logoalt Hacker News

fshtoday at 7:00 AM2 repliesview on HN

If you really don't have a stateful v4 firewall, your ISP can happily connect to all of your devices.


Replies

fc417fc802today at 9:21 AM

First they will have to change their policy of only providing one IPv4 address per ONT connection. Then they will have to convince me to disable NAT on my router, disable the DHCP server on my router, and bridge the WAN port with the LAN block.

Meanwhile in IPv6 land the ISP provided router that my relative has came configured by default to hand out globally routable addresses from the ISP provided /64. Thankfully it also had a stateful firewall enabled by default so there was no difference in practice.

ErroneousBoshtoday at 8:18 AM

How do they manage that?

show 2 replies