Nearly 40% of US traffic is already IPv6. 40% in Germany, 30% in Japan. I haven't heard of any massive increase in security issues caused by every device getting its own IP address.
If there is a desire for a certain device then absolutely, give it its own IP, but that is the exception.
Yes, there is!
But possibly more importantly: There is no benefit to assigning devices ambiguous addresses. It's as sensible as having all rooms in your business have "1" as their room number because you somehow have convinced yourself that that prevents people from entering your building.
I have no idea what you are trying to convey, I do not think you understood the concept.
I'm not talking about security.
When you connect some previously unconnected networks (a merger, or simply access for some sort of cooperation, or for maintenance access, or whatever), it's a nightmare with RFC1918 when address ranges overlap, which they invariably do. If you use globally unique addresses, you can be sure that there will be no problem.
When you debug something, you don't have to figure out what maps to what where in the network. When two machines talk to each other, the packets are labeled with the IP addresses of those two machines and the ports they are using, no matter where in the network you investigate. No matter who writes a log file about some operation happening in the network, all of those log entries are labeled with the same, uniquely identifying addresses.
And on the other side, there is still exactly zero benefit to using ambiguous adresses.
If you're not talking about security, maybe you should be?
I don't think anyone is suggesting that all devices be reachable by default. It's entirely reasonable and prudent to have a firewall between my home network and the world, but NAT is not strictly required for this.
I'm not suggesting that anyone suggest devices being reachable. Them having a unique identifier is bad enough.
WebRTC or any other video conferencing software wouldn't need a STUN server if all the clients were able to talk directly to each-other.
If not, using NAT doesn't add much privacy for "ongoing session".
Also, how many people share your internet connection? If it's a handful, like most household, your one in a handful, pretty small area. If that's a concern to you, you should use a VPN.
And there are other techniques than closing all incognito windows for each site ... Surely you recognize the difference between uniquely identifying a machine from that?
For day to day usage, I'm fine with a given IP on a /64. If the police came to find who ssh'ed through NAT from my ISP provided ipv4, it wouldn't take them very long to figure out my wife and kids can't even spell ssh!
I'm not talking about hiding from the police.
You know Facebook buys your purchase history from Credit Card companies, right? Disable ad blocking when you go to Facebook, you'll find out they know way more about you than explainable by ip address and email tracking (and now we now purchase history).
If you chose to use Facebook and credit cards, you have bigger privacy problems than non-NATed ipv6!
The only slight benefit it has imparted is the privacy benefit of hiding multiple devices behind a single address, but they can usually be individually profile anyway.
Also honorable mentions: The UPnP protocol & STUN servers
Server sends constant icmp pings with fixed payload to unreachable dead Internet IP. Client sends icmp time exceeded message to server containing original fixed ping subpayload, which the server NAT lets through because the payloads match as related traffic. Server then learns client IP and usual chownat udp hole punching tricks apply.
So, how does it do that?
> What is your justification for saying that access control measures are not security controls?
I am not saying that. It simply isn't an access control measure.
By rewriting the IP headers of packets as they traverse routing devices. If you’re trying to say that all NAT devices are stateless firewalls, then your point is even more contrived than I first thought.
> It simply isn't an access control measure.
Then why can’t other internet connected devices connect to my internet connected laptop? If I’d connected my laptop directly to my ISP then they would be able to. But I didn’t do that, I connected my home router to my ISP, and I connected my laptop to my home router, which is providing access control for me.
Some of them can. For example a device in the ISP network that can deliver a packet directly to your router's WAN interface can connect to your LAN devices in the absence of a firewall that would drop them.
As an example consider this:
A packet from src 10.10.10.10 to dst 192.168.1.1 arrives on the WAN interface. There are no firewall rules that match and the NAT is stateless. The router looks at the route table and sees a route for 192.168.1.0/24 on the LAN interface. It puts the packet on the LAN interface and calls it a day. Since 10.10.10.10 was a device on the same ISP network segment/broadcast domain as your router's WAN interface, it just reached a device in your NATed LAN.
On the campus LAN we used as a best practice to drop all packets that arrived on the WAN interface with a destination to the private LAN IP range, that had no entries in the state table.
Does this require an adversary who is or who compromises the ISP, possibly by tapping into the coax/fiber/etc in the last mile or by pwning the related nodes?
It wouldn't under normal circumstances, but could in the case of a misconfiguration or a malicious actor.
> Does this require an adversary who is or who compromises the ISP, possibly by tapping into the coax/fiber/etc in the last mile or by pwning the related nodes?
Most likely. I also don't consider the scenario likely, because most NATs/firewalls are stateful in this day and age and if the ISP is compromised the attacker could also use TR-069 to upgrade the firmware on the custormer's router and place a malicious implant⁰.
⓪ - http://www.pcworld.com/article/2463480/many-home-routers-sup...
Like, that you should use ULA and NAT with IPv6 so you don't lose the great security benefits of NAT. That is a completely logical conclusion if you believe that NAT provides security benefits. But it's just wrong.
And, yes, TR-069 is also a potential attack vector that you probably also should prevent in any halfway serious business context. Giving your ISP('s infrastructure) access to your internal network probably is not a good idea, no matter what the mechanism is.
How does that prevent hosts on that other network from accessing hosts on your "private network"? Like, a packet addressed to one of the hosts on your "private network" arrives at your NAT gateway from the "other network". How does the NAT rewrite the IP headers, and how does that provide access control?
> If you’re trying to say that all NAT devices are stateless firewalls, then your point is even more contrived than I first thought.
Even that would not be contrived. If removing the NAT function does not change the security functions of a router, then the NAT obviously does not provide security, at best it implies the presence of certain security functions. But even that just isn't the case.
> But I didn’t do that, I connected my home router to my ISP, and I connected my laptop to my home router, which is providing access control for me.
Then that presumably is because your home router provides access control? What does that have to do with NAT, though?
If you have a point to make, then explain what it is. If you’re just gonna keep asking more contrived questions then I’ll presume you’re simply trolling.
Your router could still firewall them all the same. NAT or no NAT. You would not need to have a firewall on each individual device.
That's something you can circumvent in certain scenarios. The technique is called "NAT hole punching".
No, it doesn't.
Relying on NAT alone for security is not a great idea.
And unfortunately, you don't even answer my questions, instead just hand-waving your way through the explanation, ignoring all the details that would show where your misunderstanding lies.
In any case, no, if you only remove NAT from your home router that also has a stateful firewall, nothing changes security-wise. It just doesn't. No need to install firewalls on all your devices or anything like that, having a firewall on your uplink router is still perfectly sufficient for that without NAT.
And if your home router really only does NAT, without a stateful firewall that prevents inbound connections, then no, your NAT-only router does not prevent inbound access to your home network.
I understand that you believe otherwise, but your belief simply is incorrect, but you won't be able to understand why if you don't dive into how a NAT gateway actually works instead of hand-waving your way through the explanation.
But now I don’t have an internet connection, because none of the devices on my home network have an internet routable IP.
But in any case, the implied assumption was that you also switch to globally routable addresses for all your devices/that we are possibly talking about IPv6, where that would be the norm anyway. The point is that actually usable internet connectivity without NAT and with a stateful firewall has exactly zero differences security-wise vs. a setup that uses NAT and a stateful firewall. That is, except for the fact that all those misconceptions that people have about NAT can make people think that their network is secure when it is not, simply because they have NAT--if you don't have NAT, you can not mistakenly believe that it protects you against inbound connections.
Or do you mean an adversary who is or who compromises the ISP, possibly by tapping into the coax/fiber/etc in the last mile or by pwning the related nodes?
I agree, apart from the claim that the home network is necessarily in a private range. For one, it's not technically necessary, you can use NAT with globally unique and globally routable addresses on the "internal" side. Obviously, people rarely do that with IPv4, but those people who promote the idea that NAT is somehow a security mechanism also use that claim to promote the idea that either IPv6 is bad because it doesn't use NAT, or that you possibly should use NAT with IPv6 ... which is where these misconceptions lead to some pretty crazy results.
> Or do you mean an adversary who is or who compromises the ISP, possibly by tapping into the coax/fiber/etc in the last mile or by pwning the related nodes?
Well, those are obviously attack vectors, and certainly not ones you should ignore, given how often there are all kinds of vulnerabilities being found in network equipment, including but not limited to the regular hard-coded passwords in Cisco equipment.
But, yes, there absolutely have even been publicly known cases of where this kind of access would have been possible, from ISPs that forgot to disable RIP on the customer-facing side of their routers, thus propagating some customer's RFC1918 routes into their access network (obviously kindof a configuration fuckup on that customer's side as well) to other ISPs that put multiple customers into a common ethernet segment/VLAN, so you could talk to your neighbour's router's WAN interface if you were a customer of the same ISP.
In any case, if you are responsible for the security of your network, your security boundary most definitely should be in your router, not somewhere in the ISP's network, where nothing of that sort is even legally guaranteed.
If there is no entry in the state table, then NAT rules are consulted to see whether a new rewrite entry should be added (such as DNAT/port forwarding rules on your home router), and if there is no matching rule either, it simply is forwarded without address rewriting.
I am sure a NAT could be configured any number of ways, though, and could probably do anything you want with such packets.
[0] https://en.m.wikipedia.org/wiki/Network_address_translation
Because the device is a router, and that is what routers do.
> Do you mean that it forwards it to itself, the NAT device addressed by the actual public IP?
No, it forwards it to whatever destination address is in the destination address field of the IP headers, because that is what IP routers do.
If it is addressed to one of the NAT device's own addresses, of course, the routing decision would deliver it to the local protocol stack instead of forwarding it, and if there was any service listening on the respective protocol/port, that service would receive the packet (or the TCP stack would respond with a SYN+ACK, or whatever), and if nothing is listening there, the IP stack should respond with either some ICMP error message or possibly a TCP reset or something.
> Wikipedia seems to disagree [0] "if the destination port number of the incoming packet is not found in the translation table, the packet is dropped or rejected because the PAT device doesn't know where to send it."
Well, maybe that is good enough for explaining to a lay audience what a NAT gateway does, because that is what home routers typically will do, because they tend to also have a stateful firewall built in, but it's pretty misleading if you are trying to understand what is actually going on.
> I am sure a NAT could be configured any number of ways, though, and could probably do anything you want with such packets.
Not really, simply by definition: The function of a NAT is the translation of addresses. A router can have many more features, of course, such as a stateful firewall, but the point is that if you only had the address translation functionality, that would not prevent inbound connections, and if you remove the address translation functionality and keep the stateful firewall, inbound connections still aren't possible. Hence, NAT has nothing to do with whether inbound connections are possible, other than that devices that have NAT functionality commonly also have a stateful firewall.
>NAT has nothing to do with whether inbound connections are possible
So how would you address a device on the private network from outside?
edit: I read your other response. Fair enough, if your ISP is sending you privately addressed packets they could get through.