nanog mailing list archives
Re: IPv6 uptake (was: The Reg does 240/4)
From: Matthew Walster via NANOG <nanog () nanog org>
Date: Mon, 19 Feb 2024 09:37:11 +1100
On Sun, 18 Feb 2024, 05:29 Owen DeLong via NANOG, <nanog () nanog org> wrote:
Most firewalls are default deny. Routers are default allow unless you put a filter on the interface.
This is not relevant though. NAT when doing port overloading, as is the case for most CPE, is not default-deny or default-allow. The OS processes the packet just like normal and sends an ICMP back unless there is another firewall that says drop. NAPT adds temporary rewrite rules for each flow that goes outbound. NAT adds nothing to security (Bill and I agree to disagree on this), but at
best, it complicates the audit trail.
It absolutely does add something. Whether that something is valuable or not depends on your vantage point, and I'd say it's better than nothing, but there are better solutions available. M
Current thread:
- Re: IPv6 uptake (was: The Reg does 240/4), (continued)
- Re: IPv6 uptake (was: The Reg does 240/4) William Herrin (Feb 17)
- Re: IPv6 uptake (was: The Reg does 240/4) Steven Sommars (Feb 18)
- Re: IPv6 uptake Stephen Satchell (Feb 17)
- Re: IPv6 uptake (was: The Reg does 240/4) Tom Beecher (Feb 17)
- Re: IPv6 uptake (was: The Reg does 240/4) Owen DeLong via NANOG (Feb 17)
- Re: IPv6 uptake (was: The Reg does 240/4) Owen DeLong via NANOG (Feb 17)
- RE: IPv6 uptake (was: The Reg does 240/4) Howard, Lee via NANOG (Feb 19)
- Re: IPv6 uptake (was: The Reg does 240/4) William Herrin (Feb 19)
- Re: IPv6 uptake (was: The Reg does 240/4) Jay R. Ashworth (Feb 16)
- Re: IPv6 uptake (was: The Reg does 240/4) Owen DeLong via NANOG (Feb 17)
- Re: IPv6 uptake (was: The Reg does 240/4) Matthew Walster via NANOG (Feb 18)
- Re: IPv6 uptake (was: The Reg does 240/4) Daniel Marks via NANOG (Feb 16)
- Re: IPv6 uptake (was: The Reg does 240/4) Owen DeLong via NANOG (Feb 17)
- Re: IPv6 uptake Michael Thomas (Feb 17)
- Re: IPv6 uptake Mike Hammett (Feb 19)
- Re: IPv6 uptake William Herrin (Feb 19)
- Re: IPv6 uptake Mike Hammett (Feb 19)
- Re: [External] Re: IPv6 uptake Hunter Fuller via NANOG (Feb 19)
- Re: [External] Re: IPv6 uptake Dave Taht (Feb 19)
- Re: [External] Re: IPv6 uptake Hunter Fuller via NANOG (Feb 19)
- Re: [External] Re: IPv6 uptake Dave Taht (Feb 19)