RES: ReN: IPv6 tranisition issues

"Marcelo Barbosa Lima" <[email protected]> Mon, 6 Jan 2003 08:56:20 -0200
Newsgroups gmane.ietf.ngtrans
Message-ID <D49EA2F934FFAD45B337C07A9753C00E017F55DC@MAILSRV1.aquarius.cpqd.com.br>
  I think that NAT is a good workaround and it can be done to support all=
 aplications (the cost is more complex code -- Code more complex =3D more=
 bugs =3D more security problems =3D poor performance =3D ...). NAT is im=
plemented in routers and firewallls. So, it put more dificulty to impleme=
ntators, provides problems to performance, etc. NAT and VPNs solutions no=
rmally don=B4t work very well together. I think that NAT is something tha=
t several vendors would like to kill :-). Routing and firewalling could d=
o only your work, without regarding address translation. In IPv6, routing=
 is more easy and NAT is not necessary anymore. So, packets can flow fast=
er in Internet.=20
REgards,

			Marcelo.

-----Mensagem original-----
De: Michael R. Cole [mailto:[email protected]]
Enviada em: ter=E7a-feira, 31 de dezembro de 2002 09:20
Para: [email protected]
Assunto: Re: ReN: (ngtrans) IPv6 tranisition issues=20



----- Original Message -----
From: "Keith Moore" <[email protected]>
To: "Michael R. Cole" <[email protected]>
Cc: <[email protected]>
Sent: Tuesday, December 31, 2002 12:28 AM
Subject: Re: ReN: (ngtrans) IPv6 tranisition issues


> >  A NAT box is just simply
> > a retooled router,
>
> that's a truly bizarre statement.  I suppose it's true from a
> hardware perspective, but it's like saying that a NAT box is
> just a retooled computer with a couple of network interfaces -
> true, but irrelevant to the question at hand.
>
> > just that some are better and some are worse.
>
> all NATs break applications.  some NATs know about a few more
> protocols than others, but no NAT can handle every possible protocol,
> many protocols simply cannot be made to work transparently through NAT.
>
> Keith
>

Your definition of the word break must be different than the one in the
dictionary. If an application works with a NAT box, then it is NOT BROKEN=
!
Your claim would also say that a timesharing system with only 1 public IP=
v4
address would not work which is what a cone NAT mimics. That is, a cone N=
AT
fools that public Internet into thinking that a LAN or other subnet is in
actuality a single machine. At any rate, a NAT box is a patch that gets
around the problem that a good sized chunk of the IPv4 address space was
wastefully allocated to the original players at essentially zero cost.

Maybe your first experience with a NAT box was with a really crummy one? =
If
that is your only experience or of you have no experience with NAT boxes,
then you have no business crticizing them. Some NAT software that I have
tried was absolutely horrible.

I am not trying to say that the better NAT boxes will work with ALL
applications. Somehow, the cable companies are able to use them at their
headends without breaking applications. However, I have noticed that
enterprise-class NAT boxes use a server-client setup so that applications
are not really aware or can tell that they are indirectly connected to th=
e
Internet. Symmetric NAT boxes probably do work better in part because the=
y
mimic a timesharing system with one public IPv4 address for each user.

Of course, some applications are very picky about what they will eat.

MIke Cole, [email protected]