-on-udp-socket-on-unix https://stackoverflow.com/questions/13087097/how-to-get-icmp... Using a udp socket is the "classic" way of implementing ping on low privilege syystems
- yencabulator 3y agoYou can kindly ask the kernel networking stack to inform you of errors, but that is not the same as "using udp to read icmp packets".
- voxic11 3y agoYou might be interested in https://samy.pl/pwnat/ https://samy.pl/pwnat/ Specifically, when the server starts up, it begins sending fixed ICMP echo request packets to the fixed address 3.3.3.3. We expect that these packets won't be returned. Now, 3.3.3.3 is *not* a host we have any access to, nor will we end up spoofing it. Instead, when a client wants to connect, the client (which knows the server IP address) sends an ICMP Time Exceeded packet to the server. The ICMP packet includes the "original" fixed packet that the server was sending to 3.3.3.3. The packet is INSIDE the computer. This harcoded packet is built into pwnat and acts as an identifier for pwnat. Why? Well, the client is pretending to be a hop on the Internet, politely telling the server that its original "ICMP echo request" packet couldn't be delivered. Your NAT, being the gapingly open device it is, is nice enough to notice that the packet *inside* the ICMP time exceeded packet matches the packet the server sent out. Your NAT then forwards the ICMP time exceeded back to the server behind the NAT, *including* the full IP header from the client, thus allowing the server to know what the client IP address is!
- tambourine_man 3y agopwnat seems really interesting and potentially easier than my SSH tunnels. Thanks for the link
- hddqsb 3y agoTo save others some reading: This trick (ping 3.3.3.3) is used to let a server behind NAT learn the IP address of a client that is also behind NAT, without requiring any non-NAT server (such as https://ifconfig.co https://ifconfig.co). The main action of this tool is to then create a UDP tunnel between the client and server. But based on quick reading, the tool appears to assume that the NAT does not rewrite the UDP source port, so it won't work on all routers. STUN (which is used in e.g. WebRTC) implements more sophisticated techniques, and even then there are some cases where it cannot work and the only option is to use a relay (TURN). I'm pretty sure that the same issue applies to the ping 3.3.3.3 trick -- if the NAT rewrites the ping identifier (as described in the article), the trick would break.
- demandingturtle 3y ago[dead]
- cobertos 3y agoIt annoys me when I write blog posts like this, it's so hard to link to a specific line of code and have that link stay alive and useful/fresh over time. I guess if it's GitHub, you can tie it to a specific commit hash, file name, line number tuple, but if the codebase ever changes a lot its not super useful. I've also not had luck with other, less used git webviews (git.blender.org)
- xxpor 3y agoFor linux kernel code, you can use elixir, so it'll at least be linked to a specific version. You can use an LTS version if you want the code to have at least some staying power. https://elixir.bootlin.com/linux/latest/source https://elixir.bootlin.com/linux/latest/source