> ipv6nat
Die in a fire while stung to death by scorpions and your eyes are eaten by spiders.
No. that is too much. You are my fellow human, i don't wish that on anyone.
> ipv6nat
Still. I hope you have to poop while stuck in a meeting.
> ipv6nat
Die in a fire while stung to death by scorpions and your eyes are eaten by spiders.
No. that is too much. You are my fellow human, i don't wish that on anyone.
> ipv6nat
Still. I hope you have to poop while stuck in a meeting.
Maybe somebody who knows more about this topic could explain it?
> One of the hopes for IPv6 was that it'd deliver us from IP address scarcity and hence the need for NAT and all the associated difficulty of NAT traversal.
My response:
> This is what I thought -- why would you neet Network Address Translation (NAT) when the address space is big enough to have everyone have an individual address? No need to traverse a router, it just becomes another hop in the chain.
If worried about privacy, you have a whole raft of identifying mechanisms to cope with before the IP address as an identifier even appears on the horizon, and there are tools to obfuscate your source address; NATing it away only makes things more complicated without a commensurate increase in privacy (worse, provides a false sense thereof).
If your router is "just a node" in between (that happens to have a monopoly on the address/nodes it's in front of), it just needs to disallow access to the endpoint that is behind it -- almost like purposefully leaving it out of the routing table. It's not like people are going to be able to guess your IPV6 address easily, and even if they could, the proper way to deal with that is to just ensure you're actually secure (and no ports are open, forwarding isn't being done at all, etc)
Am I missing something here? The way things work now, yes you can't find out what ip addresses are on the private network behind a router, but if any ports on the router are open, you know SOMETHING is responding (whether the router or something else. In the IPV6-no-nat world, the router could just forward all your traffic (pretending the router was the originating computer), and NOT allow any traffic that attempts to hit the IP at the computer past it. Someone still needs to know the internal address before they can try and access that internal computer -- and you can still stop it at the router if you wanted to...
What am I missing? I'm not a networks expert, but from my understanding of networking/nat/firewalls/security/etc, I can't see how ipv6 increases your exposure that much.
Internal servers, routers etc don't receive the external prefix and so can't be enumerated from the Internet.
The answer is not, just be given more IPv6 addresses. People who can benefit from ipv6nat probably don't have much of a choice. It's a technical tool.
Imagine getting just one IPv6 address to your LTE phone and wanting to share it with a room full of devices.
Just asked my friend who is on Verizon, when he is tethered to his phone his laptop/computer gets a full globally unique IPv6 address, every device that is tethered gets one. So it already exists.
Sure you can. Do the thing the people whose ISPs give them zero IPv6 addresses do -- use a tunnel broker. Or a VPN provider that gives you a real IPv6 address block.
Also, my ISP only gave me one ipv6 address. I'm OK with that.
Have you had to deal with it directly yourself and found something wrong?
host <-> nat <-> internet <-> nat <-> host
setup?the last time i tried, gossip would send a udp packet from something other than port 8302, so left to right would work ok, but nat would assume some state there, and treat right to left as a reply, rather than fresh connection, and stuff would get lost.
Although, it has been a couple of years and i'm probably misremembering the details.
I do remember it being hard to debug.
nat is just a bunch of glued together heuristics about how things should work. it's not fun to debug. i mean, you have 2^32 internets worth of space to assign to machines. everything is so much simpler without nat.
i dunno. maybe i'm an idiot. maybe nat is super cool, and i'm just jaded. imho it makes things very difficult. but i'll defer to the majority. whether i want to or not.