NAT still exists for IPv6
blogs.infoblox.com
blogs.infoblox.com
This doesn't matter with IPv4, because all my internal IPv4 addresses are NATed. But with IPv6, although each device on the network can receive a globally routable IPv6 address, the prefix keeps changing, and so the address keeps changing. This makes internal networking a nightmare, since the address of my devices is not under my control.
I don't use NPT, but it would fix the problem, so people are going to continue using it until dynamic prefixes go away. Which will probably be never.
Wouldn't this be like static bluetooth IDs, where you could be tracked wherever you go? I imagine that's a rare desire, amongst the internet population.
I could see requesting static IPs for particular devices, like you used to be able to do.
Talking about IPv4 with NAT, a "consumer" with zero server-hosting needs could get away with a changing public IP. Someone with any kind of server needs, like hosting their own Internet-accessible IoT portal, personal VPN, website, game server, etc. would want a stable public IP address.
Yeah, that may lead to tracking, but it's the status quo, I suppose is the point.
In case it isn't known, IPv6 has so many addresses and is designed in such a way, that it is expected each "network" (think home network) would be given a network prefix of 56 or 60 bits. The "host" portion of an IPv6 address is the final 64 bits of the address. Therefore, each network an ISP issues to a client should have room for something between 16 and 256 subnetworks, each with effectively unlimited client address space.
This is pretty horrific. You could investigate ULA which is a bit like RFC1918 addresses for IPv6. You could attach ULA addresses to a few devices such as a local DNS server, printers and the like.
NPT would enable you to route your ULA addressed gear to the internets if they don't have a globally routable address.
One convenient thing about ULA+NPTv6 is that, unlike IPv4 NAT, is that an external IPv6 address is basically 1:1 'equivalent' to an internal IPv6 address. The NPTv6 is stateless so that, firewall rules allowing, a connection can come right in without all sorts of contortions for port mapping.
Most (residential) gateways by default block incoming requests unless they're a reply to a previous outgoing connection. I know I can ping6 the iMac I'm typing this on, but attempts to (e.g.) SSH in are blocked by default.
When you do a IPv4 "pinhole" port map you get precisely one mapping and it will timeout eventually, which can lead to all sorts of exciting debugging opportunities.
IPv4 does have 1:1 NAT but there are so few IPs so whilst I have a /24, 2 x /28 and 2 x /29 to play with and others, I doubt most do.
NPTv6 maps an entire address space from A->B and is actually not designed to deal with NATv4 anyway. It is for outbound connections.
This is implementation specific: on my Asus I can specify to allow in all ports from in via a NPTv6-ULA hole, a port range, or even a single port.
If I want to only allow tcp/25 in to a particular IP I can do that, if I want 5900-5910 I can do that too, as well as 1-65535.
A router moves packets from A->B and a firewall defines what is allowed from A->B.
ULA to NPT is router stuff: NPT literally means "Network Prefix Translation" it turns all your IPv6 addresses into a normalised one and shifts them.
We are not talking about ports or protocols yet, just (IP) addresses.
Why? This is exactly how I want it to work: pass through only the ports (or all the ports) I want/need for the service in question.
If Xfinity changes the /60 they're giving me it doesn't change anything internally - because my internal names all use the ULA - and the GUA just gets used to get to the Internet.
Ideally there would be a way to request a new one programmatically, akin to getting a new IPv4 address via DHCP if you change the MAC address.
It is rather sad that the internet that we have, what 50-70 odd years post invention is so stifled with nonsense about addressing schemes and that.
You seem to use the term "static IP" as a talisman. I have zillions (possibly gazillions) of them on IPv6 and roughly a few 100 or 1000 on IPv4 (I own an IT company).
Dynamic DNS is a thing, so is ULA for IPv6 which looks quite like IPv4 RFC1918.
We have the tools but you do have to use them.
Compared to a PPP session with an ISP, dynamic DNS is a walk in the park and you can have multiple ones if it is that important. You could even have a mobile phone SMS an IP out.
DNS is seriously resilient to outages. Yes CF, Goog n co have all had outages but the beauty of DNS (and a pain at times if mismanaged) is TTL. Don't set all your records with a TTL of 300. I run quite a few DNS servers - Windows, BIND, PowerDNS and others, not to mention rather a lot of unbound and dnsmasq resolver/forwarder thingies.
Evaluate your requirements, evaluate the resiliency and functionality of the available technologies, evaluate your own skills and take appropriate action ... for you. That works at home just as well as at work.
You may find that you are running your own DNS server (or three) ...
You're about a decade (2007) behind the times:
Nodes use IPv6 stateless address autoconfiguration to generate
addresses using a combination of locally available information and
information advertised by routers. Addresses are formed by combining
network prefixes with an interface identifier. On an interface that
contains an embedded IEEE Identifier, the interface identifier is
typically derived from it. On other interface types, the interface
identifier is generated through other means, for example, via random
number generation. This document describes an extension to IPv6
stateless address autoconfiguration for interfaces whose interface
identifier is derived from an IEEE identifier. Use of the extension
causes nodes to generate global scope addresses from interface
identifiers that change over time, even in cases where the interface
contains an embedded IEEE identifier. Changing the interface
identifier (and the global scope addresses generated from it) over
time makes it more difficult for eavesdroppers and other information
collectors to identify when different addresses used in different
transactions actually correspond to the same node.
* https://datatracker.ietf.org/doc/html/rfc4941 This document describes an extension to IPv6 Stateless Address
Autoconfiguration that causes hosts to generate temporary addresses
with randomized interface identifiers for each prefix advertised with
autoconfiguration enabled. Changing addresses over time limits the
window of time during which eavesdroppers and other information
collectors may trivially perform address-based network-activity
correlation when the same address is employed for multiple
transactions by the same host. Additionally, it reduces the window
of exposure of a host as being accessible via an address that becomes
revealed as a result of active communication. This document
obsoletes RFC 4941.
* https://datatracker.ietf.org/doc/html/rfc8981* https://en.wikipedia.org/wiki/IPv6_address#Stateless_address...
"yoohoo - where am I?"
"You are on 2001:1001:1001:f0d::/64. My name is [ipv6] and I am a router and for some odd reason, I won't tell you where DNS comes from because ... stupid design"
"Cool, I'll fiddle in my drawers and play with my MAC address and create a really long number that starts 2001:etc. I'll also create a few other addresses randomly to hide my private parts (which is a waste of time but looks good - lol)"
No idea what you are on about wrt EUI-64 being tied to SLAAC. Why not have a go at it instead of pontificating?
Having used IPv6 in anger for several years now, it is a bit different but it is actually quite beautiful at times. It does enforce decent DNS and who here has not said "its DNS"?
Like I said, I don't touch v6 much and I'm pretty surprised at how far we've made it past v4 allocations drying up and everything still seems to work.
It does work pretty well already but I put it rather below the significance of say global warming as a thing to really worry about.
Give it a go if you get a prefix from your ISP. It's worth a play.
This sort of thing takes 50+ years to work. You have to think like an Engineer with a lot of time to play with. The internet is everywhere, it doesn't change overnight.
In scenarios where network configuration information related to IPv6
prefixes becomes invalid without any explicit and reliable signaling
of that condition (such as when a Customer Edge router crashes and
reboots without knowledge of the previously employed prefixes), hosts
on the local network may continue using stale prefixes for an
unacceptably long time (on the order of several days), thus resulting
in connectivity problems. This document describes this issue and
discusses operational workarounds that may help to improve network
robustness. Additionally, it highlights areas where further work may
be needed.
* https://datatracker.ietf.org/doc/html/rfc8978In effect, it's not much different than how IPv4 works with unstable WAN DHCP addresses from your provider, and I don't have the headaches that NAT brings with it.
It's a different way to think about the problem, but I've actually found it to be pretty nice.
For local lan services I make a dns entry in my router pointing to the ULA. I have had no issues but it took awhile to figure everything out. I host matrix chat and many other services using ipv6 without issues. YMMV.
If you only see one /128 as the IP of your router's WAN interface and nothing else, then that is the /128 assigned to your router by DHCP and nothing to do with prefix delegation.
The keyword here is "can". The difference here is this: if your NAT is not configured properly, your network is not accessible, nothing works, the problem is obvious, and is going to be fixed ASAP. If your stateful firewall is not configured properly, everything works fine, except that your network is visible from places it wasn't supposed to be. It requires some dedicated checks to verify.
So, the problem with NAT vs firewall security is not technical, it is psychological (but no less dangerous): when you have a working (but insecure) system by default, it is easy to miss the hardening step. The consequences can be catastrophic.
Network Address and Port Translation (NAPT) works well for conserving
global addresses and addressing multihoming requirements because an
IPv4 NAPT router implements three functions: source address
selection, next-hop resolution, and (optionally) DNS resolution. For
IPv6 hosts, one approach could be the use of IPv6-to-IPv6 Network
Prefix Translation (NPTv6). However, NAT and NPTv6 should be
avoided, if at all possible, to permit transparent end-to-end
connectivity. In this document, we analyze the use cases of
multihoming. We also describe functional requirements and possible
solutions for multihoming without the use of NAT in IPv6 for hosts
and small IPv6 networks that would otherwise be unable to meet
minimum IPv6-allocation criteria. We conclude that DHCPv6-based
solutions are suitable to solve the multihoming issues described in
this document, but NPTv6 may be required as an intermediate solution.
* https://datatracker.ietf.org/doc/html/rfc7157Of course, I have no idea how often an ISP actually changes your IPv6 prefix. In an ideal world, it'd never change...
A dynamic IP change can just happen without much warning, and enjoy possibly spending an hour befuddled before you realize what happened.
I don't see a way to fix this (and configuration errors are common).
Routers should have dashboards that give easy status of firewall configuration ala Windows firewall: Green for no inbound rules (or whitelisted rules) and yellow/red for non-checked rules.
Routers could even have LEDs or status displays like some higher end Ubiquiti prosumer products have, showing firewall status.
Routers could have a user-accessible API and Windows client that shows status on a taskbar item.
The technical solutions are there, but I don't have faith ASUS and co will build a competent product.
Secure systems are robust against user mistakes (and even middlemen mistakes). A NAT is one such system. Alternatives do not work like that.
The last time I was looking for a home router I specifically went for Asus because their default firmware is pretty good, and third-party options are available:
* https://www.asuswrt-merlin.net/features
Currently running an RT-AC68U.
This is insane. I don't want to have to learn, document, configure, and patch a different firewall on every internet connected device I own. That's a total nightmare. Computers can have their firewalls managed at the domain level. How is that support to work for bluray players, game consoles, light bulbs, phones, echo devices, door cams, thermostats, and kitchen appliances?
Nope. At a minimum everyone should have a stateful firewall at their edge making their devices impossible to reach/scan from the internet at large. Home routers that defaulted to using NAT made that dead simple.
On the rare occasion you really need something open to the entire internet it can sit in your DMZ. If I ever do make the move to using IPv6 on my network I'll likely continue to use NAT
Home routers have gotten pretty good about sane defaults these days, but at a minimum I'd be disabling UPnP and looking over what those defaults are before trusting it to protect my network.
You could argue that having one edge device running a checked and configured firewall means that you don't have to worry about the firewalls installed on every other device on the network, but anyone who has networking experience will know better. Problems are bound to come up on the internal network if nothing else and troubleshooting issues becomes a lot more complicated!
Also, if we're counting on every IoT product to come with its own embedded firewall you can be sure many of those are going to be so poorly thrown together that they introduce more security problems than they solve. This is a class of products that has earned a horrible reputation in terms of security.
then there is the Windows firewall:
- Applications that punch their own holes, like steam
- Windows which grants itself inbound exceptions and reenables them if you disable them
- A non standard filtering order (deny is always defore allow, not in order)
And then there are all those born in the 80s people that were told on LAN parties to "just disable the Windows firewall" and kept doing so.
You caught me. I think a firewall on the router is absolutely essential regardless of NAT scenarios.
With the understanding that you have an entire generation of computer users who equate that internet box with some degree of safety, you will find less friction with some tweak to that experience. You can still call it "port forwarding", block all inbound by default, and keep most of the same UX.
I personally like to operate my home network like a DMZ. Being able to reach any computer from any other without screwing around with networking is very convenient to me. I operate with an all-or-nothing trust model on my LAN. Having some centralized firewall helps a lot with this.
The rest of the world, though, knows that you don't just randomly open ports without good reason and without ways to turn off services.
Perhaps you should inform the IoT community.
What I'm saying is that if you can get, say, 2001:db8:1234::/48 delegated to your router, then:
1. You would configure your LAN to have the subnet 2001:db8:1234:1::/64
2. You would configure the webserver on your LAN to have a static IP like 2001:db8:1234:1::1
3. You would add a firewall rule in your router on the WAN interface to allow incoming TCP traffic with destination [2001:db8:1234:1::1]:443 . This rule would have higher precedence than the default rule that blocks all incoming traffic).
At this point, anyone in the world who attempts to reach 2001:db8:1234:1::1 will reach your ISP, which will route it to your router's WAN interface (because the ISP delegated the prefix to your router), which will allow the packet to cross from WAN to LAN because of the firewall rule, which will then route it to your webserver.
Let's say Amazon won't deliver to your apartment number, just a central point at your apartment.
- This is like thinking you can stop locking your door because your apartment number isn't public information.
- It would be better if your apartment had a direct public address so you could get packages to your doorstep instead of having them wait in some common area.
- Most people take regular, obsessive trips to application-level exchanges like "Facebook" to interact with others and are fine with it. Hopefully everything you ever want to do is OK with Facebook.
We have no need for NAT in the traditional IPv4 sense but NPT is handy for failover and that is why it was invented because IPV6's design lacked one crucial thing: telling the clients which internets are available so they can select which local address to start out from.
Perhaps everyone should run BFD(v6) by default.
Technical footnote: /127 addresses are supported (and were a thing for a short while) on inter-router links:
* https://datatracker.ietf.org/doc/html/rfc6164
Technical technical footnote: you can just use link-local address for inter-router links because all the router cares about is the next next-hop, and you don't need a globally routable address for that.
In an IPv6 network, it is possible to use only link-local addresses
on infrastructure links between routers. This document discusses the
advantages and disadvantages of this approach to facilitate the
decision process for a given network.
* https://datatracker.ietf.org/doc/html/rfc7404Yes they are but I want a shit load of stuff on my WAN available to the world and I don't want to piss around with NAT n that.
The IPv6 address-space is big enough to deal with PtP links. It doesn't really matter, You could do a /127 for WAN and then I allocate a /64 from my /48 for WAN. Or you could use a recent RFC that enables a /64 or smaller to be used for WAN without a separate allocation.
Instead of a router coming default with NO access control/firewall, and inbound connections being denied by the technical impossibility of addressing an inbound Internet packet to a private address, the industry should shift to "default ACL of allow all outbound, allow none inbound" and then have users craft inbound firewall rules as needed.
Try explaining that to non-techies. There's a reason UPnP exists.
We would ideally want something like NAT hole punching but more standardized.
Yes, it can. I used to work in a place that had so many public IPv4 addresses that they were using them for laptops and workstations. With a good firewall configuration it is certainly possible.
However I agree with you that IPv6 NAT may be useful still.
The weird part is that I traced the router advertisements as coming from an old Google Chromecast. It was advertising the prefixes of my old ISP. Bug or intended? If the latter, why?