5 ms·
> ok, but why? Because NAT breaks a lot of services. > Is that going to change with ipv6? Yes. You no longer need NAT, so port negotiation is much easier (ev
by jjjjmoney 3y ago
> ok, but why?
Because NAT breaks a lot of services.
> Is that going to change with ipv6?
Yes. You no longer need NAT, so port negotiation is much easier (even when inbound is blocked)
> Are you _really_ just going to allow random traffic into your network?
Common misconception! Even without NAT, the router can have port/traffic policies. There's just no address translation happening.
There's a lot of good stuff about IPv6, and I would encourage more people to learn about it and try it out.
- ULAs can act like static internal LAN addresses
- A "strong" NAT is easier to avoid and no longer breaks connections to things that are sensitive like gaming consoles
- Randomized, temporary IPv6 public addresses are a nice feature, and mostly turned on by default
- The biggest one is people seem to equate NAT = router/firewall. This is absolutely not the case, and they are distinctly different. You can absolutely have a router/firewall without NAT!
- CG-NAT is becoming more popular due to the lack of IPv4 addresses, and I hate everything about that.
- You can even run a NAT64 to provide IPv4 access to your IPv6-only devices
- exabrial 3y ago[flagged]
- jjjjmoney 3y agoYou might not but NAT has many different flavors, and many people don't get to choose which is used on their network. https://serverfault.com/questions/208522/what-is-strict-moderate-and-open-nat https://serverfault.com/questions/208522/what-is-strict-mode... This can particularly play havoc with sensitive protocols like STUN. I believe many game consoles make use of this when in multiplayer matches. I have personally run into this using OpenBSD's pf, but I'm fortunate enough to have access and the known-how to fix it for my consoles. It's one of those things that's fine until you run into "edge cases," and unfortunately NAT configurations can introduce a lot of undefined behavior from the user perspective.
- lxgr 3y agoVoIP. Two peers, each behind a CG-NAT (or other symmetric NAT), depend on somebody running a relay in order to be able to communicate. This makes it very expensive (and sometimes risky, since unrestricted relays can be used for all kinds of nefarious things too) to deploy any new VoIP service. I'd call that "broken by NAT". > everything works right now. Yes, everything that works right now works right now, but that's a tautology, not proof of anything. The things that don't exist because they wouldn't work in a predominately NATted world don't work, because we live in a predominately NATted world.
- exabrial 3y agoDoesn't that present a privacy issue? One can _casually_ infer who you are talking to merely by examining network traffic.
- lxgr 3y agoYou're always free to use a relay for privacy reasons. Many common VoIP solutions allow just that. IPv6 (or more generally, the absence of NAPT) just changes the switch label from "try [not] to use direct connections, unless NAT gets in the way" to "[always|never] use direct connections". In other words, it cleanly separates the two distinct concerns of privacy and connection topology. I think that's a good thing.
- hristov 3y agoI remember having to do a lot of port forwarding to get certain things to work behind a nat. Certainly doable but beyond the competence of a non-expert.
- supriyo-biswas 3y agoAnd that's entirely out of your control if your ISP is doing the NATing.
- jjjjmoney 3y agoNot even your ISP - it could be university, business, shared internet for apartments, etc.
- saltminer 3y agoAnd sometimes, entire nations. Qatar used to share a single IPv4 address, which I found out when news articles started reporting that the entire country could no longer edit Wikipedia without an account, which at the time, was also restricted if your IP was banned from anonymous edits. If you didn't create an account prior to the ban, you were completely blocked from editing. https://en.wikipedia.org/wiki/User:82.148.97.69 https://en.wikipedia.org/wiki/User:82.148.97.69 https://techcrunch.com/2007/01/01/wikipedia-bans-qatar/ https://techcrunch.com/2007/01/01/wikipedia-bans-qatar/
- jjjjmoney 3y agoThis isn't entirely about static port-forwarding. As others have pointed out, STUN, VoIP, PASV, etc rely on deterministic NAT behavior to work. That is not always guaranteed, and often out of your control.
- supriyo-biswas 3y agoThe existence of PASV mode and STUN/TURN is because the end-to-end addressibility of the IP protocol was broken with CGNAT. Furthermore, in populous countries like India, ISPs enforce extremely aggressive timeouts on IPv4 connections in order to keep the 5-tuples on the egress side of things manageable. Trying to make a request that takes 10 seconds to process (like a user requesting a report consisting of multiple SQL queries)? You get a connection reset. I must also must point out the HN guidelines because you bring a combative tone to this entire conversation which is not helping it. > Be kind. Don't be snarky. Converse curiously; don't cross-examine.
- LegionMammal978 3y ago> The existence of PASV mode and STUN/TURN is because the end-to-end addressibility of the IP protocol was broken with CGNAT. But isn't all that still necessary as long as the typical user isn't going to be opening their firewall on those ports to arbitrary incoming connections? That's the whole point here.
- lxgr 3y agoSTUN (or something similar) yes (since you'll need to coordinate outbound traffic which creates the appropriate inbound rules), TURN no (since STUN will always succeed with stateful but non-translating firewalls). And STUN scales almost infinitely better than TURN.
- deleted 3y ago[deleted]
- phpisthebest 3y ago>> The biggest one is people seem to equate NAT = router/firewall. This is absolutely not the case, I dont think anyone equate that, but IPv6 proponents refuse to recognize that decades and decades, especially in home users, and SMB space, NAT was a layer of the security model, often times one of the biggest Right or wrong is irrelevant, that is/was the reality Just tossing IPv6 as a replacement for ipv4 with out factoring that in while simply screaming into the void "NAT IS NOT A FIREWALL" will be of little comfort to the elderly retiree that has their home computer ransomwared, or the small business that is put under due to a cyber attack because the ipv6 address was strait on the public internet
- bluepizza 3y agoHome router NAT "layer of security" is equivalent to closing all ports. If an IPv6 home router closes all ports by default, then the same level of security is achieved.
- hot_gril 3y agoThat's a big "if." > Randomized, temporary IPv6 public addresses are a nice feature, and mostly turned on by default I really do not want this.
- devman0 3y agoIt isn't a big if, it is literally the same connection tracking stack except without the address and port mapping. If you take away the mapping the tracking doesn't go away. Inbound traffic still needs to match to to a session created by outbound traffic.
- hot_gril 3y agoYes, and every router has to do it properly by default, which so far they haven't really been. NAT is a lot harder to do wrong, cause the local IPs aren't even addressible.
- adriancr 3y ago> Yes. You no longer need NAT, so port negotiation is much easier (even when inbound is blocked) In practice someone can still configure NAT on IPv6 same as on IPv4 at least on Linux and some vendors, even if IETF resists standardizing it. https://blogs.infoblox.com/ipv6-coe/you-thought-there-was-no-nat-for-ipv6-but-nat-still-exists/ https://blogs.infoblox.com/ipv6-coe/you-thought-there-was-no... So you might still see CGNAT if someone is determined to configure it.
- jjjjmoney 3y agoYes this is absolutely possible, but I do like that IPv6 doesn't mandate NAT.