nanog mailing list archives
Re: IPv6 uptake (was: The Reg does 240/4)
From: "John Levine" <johnl () iecc com>
Date: 16 Feb 2024 22:10:34 -0500
It appears that William Herrin <bill () herrin us> said:
Now suppose I have a firewall at 199.33.225.1 with an internal network of 192.168.55.0/24. Inside the network on 192.168.55.4 I have a switch that accepts telnet connections with a user/password of admin/admin. On the firewall, I program it to do NAT translation from 192.168.55.0/24 to 199.33.225.1 when sending packets outbound, which also has the effect of disallowing inbound packets to 192.168.55.0/24 which are not part of an established connection.
Or you set up port forwarding for some other device but you mistype the internal address an forward it to the switch. Or the switch helpfully uses UPNP to do its own port forwarding and you forget to turn it off. If you configure your firewall wrong, bad things will happen. I have both IPv6 and NAT IPv4 on my network here and I haven't found it particularly hard to get the config correct for IPv6. Normally the ISP will give you an IPv6 /56 or larger so you can have multiple segments behind the router each with a /64 and different policies for each segment.
Current thread:
- Re: IPv6 uptake (was: The Reg does 240/4), (continued)
- Re: IPv6 uptake (was: The Reg does 240/4) Michael Thomas (Feb 18)
- Re: IPv6 uptake Nick Hilliard (Feb 18)
- Re: IPv6 uptake Michael Thomas (Feb 18)
- Re: IPv6 uptake Nick Hilliard (Feb 18)
- Re: IPv6 uptake Michael Thomas (Feb 18)
- Re: IPv6 uptake Nick Hilliard (Feb 18)
- Re: IPv6 uptake John Levine (Feb 18)
- RE: IPv6 uptake (was: The Reg does 240/4) Howard, Lee via NANOG (Feb 19)
- Re: IPv6 uptake (was: The Reg does 240/4) William Herrin (Feb 19)
- Re: IPv6 uptake (was: The Reg does 240/4) Michael Thomas (Feb 18)
- Re: IPv6 uptake (was: The Reg does 240/4) John Levine (Feb 16)
- Re: IPv6 uptake (was: The Reg does 240/4) William Herrin (Feb 16)
- Re: IPv6 uptake (was: The Reg does 240/4) John R. Levine (Feb 16)
- Re: IPv6 uptake (was: The Reg does 240/4) William Herrin (Feb 16)
- Re: IPv6 uptake (was: The Reg does 240/4) Ryan Hamel (Feb 16)
- Re: IPv6 uptake (was: The Reg does 240/4) Justin Streiner (Feb 17)
- Re: IPv6 uptake (was: The Reg does 240/4) Owen DeLong via NANOG (Feb 17)
- Re: IPv6 uptake (was: The Reg does 240/4) William Herrin (Feb 17)
- Re: IPv6 uptake (was: The Reg does 240/4) Steven Sommars (Feb 18)
- Re: IPv6 uptake Stephen Satchell (Feb 17)
- Re: IPv6 uptake (was: The Reg does 240/4) Tom Beecher (Feb 17)