Hacker News new | ask | show | jobs
by barneygumble742 2928 days ago
Reboot the internet with IPv6 and now all your internal devices will be openly addressable to the internet. I see nothing good coming from that.
3 comments

NAT is not a firewall. There's no reason you can't hide your LAN from a WAN connection with IPv6.
Exactly right. When I enabled IPv6 on my home LAN, I made very sure that only those hosts (and ports!) I wanted open were available to the outside world. Otherwise, incoming IPv6 is DROP by default.
This is strange, oft-repeated, mostly incorrect argument. Almost every modern router, if it handles IPv6, handles IPv6 without NAT but with a firewall. Most consumer routers just have ALLOW ALL outbound, ALLOW EXISTING inbound, default firewall rules that would be just fine for IPv6.
For a start your internal devices shouldn't have an Internet-routable prefix assigned.

Secondly, refer to other comments re: firewalls