[GRLUG] IPv6: My views

Michael Mol mikemol at gmail.com
Fri Jun 8 16:43:20 EDT 2012


On Fri, Jun 8, 2012 at 4:25 PM, L. V. Lammert <lvl at omnitec.net> wrote:
>> On Fri, 2012-06-08 at 16:02 -0400, detrix42 at gmail.com wrote:
>> > Hello everyone.  About three months ago I look around to see if there
>> > were any IPv6 ready home routers.
>>
>> No, it is *NOT* a security issue.  It is *NOT* a security issue.
>>
> Sorry, that is very shortsighted and elitist! If you have public ports
> that need to transit the 'boundary', then fine, a firewall is required.
>
> However, for 99% of the SOHO/Home users, NAT is EXTREMELY valuable
> security, something that protects against a significant number of threats.

First, it's not simply "NAT". The kind of NAT you're thinking about is
"NAT-PT". If you were using SNAT, you'd have no security without the
application of a firewall.

Unless you're trying to hide your internal network topology, the exact
same benefits you're looking for are achieved with only two ip6tables
commands.

-- 
:wq


More information about the grlug mailing list