The funny thing about IPv6 is that you see a lot of curmudgeonly rhetoric about it here and elsewhere, but once you dig in a little, it snaps and you think "hey, this really makes sense!" And then you wonder why others are grumbling so much.
The main thing to do is to stop thinking about IPv4. Just put the IPv4 concepts aside and start thinking about it as if IPv6 just showed up on the scene as the L3 protocol.
Forget about crusty concepts like NAT, because NAT was a kludge anyway. Just think about the big address space. Understand that firewalls examine traffic going from one side to the other and that NAT is not part of that equation (people frequently argue that NAT is valuable for network security - nonsense).
Just start fresh with it and resist the urge to hug your old IPv4 teddy bear.
Most of the devices on my home network should never be routable from the Internet. Without NAT, they suddenly are, and I have to go out of my way to configure a firewall (either on the device or an intermediary appliance) just to get back to that baseline. That is more configuration to get right and is a worse experience than when they were just impossible routes under NAT. So, I get it, NAT was not "designed" with security as a primary consideration, but when thousands of Grandma's printers are suddenly pwn'd because their 2.6.x kernels wind up answering traffic from the public Internet, it's quite devilish to say "gosh, well, they should never have relied on things continuing to work the way they always have, because it was philosophically never meant to be that way."
It's quite possible I'm missing something (because I haven't bothered to learn much about v6 yet) and consumer routers are smart enough to drop unsolicited traffic to "private" addresses (however that is determined). If that's the case I cede a little.
If routers can enable NAT by default, they have a stateful firewall by default. The printer won't be on the internet unless you punch a hole in NAT, it won't be on the internet unless you punch a hole in that firewall. You can have that firewall without NAT.
With a firewall then I have no idea. I guess you have to check on the router, and maybe do some kind of online test? Can't imagine grandma doing that.
I do think a firewall is a cleaner solution but it's definitely true that NAT is way more foolproof.
I wonder what can be done to educate people that NAT != Firewall, and that all IPv6 home routers also include a default-deny firewall?
It seems like the concept of NAT=>Secure and also RFC1918=>Secure isjust embedded so deeply in people's consciousness that they assume !NAT=>!Secure.
That's not what I said at all. Read it again. NAT is a more foolproof kind of security.
> NAT != Firewall
NAT is effectively a pretty good firewall isn't it? How would you access a device behind NAT?
NAT only applies to outbound connections. It does nothing for inbound ones, and thus doesn't provide any firewalling functionality.
If I'm wrong I'd like to know, but you haven't provided any evidence that I'm not!
No matter what, the packets have to traverse multiple hops, including the residential router that you've currently got.
It's not like the IPv6 packets magically "hop over" the router and skip it, they're processed the same way, except for one difference: the destination addresses are not altered in the process.
Note that IPv4 is supposed to work the same way. Back in the good old days, you'd get a public routable address even for home connections. Every router in the path to your PC would not modify the destination address.[1]
The RFC1918 address space was formalized in 1996, but I had an Internet connection as far back as 1992, and the "IPv4 Internet as we know it" materialised back in the '82-'83 era, and HTML in 1990.
This means that NAT is a "new thing", a workaround for the problem of address space exhaustion only. It wasn't a solution for security. Firewalls existed before, firewalls existed after, and generally worked the same with or without NAT.
Without NAT, my home Internet is still secure. Inbound connections are blocked by default. If I permit an inbound connection, it takes the same path through the same devices. All of the processing is the same, except for not having a single 32-bit address[2] rewritten in the packet headers.
Having my internal network devices being 1:1 addressable from the outside doesn't mean accessible. The default-deny firewall is in place either way, NAT or no NAT.
PS: If you can afford the USD 40 per public IPv4 address, and your ISP is willing to sell you a /C or whatever, you can totally have the non-NAT "experience" with IPv4 on your home network! It'll work the same as IPv6, with directly addressable devices with public-routable addresses. The firewall in your router will work the same! You'll still be just as protected.
[1] THIS is where the perception that NAT is required for security came from! In the 90s, most endpoints did not have a built in default-deny firewall, especially Windows. Most people dialed into the Internet via a modem and got a public IP on their PC, exposing them to attackers without any firewalls in the way (software or hardware). When people were forced to move to NAT, as a side-effect they also got a firewall on their network for the first time. Now? Every residential Internet router has a firewall, as does every endpoint on top of that.
[2] Okay, the address, the port, TTL, and the checksum.
A firewall will block any incoming connections unless explicitly allowed.
Basically the NAT happens to overlap a bit the job of the firewall as a side effect of how it works. In practice NAT and firewall are implemented by the same system. For example look at iptables on Linux.
Copy-pasting from a previous discussion a little while ago:
---
IPv4+NAT does not remove any more classes of problems than IPv6+firewall. Firewalls under IPv6 work exactly the same way as they do with IPv4.
An IP connection is started from the 'inside' to the 'outside', and the source-destination tuple is recorded. When an 'outside' packet arrives the firewall checks its parameters to see if it corresponds with an existing connection, and if it does it passes it through. If the parameters do not correspond with anything in the firewall's table(s) it assumes that someone is trying to create a new connection, which is generally not allowed by default, and therefore drops it.
The main difference is that with IPv4 and NAT the original (RFC 1918?) source address and port are changed to something corresponding to the 'outside' interface of the firewall.
With IPv6 the address/port rewriting is not done.† Only state tables are updated and checked.
New connections are not allowed past the firewall towards the inside with either protocol, and only replies to connections opened from the inside are passed through.‡
There's no magical security behind NAT: tuples and packet flags are read, looked up in a state table, allowed or not depending on either firewall rule or state presence.
The security comes from the state checking.
[…]
I have a printer with an IPv6 stack. I also have IPv6 addresses from my ISP. Yet somehow my Asus AC-68U prevents the public Internet from reaching my printer.
† It is possible to have private IPv6 addresses using ULA, and then the router/firewall uses NPTv6 to rewrite the prefix (leaving the /64 interface component alone).
‡ Just like with IPv4 (NAT), to allow unsolicited 'new' connections in you have to do do firewall hole punching with (e.g.) UPNP. But by default things are blocked.
---
* https://news.ycombinator.com/item?id=28390634
IPv6 firewall on my Asus:
That's exactly the problem with IPv6 and why its struggle to get traction as a replacement for IPv4. It's the Gnome3 of networking protocols.
The core concepts of IPv6 isn't the hard part. The hard part is fighting issues like why suddenly you can't resolve anything[1], why your Android device isn't resolving this host when IPv6 is enabled on your router[2] or how the hell you're supposed to write firewall rules when your prefix changes and the firewall only supports static IPs[3].
[1]: Router hands out its global IPv6 address as DNS server to clients and router just got a new prefix. Bonus points to pfSense for not having a way to disable this...
[2]: Android refuses to use supplied IPv4 DNS server if it gets an IPv6 address...
[3]: pfSense couldn't until mere months ago: https://redmine.pfsense.org/issues/6626