Security gain from NAT (was: Re: Cool IPv6 Stuff)

michael.dillon at michael.dillon at
Tue Jun 5 09:29:23 UTC 2007

> I posit that a screen door does not provide any security.

"Any" is too strong a word. For people living in an area with
malaria-carrying mosquitoes, that screen door may be more important for
security than a solid steel door with a deadbolt. It all depends on what
the risks are, what you are protecting, and where your priorities are.

It is rather odd to see this discussion just a few weeks after the IETF
issued RFC 4864 to address just this misconception of NAT. How many of
the participants have read the RFC? Assuming vendors of cheap consumer
IPv6 gateway boxes implement all the LNP (Local Network Protection)
features of RFC 4864, is there any reason for these boxes to also
support NAT?

As far as I can see the only good reason to put NAT in an IPv6 gateway
is because uneducated consumers demand it as a checklist feature. In
that case, let's hope that it is off by default and that disabling the
NAT does not disrupt any of the other LNP features. That way, when the
customer calls the support desk to complain that they are not getting
SIP calls from Mom, you can tell them to turn off the NAT and try again.

--Michael Dillon

More information about the NANOG mailing list