logoalt Hacker News

lxgryesterday at 3:20 PM3 repliesview on HN

IPv6 solves the addressing problem, not the reachability problem. Good luck opening ports in the stateful IPv6 firewalls in the scenarios outlined in TFA:

> And that assumes a single NAT. Many sites have a security firewall behind the ISP modem, or a cellular modem in front of it. Double or triple NAT means configuring port forwarding on two or three devices in series, any of which can be reset or replaced independently.


Replies

zamadatixyesterday at 7:30 PM

The article's proposed solution for IPv4 is a combination of VPN+NAT. The solution in IPv6 can be just VPN, sans NAT.

bigstrat2003yesterday at 4:26 PM

I'm not really seeing a reason why it would be impossible to open firewalls in that scenario. More work, sure, but by no means impossible. In any case TFA says right up front that it is trying to solve the problem of overlapping subnets, which IPv6 solves nicely.

show 3 replies
1970-01-01yesterday at 3:35 PM

With IPv6 you don’t forward ports at all. The device already has a public address.

show 2 replies