An Opinion in Defence of NATs
potaroo.net
potaroo.net
The key word here is "appear". There are two main factors which maintain this appearance:
1. Any technology which does not play well with NAT is guaranteed to be DOA with respect to the consumer market, so few resources get spent on them. This is a classic chicken and egg problem.
2. A tremendous ongoing effort by network device and application developers to implement whatever kludges are necessary to keep their products working with NAT.
Both of these costs are largely hidden from consumers, so of course there is little outcry about them. That doesn't mean the world wouldn't be much better off if NAT went away.
However, as you say - a lot of time was lost making things work that should not be too tricky.
I wonder if the centralized internet we have today - where information sharing between people usually involves large server farms run by big corporations - would have happened without NAT. Maybe, without NAT, people would have just stuck with the old way of doing things. Why involve a third party when you can just connect directly?
NAT made it easy for the centralized services to take over. When NAT came, all the good p2p apps of the 90s and early 00s either ceased working completely, or at least became unreliable (applications were then trying all kinds of tricks for NAT traversal, but it was often slow or failed). The generally overly complex configuration for port-forwarding on routers didn't help either - if you ever tried to walk someone through setting it up back then via chat or telephone, you'll know what I mean...
With a clean slate like that, with the vacuum that was created, the centralized services could just walk in. Simply because they worked. Together with all the user tracking and surveillance that came with it.
There's something wrong with the internet when two devices that want to talk to each other need to trick the NAT with a hole-punching server before they can communicate.
When you need an 3rd-party provider to "get in" the internet. FTFY.
Someone needs to run the trunk lines, and you will always need to talk to these people to get yourself connected.
And if you have multiple devices that use the same port you can open that port on each one. No need for an external server to look up what port the device can be reached on.
But I think the article is ignorant of the real problems that NAT traversal cause in many situations. Yes, we have a system that largely works. But that in itself doesn't prove the current system is equivalent to the IPv6 alternative. In fact, there are good reasons to believe an IPv6 world will make the Internet significantly more dynamic and peer-to-peer friendly.
Now how does that lot get to and from the internet? For a PC to get to a web server it has to use the correct "local" address to get to the other end via the relevant ISP connection. However the PC can't know which internet connections are working without some form of routing protocol telling it what is going on upstream. So all my PCs, servers, printers and even IP cameras need to be routers rather than simply having a default gateway!
As you can probably guess, that is not what I will actually do when I flick the IPv6 switch for real at work (home has been dual stack with one link for several years now).
My current plan is ULA (a bit like IPv4 RFC 1918 - 192.168., 172.16. 10.) with Network Prefix Translation. That way my DNS servers, AD DCs (I think of those merely as KDCs but apparently they do other jobs) and other handy things wont renumber themselves every time a link goes down. The real joy of all this is I'll also get to manage two lots of firewall rules per VLAN. Can you imagine how busy a DNS server would get in the event of a flapping internet connection if it had to do dynamic DNS updates?
Don't get hung up over NAT, the world of fully tooled up IPv6 is going to be far more "interesting", especially when you are not a big institution with a huge budget but want a bit more connectivity than one ISP connection provides.
To put it bluntly, people like you are the reason why the IETF resisted standardizing any form of NAT for IPv6. They know that if there's a half-assed solution to a problem which makes the immediate pain go away but imposes negative externalities on the network as a whole, lots of people are going to take it.
However PI implies an additional internet routing entry (BGP) and of course that implies routing fragmentation. One of the goals of IPv6 was routing simplicity.
To reply, rather bluntly to people like you, I am a sysadmin and a business owner who does not have an unlimited budget. I almost certainly have more experience with IPv6 than you, judging by your remarks. I am not combative by nature but please tell me what is the most effective way in your opinion of making best use of IPv6 with multiple links to the internet.
Yes, if everyone used PI it would bloat the routing table, but the vast majority of businesses have no good reason to use PI. Having five providers makes you a special case, one where PI is clearly justified.
IPv6 also makes it difficult to plug and play new devices and install new networks. Example: The business needs to separate their Office PCs and their payment terminals (PCI DSS). Easiest way is to plug a firewall behind the existing LAN, and hang the terminals off the new firewall. You can't do that with IPv6 without the original router supporting DHCP6-PD, which it likely won't; or the ISP hasn't routed a large enough subnet to it to delegate smaller chunks. This is a mom and pop business that knows next to nothing about IT and shouldn't be penalised for that.
In an ideal world where everyone has full knowledge of their systems and networks and can work with their providers to precisely accommodate their networking needs, IPv6 would work. I don't believe with the limited time, resources, and money we have that it is possible.
Ultimately it's down to who caves in first. If the ideal solution requires £$€3000/yr more than another solution, and the other solution solves all the issues the business cares about, why would they spend the money to remove NAT?
Well, if you want to ignore the fact that IPv6 can utilize the same port combinations as IPv4, then your math works. If you actually compare apples to apples though, it's fundamentally flawed.
That said, I happen to be a fan of NAT - just not for the reasons outlined here.
FTFY
Now given that the smallest subnet in IPv6 is /64 then you are unlikely to need to bother with port mapping as well. I will grant you that putting 65000 odd IPs on a system may not be the most efficient way of doing things. Anyway at least you get a choice in the matter. Many problems with, for example, VoIP are fixed with symmetric NAT which falls out of this scheme right away.
My problem with IPv6 is how you get "tied" to your initial ISP in an intimate way due to getting all your IP addressing from them. SLAAC does go a long way to fix this but it is a little like ISP assigned email addresses stopping people from moving away.
Also, consider what happens when you have multiple internet connections perhaps for redundancy/backup. You actually need NPT to get that to work in any meaningful way unless you pay for private address space and take a deep dive into BGP etc.
At a lower layer, you can get a similar effect with VRRP/CARP. For example I have two pfSense (FreeBSD) routers at work that present an additional set of "virtual" IPs in a master/slave HA setup. I can reboot or power off either of them and the virtual addresses will move to the other if needed, along with all state entries - handy for system updates without loss of service.
I also have a couple of HA Proxy systems that are NATed through those virtual addresses. Those proxies have multiple backends that actually serve content.
So: 1 IP -> two firewall/routers -> two HA proxies -> many app servers.
I can take out any one bit of each stage and still maintain service. Actually its a bit more complex than that due to virtualisation.
If I only had one internet connection then that would be fine but I have five.
I think I've given a flavour here and in other comments I've left around here that IPv6 isn't too hard and doing away with NAT is actually a good thing but IPv6 is seriously rubbish when it comes to multi-link (ISP) and rapidly becomes seriously hard and that actually a form of NAT in the form of ULA and NPT is the "fix". ULA is analogous to say 192.168.0 and NPT makes one IPv6 prefix map to another one (which could include ULA) - that's NAT by another name. You also have port mapping as well - just like IPv4 NAT.
I could buy what's know as PI address space at something like £3000 per year and get that routed instead - I would then have multiple links for redundancy but not for bandwidth utilisation and besides I would not get my four FTTC (VDSL) providers to do it anyway.
IPv6 does not address the whole internet connectivity thing across the whole stack - it is only concerned with logical addressing at one point and fixes only a few problems. It does fix address exhaustion very nicely despite what armchair commentators state. It will fix the rapid proliferation of routing table entries on the global internet, except that PI addresses will screw that up royally. It does do away with NAT, which really is a good thing. Except multi link screws that up. SLAAC makes setting up a network really easy. Except multi link screws that up. DHCPv6 - the darling of "enterprise" anally retentives that don't get it will probably screw something else up.
Recently I decided to put a Lets Encrypt cert on my laptop. Now I do have a block of eight IPv4 addresses at home but all of them (the six usable) were already mapped on port 80 and 443/tcp to various things. I put in a AAAA record on my DNS server (and an inbound firewall rule) and got a cert. Most people have a single static IPv4 if they are lucky or a dynamic one which will change (OK - dynamic DNS) However, if you have IPv6 at the ISP, you will normally get the same prefix. At worse you get a /64, better a /56 and the intended allowance of all was /48. At worse you have billions of globally routable addresses.
Security risk being globally routable? meh! every single home router I know of (IPv4 and/or 6) defaults to deny inbound. They all have a firewall that applies that policy. NAT is not a firewall and it does not give you any real, tangible, additional security. Actually, many consumer router/firewalls try to be helpful by providing UPnP support enabled out of the box - to make your gaming/music streaming/whatever experience easy.
Hmmm, I'm really starting to waffle here - sorry - but I think if you have got this far, you might have an idea that NAT is the least of your worries.
Exactly the same as in IPv4. This also applies to multihoming.
For example you want to run your own email system with webmail and Nextcloud for file synchronisation. You want to secure them both with TLS. You have a single static IPv4 address (if you are lucky, otherwise you have to use a dynamic DNS service.
So you have two things that both want to use 443/tcp on the same "external" IP address.
Options:
* Put one of them on a non standard port eg 8443 - rubbish but works (unless the app assumes and enforces 443 - some do)
* Put in a proxy, eg HA Proxy - cool! it can be used to fix up TLS crapness and get you that A+ score on the SSL labs test but it can be tricky to set up
* Get more IPv4 address space - RLY (for most of the world)?
* IPv6 - generally statically assigned and you have billions of globally routable addresses to play with
NAT creates a limitation inbound - in general outbound is fine unless you want to use SIP n RTP or FTP, in which case you may have to become a network engineer unless your router's ALGs work out of the box, if it has them, if they work correctly, if they don't actually break things. NAT adds a lot of complexity but it has become the norm.
There is no tool yet available but with IPv6 numbers going up it just matter of time before it become a necessity.
Do you actually have any experience of IPv6?
Please read up on IPv6 before posting - it's been available for 19 years or so now. I'll grant you that a lot of the write ups on it are absolute bollocks but you should be able to find a reasonably good treatise somewhere. Look for names that you trust.
Like in the old days, when scanning the entire IPv4 was seen unfeasible due to the high latency low speed internet but those numbers are going up each day on both network speeds and going down for latency by the time we have 100% IPv6 deployments it will be fast enough. Mirai 2.0 in the making thanks to net-engies pushing IPv6 hard.
https://www.google.com/amp/s/arstechnica.com/information-tec...
However, disabling something that you don't understand and is enabled by default on a system for which it probably wont work fully anyway isn't too bad an approach.
That said, I will be using IPv6 to route around the sheer naffness of 192.168.0|1 at customer sites. Quite a few businesses have a networking legacy, shall we say. I currently use OpenVPN and a 1:1 NAT (see https://doc.pfsense.org/index.php/OpenVPN_NAT_subnets_with_s...) With IPv6 and a little DNS work I can make routing work again - smashing!
So do routers, but the extent of their manipulation is merely to ensure a packet reaches its desired destination. NATs act more aggressively.
That is the sort of mentality that has always toxified this whole matter. This is an engineering issue. NAT wasn't created to enslave anyone.
The author isn't arguing in favor of NAT. Only that NAT is much more than an address scarcity kludge and is actually an expression of real requirements that neither IPv4 and IPv6 can address well sans NAT. The concept of a fixed, routable, global address number is possibly naive considering mobile hosts, privacy, multi-homing, security and other issues. Maximum liberty may be to decouple routing from any particular routing number scheme.
It's impossible to discuss any of this rationally; the anti-NAT camp has its dogma and can't be engaged. Two decades of this myopia headed into three...
With IPv6, users can put their devices out on the wild-west open internet without needing any kind of NAT or firewall for protection.
The large number of open access points in the wild points out the danger here -- most consumers know nothing about network security and will set up their home network with dozens of IoT devices all on the public internet behind their ISP's non-firewalling router because they can, and everything works.
They'll do whatever makes support easiest until they are forced to do otherwise by regulation or bad press.
Denying the ISPs trivial inspection into the structure of home networks, OTOH, is a major benefit and maybe a concrete downside to adopting IPv6 locally.
Everyone seems to misunderstand that I am not advocating for what should be/should have been, but instead providing the benefits of how things played out given the reality of the world.
Abstract:
pwnat, pronounced "poe-nat", is a tool that allows any
number of clients behind NATs to communicate with a
server behind a separate NAT with *no* port forwarding
*no* DMZ setup, and *no* 3rd party involvement. The server
does not need to know anything about the clients trying
to connect.
(0) https://samy.pl/pwnat/In other words, get sent to a domain that initiates the knock sequence. Other machine in waiting responds, and NAT traversal takes over, to any machines inside NAT.
The only real question is how much code is actually required to start this.
So yes, it looks like some sort of further in-depth hackery would be required, or planting some sort of SBC in the building on the network. It's quite a bit more infeasible than I had initially thought.