|
|
|
|
|
by rnhmjoj
1758 days ago
|
|
Ah, the inevitable NAT security comment on every IPv6 discussion. > yet it removes a whole class of problem (eg: windows print spooler is listening on [::] by default or something like that) NAT is just address translation, that's it: it doesn't imply a firewall. What you're thinking is a typical CPE router which, along masquerading the usual RFC 1918 range, runs a stateful firewall that blocks all incoming connections by default (but can be easily punched, even automatically by NAT-PMP, UPnP and a bunch of other protocols). Lifting the NAT doesn't mean lifting the firewall: new ISPs that deployed native IPv6 are doing exactly the same firewalling as before. |
|
The ISP level yada yada doesn't matter, nobody cares about that at a consumer level.
NAT doesn't imply firewalling, that true, but NAT also means that hosts being the gateway are not exposed by default.