RES: ReN: IPv6 tranisition issues
"Marcelo Barbosa Lima" <[email protected]> Mon, 6 Jan 2003 08:56:20 -0200
| Newsgroups | gmane.ietf.ngtrans |
|---|---|
| Message-ID | <D49EA2F934FFAD45B337C07A9753C00E017F55DC@MAILSRV1.aquarius.cpqd.com.br> |
I think that NAT is a good workaround and it can be done to support all= aplications (the cost is more complex code -- Code more complex =3D more= bugs =3D more security problems =3D poor performance =3D ...). NAT is im= plemented in routers and firewallls. So, it put more dificulty to impleme= ntators, provides problems to performance, etc. NAT and VPNs solutions no= rmally don=B4t work very well together. I think that NAT is something tha= t several vendors would like to kill :-). Routing and firewalling could d= o only your work, without regarding address translation. In IPv6, routing= is more easy and NAT is not necessary anymore. So, packets can flow fast= er in Internet.=20 REgards, Marcelo. -----Mensagem original----- De: Michael R. Cole [mailto:[email protected]] Enviada em: ter=E7a-feira, 31 de dezembro de 2002 09:20 Para: [email protected] Assunto: Re: ReN: (ngtrans) IPv6 tranisition issues=20 ----- Original Message ----- From: "Keith Moore" <[email protected]> To: "Michael R. Cole" <[email protected]> Cc: <[email protected]> Sent: Tuesday, December 31, 2002 12:28 AM Subject: Re: ReN: (ngtrans) IPv6 tranisition issues > > A NAT box is just simply > > a retooled router, > > that's a truly bizarre statement. I suppose it's true from a > hardware perspective, but it's like saying that a NAT box is > just a retooled computer with a couple of network interfaces - > true, but irrelevant to the question at hand. > > > just that some are better and some are worse. > > all NATs break applications. some NATs know about a few more > protocols than others, but no NAT can handle every possible protocol, > many protocols simply cannot be made to work transparently through NAT. > > Keith > Your definition of the word break must be different than the one in the dictionary. If an application works with a NAT box, then it is NOT BROKEN= ! Your claim would also say that a timesharing system with only 1 public IP= v4 address would not work which is what a cone NAT mimics. That is, a cone N= AT fools that public Internet into thinking that a LAN or other subnet is in actuality a single machine. At any rate, a NAT box is a patch that gets around the problem that a good sized chunk of the IPv4 address space was wastefully allocated to the original players at essentially zero cost. Maybe your first experience with a NAT box was with a really crummy one? = If that is your only experience or of you have no experience with NAT boxes, then you have no business crticizing them. Some NAT software that I have tried was absolutely horrible. I am not trying to say that the better NAT boxes will work with ALL applications. Somehow, the cable companies are able to use them at their headends without breaking applications. However, I have noticed that enterprise-class NAT boxes use a server-client setup so that applications are not really aware or can tell that they are indirectly connected to th= e Internet. Symmetric NAT boxes probably do work better in part because the= y mimic a timesharing system with one public IPv4 address for each user. Of course, some applications are very picky about what they will eat. MIke Cole, [email protected]