NAT has been so successful, that IPv6 is shocking to users who cannot even fathom why public traffic is being introduced to what was 'supposed' to be a private network.
NAT has been so successful, that IPv6 is shocking to users who cannot even fathom why public traffic is being introduced to what was 'supposed' to be a private network.
This leads to some very peculiar traffic being routed around. For example, some kind of Logitech gaming driver is broadcasting a constant of packets with someone's PC stats to my publically reachable desktop/server/laptop, because the software thinks it runs behind a trusted NAT. There's also a HUGE amount of devices you can connect to if you open the Windows network overview because everyone clicked "home network" when Windows asked them what kind of network eduroam is supposed to be.
It's funny how scared people are when they realise they're not behind any strict firewall. They all know they shouldn't be disabling the firewall on their devices anyway, or so they claim, but this method of networking still instills fear into people as if NAT is a security measure (NAT slipstreaming works, NAT is not a firewall!)
This is a false meme right up there with "docker is not a security boundary".
If the router is configured as both NAT (SNAT) and firewall, it will drop such packet as not associated with any existing flow, but if it is just configured as SNAT, then such packet would be just forwarded inside unmodified.
(Also there is no requirement that you use RFC-1918 addresses behind NAT.)
NAT was never designed to be a security boundary and should not be considered one. It's only a matter of time until the next NAT slipstreaming attack is discovered. That doesn't mean your computer is in some kind of immediate danger or that you should cut your internet cable right now, of course. It's just good to know what does and what doesn't work when it comes to your network security and why IPv6 changes very little.
In fact, I'd argue that most IPv6 routers are actually more secure than IPv4 NAT because incoming traffic will never be translated as if it came from your router like some NAT implementations do, and incoming traffic is usually always blocked. The lack of a need for parsing and interpreting network packets makes your firewall a lot easier to reason about.
Docker is not designed as a security boundary, but it does provide some security functionality if used correctly that would otherwise be a pain. Sticking something in a docker container and just running it as root is dangerous, but Docker makes it easy to apply strict, complex security measures, which its security bonus comes from.
NAT is the opposite, it's supposed to work like magic. That's why network protocols like UPnP were invented, not to automate firewall management, but to make application use transparent to the user.
After reading up about public IP addresses I realised that my (Dutch) ISP has also provided me a public IP... and that the Netherlands has a lot more IP addresses per capita than most European countries.[1]
1. https://www.ripe.net/participate/meetings/roundtable/january...
The danger associated with public IPs is not that high as long as you use software that binds to localhost instead of 0.0.0.0 for network services or use a firewall on your PC. The problem is that many software developers don't expect end user devices to be reachable from the internet so security practices are sometimes lax.
The Windows Messenger Service alerts that you could make pop up with a simple command-line incantation, you mean?
> It was such a common thing, and the only fix was to turn off the service altogether in Windows XP.
What? Nooo, don't do that! This meant no more cool "There, almost done. Lunch in five? /CRC" messages on your colleagues' screens.
NET SEND * "You are broadcasting an IP address!"Each had their own PC and direct, symmetric 100Mbit/s access to the Internet with public IP and no filters whatsoever.