Re: RES: ReN: IPv6 tranisition issues

"Michael R. Cole" <[email protected]> Fri, 10 Jan 2003 04:28:55 -0500
Newsgroups gmane.ietf.ngtrans
Message-ID <004101c2b88a$b2c5a490$ca00a8c0@k6500a>
----- Original Message -----
From: "Rod Van Meter" <[email protected]>
To: "Marcelo Barbosa Lima" <[email protected]>
Cc: "Michael R. Cole" <[email protected]>; <[email protected]>
Sent: Wednesday, January 08, 2003 5:41 PM
Subject: Re: RES: ReN: (ngtrans) IPv6 tranisition issues


> > -----Mensagem original-----
> > De: Michael R. Cole [mailto:[email protected]]
> > Enviada em: terga-feira, 31 de dezembro de 2002 09:20
> > Para: [email protected]
> > Assunto: Re: ReN: (ngtrans) IPv6 tranisition issues
> >
> >
> > Your claim would also say that a timesharing system with only 1 public
IPv4
> > address would not work which is what a cone NAT mimics. That is, a cone
NAT
> > fools that public Internet into thinking that a LAN or other subnet is
in
> > actuality a single machine.
>
> That's a gross oversimplification that eliminates the actual problem, so
> of course it doesn't sound bad when you put it that way.
>
> When a computer has a global address, you open a socket and get a port,
> and you can tell anyone anywhere in the world using any communications
> medium that they can reach you there.  You can call someone on the
> telephone and tell them, "My cool new game server is at port 1982 on
> 1.2.3.4!" and it works.  You can send the info via snail mail, and it
> works.  One friend can tell another friend, and it works.
>
> With NAT, you can't do that, end of story.  The NAT box HIDES
> INFORMATION from BOTH ENDS of the conversation, so you can't know what
> the people at the other end see your address and port number to be.
>
> It also does not allow YOU to hide information for protocols it expects
> to affect.  You can't do FTP over IPSec, because then the NAT box can't
> reach into the FTP packets and modify them.
>
> I would have thought that all of this was pretty well understood by
> now...
>
> --Rod
>
>
>

Well of course it was an oversimplification but then the NAT box software
that I did get to work on my home network (on a trial basis) seemed to be a
lot smarter than one other that I tried. There is also a commercial grade
NAT+firewall+gateway software package on the market that does have versions
of ping and traceroute that do allow you to find out what address+port
combinations the box is presenting to other people. It is also about twice
the cost (for the same number of users) of the cheapies that are sold for
residential use.

Right now, my budget levels are such that I am not doing that much playing
around with software packages to see how well they work. The only
application that I have for NAT right now is to run Atomic Clock Sync which
does not justify the expense. I would also rather wait for a better
connectivity package that would allow an IPv6 router to run in parallel with
the NAT functionality so that I do not end up buying software twice.

MIke Cole