All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Krzysztof Olędzki" <ole@ans.pl>
To: Jan Engelhardt <jengelh@medozas.de>
Cc: David Miller <davem@davemloft.net>,
	T.Moes@student.ulg.ac.be, netfilter-devel@vger.kernel.org
Subject: Re: NAT66 : A first implementation
Date: Sun, 17 Jul 2011 07:09:17 +0200	[thread overview]
Message-ID: <4E226E7D.6050800@ans.pl> (raw)
In-Reply-To: <alpine.LNX.2.01.1107150151390.20658@frira.zrqbmnf.qr>

On 2011-07-15 01:55, Jan Engelhardt wrote:
> On Friday 2011-07-15 01:17, David Miller wrote:
>
>> From: Jan Engelhardt<jengelh@medozas.de>
>> Date: Fri, 15 Jul 2011 01:15:47 +0200 (CEST)
>>
>>> Of course yours is feature-richer. But the topic of IPv6 NAT has had
>>> come up a number of unrecollectable times, and the response has been the
>>> same everytime - NAT is still an ugly undesired hack whose recurrence
>>> wants to be avoided.
>>
>> People want to hide the details of the topology of their
>> internal networks,
>
> And IPv6 Privacy w.r.t. random address selection, combined with a
> firewall, won't do that?

Be rational.

How would you imagine managing and maintaining a typical corporate 
network (1K+ devices) of different devices and operating systems - 
workstations (Windows, Mac, Linux), servers (Windows, Linux, BSD) 
routers, switches (radius), firewalls, APs, etc; without static IP 
addresses? Static = not random.

Also, how would you imagine readressing such network one day, when you 
decide to change your ISP?

Without NAT (and BTW without working and complete L3 security in 
switches) no one will consider IPv6 seriously nor dare to implement it 
in production. Of course NAT does not provide security but it provides a 
real and useful privacy, opposite to annoying randomness.

Best regards,

				Krzysztof Olędzki
--
To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html

  reply	other threads:[~2011-07-17  5:30 UTC|newest]

Thread overview: 23+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2011-07-14 15:47 NAT66 : A first implementation Terry Moës
2011-07-14 16:22 ` Jan Engelhardt
2011-07-14 16:27   ` Terry Moës
2011-07-14 23:15     ` Jan Engelhardt
2011-07-14 23:17       ` David Miller
2011-07-14 23:37         ` Rick Jones
2011-07-15 15:43           ` Rick Jones
2011-07-14 23:55         ` Jan Engelhardt
2011-07-17  5:09           ` Krzysztof Olędzki [this message]
2011-07-17 22:23             ` Ed W
2011-07-17 23:54               ` Krzysztof Olędzki
2011-07-18  8:38                 ` Ed W
2011-07-15  0:48         ` Jeff Haran
2011-07-15  2:29           ` Adam Roach
2011-07-15 22:12             ` Jeff Haran
2011-07-16  3:08               ` Adam Roach
2011-07-18  2:05         ` YOSHIFUJI Hideaki
2011-07-18 15:50         ` Patrick McHardy
2011-07-21  7:15           ` Harald Welte
2011-07-15  5:48       ` Philip Craig
2011-07-15 10:29         ` Jan Engelhardt
     [not found]       ` <4E20051D.7080208@student.ulg.ac.be>
2011-07-15  9:16         ` Terry Moës
2011-07-15 11:09           ` Jan Engelhardt

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=4E226E7D.6050800@ans.pl \
    --to=ole@ans.pl \
    --cc=T.Moes@student.ulg.ac.be \
    --cc=davem@davemloft.net \
    --cc=jengelh@medozas.de \
    --cc=netfilter-devel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.