Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

NAT requires a stateful firewall too. In fact all router firewalls are stateful otherwise you’d have to have large ranges of ports permanently open to incoming connections.

So you don’t actually need anything different nor special to have the same level of security with IPv6 vs IPv4 + NAT.



> NAT requires a stateful firewall too.

Yes, you’re repeating what I’m saying. NAT forced router vendors to implement stateful connection tracking and it increased the security of everything behind them.

> So you don’t actually need anything different nor special to have the same level of security with IPv6 vs IPv4 + NAT.

This isn’t how it played out in practice though. Huge swaths of home routers had no firewall at all when you enabled IPv6 support because it would have taken slightly extra work to enable the v6 conn tracking.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: