|
|
|
|
|
by chatmasta
3744 days ago
|
|
I didn't say NAT is a security feature. I said developers use NAT to benefit security. The security benefit of NAT is that it forces developers to assign a predictable, private IP address to each device/container/vm/box behind its "firewall," which the gateway can then use for enforcing QoS policies or port whitelisting. Sure, you can do this on IPv6. But IPv6 is more complicated to implement, because all tools support IPv4, and only some support IPv6. |
|
IPv6 has usability problems (I've written on this), but these are unrelated to security in any direct way.
The reason I call it toxic is that the idea that NAT helps security is a harmful superstition that spooks people about IPv6 adoption. It's also driven some to actually implement IPv6 NAT, which is kind of like strapping a horse feed bag on the front of your car.
There's a ton of superstition and cargo cultism in network security, since most people -- even developers -- don't understand much about how networks work.