4 ms·
NAT as become a pillar of internet security in spite of itself. So with IPv6 as to come improvement in security. As you said the generalization of SSL/TLS as we
by HackinOut 12y ago
NAT as become a pillar of internet security in spite of itself. So with IPv6 as to come improvement in security. As you said the generalization of SSL/TLS as well as ND and IPSec that comes with IPv6 but we also need the generalization of stateful firewalls to emulate what NAT was doing for us. Ironic...
- api 12y agoNAT does little to nothing for security. NAT != firewall, and if your security depends on keeping internal IPs secret you have a problem. You can easily firewall without NAT.
- HackinOut 12y agoIn theory we agree. But in practice there is little to no firewalling in the default configuration of home routers BUT there is masquerading NAT which behave as a firewall of sorts. NAT under linux is actually done with iptables which is considered to be an "interface to the linux firewall", although it's only for practical reason, once again. Now I do agree that my point was kind of moot because it's indeed easy to firewall without NAT. I am all for IPv6 if it's done well. I especially like the idea of finally moving away from ARP Spoofing attacks thanks to Neighbor Discovery (ND).
- HackinOut 12y agoI meant IPSec, ND is functionally the same as ARP. Also IPSec support is no longer required with IPv6 so IPv6 might not really help with that.