4 ms·
My ISP supports ipv6, I spent a while yesterday setting it up because Hetzner VPS’s are slightly cheaper if you opt out of a v4 address so I wanted to try it ou
by djhworld 2y ago
My ISP supports ipv6, I spent a while yesterday setting it up because Hetzner VPS’s are slightly cheaper if you opt out of a v4 address so I wanted to try it out.
It all worked ok until I noticed I could access open ports on my Mac from the public internet, and then found out my router does not support blocking incoming traffic for IPV6.
Granted, it’s probably unfeasible for attackers to scan the entire space to find open ports, but I still wasn’t comfortable with leaving all my stuff exposed, so I disabled ipv6 again and came crawling back to v4.
Maybe when/if I get a better router that supports firewalling ipv6 I’ll try again.
- tonymet 2y agoI had a similar experience with my router and learned the hard way. On the positive side, I became much more careful with Windows, MacOS & UFW firewall . On the downside, I have no idea how to manage firewall settings on mobile devices with or without MDM
- k8sToGo 2y agoBut nothing changed? Technically your router is (or should be) your IPv6 firewall in this case.
- tonymet 2y agothe router vendor never tested any of the ipv6 support. ipv6 firewall was broken in the UI, and iptables commands were blocked on the CLI. so there was no ipv6 firewall (it was allow-all)
- deleted 2y ago[deleted]
- Borg3 2y agoWhy you dont run FW on your MAC? Thats not only a router problem, but your personal computer. Having on w/o firewall is terrible idea.
- stingraycharles 2y agoNot sure, depends on your threat model and how you organized your LAN. I put my “trusted” devices in a special vlan and untrusted devices (IoT) in another one. Only trusted devices can access IoT devices but not vice versa. Works pretty well. But yeah that does require a more advanced router / switch as well.
- Sophira 2y agoBack before NAT was a thing, technically-inclined people like us would seek out firewalls on our computers. Nowadays most people have them in the form of with Windows Firewall and IPTables, but many people don't really understand how to use them because they're not as necessary as they were. I would imagine most people's interactions with Windows Firewall have just been to designate which networks are private and which are public, and only then because Windows automatically asks you when you connect to a network. With IPv6, that's going to change again, and firewalls are going to become much more important once more - but It would explain why people can run without firewalls, right now. After all, currently the only things they're protecting against are from your local network, since your router is probably doing most of the external blocking already with NAT. Of course, this doesn't help IPv6 adoption at all...
- lynx23 2y agoThat is the obvious disadvantage of moving away from NAT.
- stephen_g 2y agoNAT is a crappy replacement for what can be done with a simple stateful firewall though… It kind of works for one use case (where you want to block everything or have no more than one host on a single forwarded port) but hinders or breaks literally every other use case! And then if you’re behind CGNAT you’re even more restricted!
- globular-toast 2y agoIt's not a disadvantage, it's the whole point of IPv6: each device can, once again, have it's own IP address like it was meant to be. That you probably want to run a firewall is nothing new. IPv4 and NAT have corrupted people's understanding of what the internet is.
- Sophira 2y agoThat's true, but for most people it's all they've ever known.
- globular-toast 2y agoActually I think you'll find most people just connect their devices to the internet and expect them to just work. Their mental model of the internet is probably closer to a pure IPv6 internet than nerds and engineers who have had to learn all this extra complexity required to get IPv4 to keep working.
- lynx23 2y agoFascinating. Me mentioning NAT as a positive (blocks all incoming ports) prompts people to reply with a word salad that contains "crappy" and "corrupted". Fact is, NAT is being used in almost every apartment LAN setup since, what, 30 years? Its no surprise that people grew used to the implicit port block. And therefore its no surprise that when switching to IPv6, some people will discover the hard way that they now need to do extra work. But hey, why think about it rationally, if you can throw crappy and corrupted around?
- MaKey 2y agoA router that supports IPv6 but has no firewall for it? Sounds weird to me. Which one do you use?
- djhworld 2y agoTP Link Omada ER605, V1 edition I believe the V2 models have updated firmware to support IPV6 firewalling but I made the mistake of buying the V1
- globular-toast 2y agoTurns out you've been running without a firewall this whole time! Time to get a firewall. PfSense and Opnsense are good options.