4 ms·
Even with IPv6 you still might have stateful firewalls allowing only for outbound connection at both ends (e.g. a CPE a.k.a. “WiFi router”) and to establish com
by TuxPowered 7mo ago
Even with IPv6 you still might have stateful firewalls allowing only for outbound connection at both ends (e.g. a CPE a.k.a. “WiFi router”) and to establish communication you’d need to punch a hole in those firewalls.
- brewmarche 7mo agoThat’s true we won’t get rid of hole-punching with IPv6. But at least it will get rid of TURN.
- gzread 7mo agoThe hole punching is so much simpler because you don't need to guess your own address and port - you just know it
- ranger_danger 7mo agoDoesn't that assume that your machine is given its own world-routable (and unfiltered) v6 address?
- gzread 7mo agoThat's how it works in ipv6. If your network doesn't give you an address, it's broken. We do not assume unfiltered since we are talking about hole punching.
- brewmarche 7mo agoIPv6 still allows proper NAT (prefix translation), but even then finding your global address wouldn’t need TURN, just STUN, actually not even that, just a service like “What’s My IP.”
- gzread 7mo agoIt does allow it in the sense that it's possible, and even useful in some scenarios, but then you're on a weird experimental network and not a normal one.
- brewmarche 7mo agoYes, you are right, quite literally, as RFC 6296 is marked ‘experimental.’
- majorchord 7mo agoHow will it get rid of TURN? Can't IPv6 addresses still be firewalled by your carrier like they do already for IPv4?
- brewmarche 7mo agoI thought TURN was for symmetrical PAT, not for proper NAT (which just needs STUN for address determination) or full/restricted cone PATs (which need STUN for address and port determination, and then, in case of restricted cone, performs a hole punch). Standard-conforming IPv6 at most allows prefix translation (i.e., proper NAT, not PAT), which wouldn’t need it.