Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Dagger2
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
181.
▲
by
Dagger2
9mo ago
You don't need prefix translation to use a ULA prefix. You just configure both the ULA and the ISP-delegated GUA prefixes simultaneously.
182.
▲
by
Dagger2
9mo ago
And like I said, I can do that if you get me into a place where I can demonstrate it. If you want me to demonstrate that the lock on your safe isn't doing anything, you have to let me into the room where the safe is. Otherwise you won&
183.
▲
by
Dagger2
9mo ago
NAT doesn't protect you from 99.999% of attackers though. It doesn't do anything to incoming connections, so it actually protects you from 0% of attackers.
184.
▲
by
Dagger2
9mo ago
I'm reasonably sure I do. I've done that exact test literally half a dozen times now due to people telling me that I'm wrong, and each time I test it turns out that I'm right. What other conclusion am I supposed to come
185.
▲
by
Dagger2
9mo ago
Of course it won't do that -- when did I ever claim it would? But that's not the same behavior as a stateful firewall at all. A stateful firewall would block packets addressed to the router, or to machines behind it. NAT not trans
186.
▲
by
Dagger2
9mo ago
No, I'm not going to "admit" that, because I know full well that it won't. It's not like I'm sat here thinking "I know it does block traffic, but I'm going to lie to everyone that it won't".
187.
▲
by
Dagger2
9mo ago
How does the router rejecting a connection to the router protect the machines behind the router? That doesn't make any sense.
188.
▲
by
Dagger2
9mo ago
Right, we were talking about NAT. So how is any of that non-NAT-related stuff relevant? > Sure, but the Internet will not route packets going to RFC1918 addresses This is about RFC1918, not NAT. > So, if you're using an RFC1918 a
189.
▲
by
Dagger2
9mo ago
Again, I ask: what is NAT doing to make those internal addresses unreachable? What side effect of NAT is making it basically impossible to expose your devices? In the post I was replying to, the hosts were already unreachable (or... mos
190.
▲
by
Dagger2
9mo ago
It will reach the router, obviously. If it's a TCP SYN packet and there's a server listening on that port, you'll connect to that server. If there's no listener then you get a RST.
191.
▲
by
Dagger2
9mo ago
So? How is any of that relevant?
192.
▲
by
Dagger2
9mo ago
Whichever machine has the NAT's external IP assigned to it will accept or refuse the connection, depending on whether they have a server running on that port or not.
193.
▲
by
Dagger2
9mo ago
Sure, okay. You're using RFC1918 on the internal network, so I'll need to connect to your router's WAN interface to do it, but after that it's just a matter of doing `ip route add 192.168.1.0/24 via 58.19.1.129` and
194.
▲
by
Dagger2
9mo ago
The return packet wouldn't be NATed, because stateful NAT tracks connections and only applies NAT to packets that belong to outbound connections. Arguing over how likely this is is missing the point. If it can happen at all when you&#x
195.
▲
by
Dagger2
9mo ago
No, NAT requires state tracking , not a stateful firewall. If you want a firewall when NATing, you have to configure that separately. You can absolutely NAT without a firewall, and it won't act like one by itself.
196.
▲
by
Dagger2
9mo ago
There's always somewhere to forward a packet to. The router looks at the dest IP field in the packet header, and that's where it goes. > If the packet was going to a private RFC 1918 address, there wouldn’t be a way to get it t
197.
▲
by
Dagger2
9mo ago
It might be dropped by a firewall, but not by NAT. IP packets have a "destination IP" field in the header. The router knows where to forward packets because it reads that IP out of the header.
198.
▲
by
Dagger2
9mo ago
If you have NAT, that doesn't tell you anything about whether the router is secure. All it tells you is that outbound connections made through the router will appear to come from the router's own IP; it doesn't tell you wheth
199.
▲
by
Dagger2
9mo ago
That will only give the NTP server the IP you use for outbound connections. If you use privacy extensions, they'll get a temporary address. If you don't configure your firewall to allow inbound connections to the temporary address
200.
▲
by
Dagger2
9mo ago
It's not isomorphic to a firewall, because it doesn't have default-deny semantics for incoming connections. Think about it for a second. These NAT implementations change the apparent source IP of your outbound connections. How doe
201.
▲
by
Dagger2
9mo ago
The point was that turning NAT on or off doesn't affect whether your LAN is reachable or not. NAT just edits the source address of your outbound connections. It's irrelevant to how your inbound connections behave. > Correction:
202.
▲
by
Dagger2
9mo ago
No, it doesn't imply that. Let's say your LAN is using 192.0.2.0/24, and your router has 203.0.113.42 on its WAN interface. With NAT, outbound connections from 192.0.2.x will appear to be coming from 203.0.113.42 -- in your w
203.
▲
by
Dagger2
9mo ago
It doesn't though. NAT edits your outbound connections to appear to come from the router's IP; it doesn't do anything to make inbound connections harder.
204.
▲
by
Dagger2
9mo ago
> NAT provides security because normally it disallows external actors on the outside from accessing resources on the inside side. No... it doesn't do that. NAT edits your packets so that your outbound connections appear to come from
205.
▲
by
Dagger2
9mo ago
NAT: iptables -A POSTROUTING -o wan0 -j MASQUERADE Firewall: iptables -A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT iptables -A FORWARD -m state --state INVALID -j DROP iptables -A FORWARD -i lan0 -j ACCEP
206.
▲
by
Dagger2
9mo ago
That whole section is talking about outbound connections: When an internal endpoint opens an outgoing session through a NAT, the NAT assigns a filtering rule for the mapping between an internal IP:port (X:x) and external IP:
207.
▲
by
Dagger2
9mo ago
No, NAT only affects which IP your connections appear to be coming from. It doesn't change which IPs your devices actually have. The person I replied to said that they only get a single v6 address. If that's true, it doesn't
208.
▲
by
Dagger2
9mo ago
You should read my other comments on this post. I've attempted, multiple times (but apparently without much success) to make the point that NAT is not a security feature because it does not, without a firewall, protect against an attac
209.
▲
by
Dagger2
9mo ago
That's the type of NAT I've been talking about the entire time. It doesn't do anything to inbound connections unless you explicitly tell it to. Connections to the router's IP address go to the router, but you need to con
210.
▲
by
Dagger2
9mo ago
It's not, because in the real world NAT only affects your outbound connections. That means that turning it off only changes the behavior of outbound connections, not inbound ones. Any inbound connection that would have worked before yo
More ›