So yeah, having to relearn a bunch of basic network knowledge that worked just fine for decades is a PITA, and I’m 100% positive a design process that focused more on the people that need to configure networks could have yielded a much friendlier, and therefore a much easier to adopt standard.
its really extremely simple, just dont NAT, is that really so hard? just because you dont NAT, doesnt mean you have to let the traffic pass through, that is also an extremely simple concept, no?
There are a shitload of people who maintain networks, like home or small business networks, that aren’t network administrators. Most of those people are not prepared to have their Chinese WiFi cameras, myriad smart appliances, and heck, even home computers easily individually accessible from the internet. It’s an extremely simple concept, no?
It isn't. Routing is good though.
And home routers have firewalls that block inbound connections by default -- including with no-NAT IPv6.
perhaps you could explain how its such a new paradigm and mental model that it simply confuses people? because I dont buy it, its without exaggerating a smaller difference in so far as this goes, than when people get a new microwave oven, and substantially less difference than when people switch phone brands.
Suppose I've got a machine on the LAN and I want to open it up to the world on port 1025 with IPv6.
This can't happen with SLAAC? It has to be a new address? Does the ISP pick the prefix for that address? And one can't centrally-manage that address (because people keep saying that DHCPv6 isn't worth stuffing around with)? What happens when the router fails over to a backup ISP? How does dynamic DNS fit in with all of this?
Those questions don't really exist with IPv4, wherein: One can just set up a static DHCP assignment, forward port 1025, and [optionally] set up dynamic DNS -- and this all happens within the confines of a single home router.
Things would be nicer if NAT66 were used by default for home users though so the question of prefixes would disappear, and it'd perhaps match the "more advanced" home user ipv4 mental model. You'd just use e.g. fd00::2 as your server address.
> The “you don’t have to use NAT anymore” is great theoretically, but it renders a lot of casual network maintainers mental model of network security obsolete without a clear and simple alternative
If your mental model of security relies on NAT then your mental model was wrong, and obsoleting it was the right thing to do.
If v6 made you realize this, then it seems it's more intuitive than v4+NAT was for you.