Linux: Limit IPv6 connectivity to specific programs
fds-team.de
fds-team.de
Does anyone know why this is the case? I'm not a network security expert but to me I don't see how IPv4/v6 makes a different in terms of security. I'd assume that each computer on the network could most likely be assigned a public IPv6 address rather than using NAT in which case how is configuring your perimeter firewall to drop incoming connections by default any different from not having any port forwarding setup by default? Even your average domestic router has some sort of basic firewall built in.
iptables -A INPUT -i lo -j ACCEPT
iptables -A INPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT
iptables -A INPUT -s 192.168.1.0/24 -j ACCEPT
iptables -A INPUT -p icmp -j ACCEPT
iptables -A INPUT -j DROP
iptables -A FORWARD -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT
iptables -A FORWARD -s 192.168.1.0/24 -j ACCEPT
iptables -A FORWARD -p icmp -j ACCEPT
iptables -A FORWARD -j DROP
Here are the IPv6 rules: ip6tables -A INPUT -i lo -j ACCEPT
ip6tables -A INPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT
ip6tables -A INPUT -s 2001:xx:xx:xx::/64 -j ACCEPT
ip6tables -A INPUT -p ipv6-icmp -j ACCEPT
ip6tables -A INPUT -j DROP
ip6tables -A FORWARD -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT
ip6tables -A FORWARD -s 2001:xx:xx:xx::/64 -j ACCEPT
ip6tables -A FORWARD -p ipv6-icmp -j ACCEPT
ip6tables -A FORWARD -j DROP
Does that look like it would be hard to do? Your router should come with these rules already. If it does not, ditch it and buy one that is supported by OpenWRT, where IPv6 support is not a second class citizen.Edit: Naturally, IPv4 rules would have to be more complicated since you'll want to have your NAT setup in there. In this way, configuring IPv6 is actually easier :). Also, a real router would have rules set up for throttling certain types of traffic (e.g.: you don't want more than, say, 1000 ICMP messages per second). However, all those steps are identical for IPv6.
Why?
Using NAT increases security simply by having deny by default.
In general, use the right tool for the job. NAT provides some blunt security features incidentally. It does not, for example, prevent your server from making connections to the outside world. The firewall is what is meant to be used to restrict traffic. That is its only job and it does that well.
What would you call it when a router at the edge of a private network presents a single IP to the world no matter how many devices are behind it, for privacy reasons?
It probably has something to do with NAT being a huge obstacle later, when needs change. For example, while it might make sense at one point to have multiple hosts appear as one, it is at the expense of direct addressability, and the workaround - having a unique address+port combination - makes less sense than having a unique directly-routable address.
"What would you call it when a router at the edge of a private network presents a single IP to the world no matter how many devices are behind it, for privacy reasons?"
The wrong tool for the job. :)
The privacy is gained not by translation but by blocking direct connections (which is a feature of a firewall - not of NAT). While there is some value in NAT's ability to falsify the origin of data - ie, to take credit for non-local flows - but if those applications ever grow they will be fighting to escape the single address of NAT and are thus only suitable in the short term. Ideally, NAT would go unused because every element is uniquely addressable and fully independent... Most people would not consider someone else who continually takes credit for their or someone else's work to be a feature, and so it is with NAT.
Taking credit for someone else's work is not a useful analogy for NAT, nor are the corresponding moral implications relevant.
So, you would rather use one address for everything, making it easy as pie to track you? You can pretty much pick IPv6 addresses at random (under your router prefix), and you have (many many many) more addresses than the whole IPv4 address space to choose from (it's a 128 bit address space and providers typically give a /48, /56, or /64 prefix at worst... that's 128-64=64 bits... that's 2^63.9999... more addresses than IPv4). In short, you don't really "map" the IPv6 space the same way you do the IPv4 space.
Taking credit for someone else's work very much is a useful analogy: if I can only speak through a third party, and I need that third party's permission to speak, let alone be spoken to, I quickly resent him or her. This is quite the case with current NAT solutions, with system administrators restricting "their" networks, making communication difficult for everyone else (by holding the only globally-routable address or "allocating" only a few; everyone else is second-class).
I'm willing to bet that any IPv6 capable router also has a firewall.
While it could be argued that NAT adds an extra layer to security-in-depth by making it harder to accidentally open things up by missing out the default drop/reject rule, but I'd argue that all the faf that NAT can create by making it difficult to arrange point-to-point connections where they are actually desirable is not worth that little bit of protection against failing to configure the firewall correctly.
The advantage of IPv6 is that any computer can act as a server again. NAT makes it unnecessarily difficult to build simple peer to peer applications such as for telephony, remote access or file transfer.
The tunnelling scenario is valid though - because they add quite a bit of latency so you might not want to use it for everything.
Also, requiring root privileges for launch is a bit of a burden in some use-case scenarios.
My point is just that I'm sure some very very weird stuff can happen with software.
But theoretically, I could enable IPv6 for sshd (where I stand the most benefit) and leave it off for wget and browsers with this.
"the ipv6 peer entry displayed a lower delay and less jitter while the offsets were reasonably close."
I can find some old Linux on linksys sites but not a lot recently