What I'm saying is that if you can get, say, 2001:db8:1234::/48 delegated to your router, then:
1. You would configure your LAN to have the subnet 2001:db8:1234:1::/64
2. You would configure the webserver on your LAN to have a static IP like 2001:db8:1234:1::1
3. You would add a firewall rule in your router on the WAN interface to allow incoming TCP traffic with destination [2001:db8:1234:1::1]:443 . This rule would have higher precedence than the default rule that blocks all incoming traffic).
At this point, anyone in the world who attempts to reach 2001:db8:1234:1::1 will reach your ISP, which will route it to your router's WAN interface (because the ISP delegated the prefix to your router), which will allow the packet to cross from WAN to LAN because of the firewall rule, which will then route it to your webserver.
We have no need for NAT in the traditional IPv4 sense but NPT is handy for failover and that is why it was invented because IPV6's design lacked one crucial thing: telling the clients which internets are available so they can select which local address to start out from.
Perhaps everyone should run BFD(v6) by default.
Technical footnote: /127 addresses are supported (and were a thing for a short while) on inter-router links:
* https://datatracker.ietf.org/doc/html/rfc6164
Technical technical footnote: you can just use link-local address for inter-router links because all the router cares about is the next next-hop, and you don't need a globally routable address for that.
In an IPv6 network, it is possible to use only link-local addresses
on infrastructure links between routers. This document discusses the
advantages and disadvantages of this approach to facilitate the
decision process for a given network.
* https://datatracker.ietf.org/doc/html/rfc7404Yes they are but I want a shit load of stuff on my WAN available to the world and I don't want to piss around with NAT n that.
The IPv6 address-space is big enough to deal with PtP links. It doesn't really matter, You could do a /127 for WAN and then I allocate a /64 from my /48 for WAN. Or you could use a recent RFC that enables a /64 or smaller to be used for WAN without a separate allocation.
Instead of a router coming default with NO access control/firewall, and inbound connections being denied by the technical impossibility of addressing an inbound Internet packet to a private address, the industry should shift to "default ACL of allow all outbound, allow none inbound" and then have users craft inbound firewall rules as needed.
Try explaining that to non-techies. There's a reason UPnP exists.
We would ideally want something like NAT hole punching but more standardized.
Let's say Amazon won't deliver to your apartment number, just a central point at your apartment.
- This is like thinking you can stop locking your door because your apartment number isn't public information.
- It would be better if your apartment had a direct public address so you could get packages to your doorstep instead of having them wait in some common area.
- Most people take regular, obsessive trips to application-level exchanges like "Facebook" to interact with others and are fine with it. Hopefully everything you ever want to do is OK with Facebook.
Yes, it can. I used to work in a place that had so many public IPv4 addresses that they were using them for laptops and workstations. With a good firewall configuration it is certainly possible.
However I agree with you that IPv6 NAT may be useful still.