Re: RES: ReN: IPv6 tranisition issues
"Michael R. Cole" <[email protected]> Fri, 10 Jan 2003 04:47:28 -0500
| Newsgroups | gmane.ietf.ngtrans |
|---|---|
| Message-ID | <009901c2b88d$4aa322e0$ca00a8c0@k6500a> |
----- Original Message ----- From: "Caitlin Bestler" <[email protected]> To: <[email protected]> Sent: Thursday, January 09, 2003 1:14 PM Subject: Re: RES: ReN: (ngtrans) IPv6 tranisition issues > On 1/8/03, Rod Van Meter wrote: > > >> -----Mensagem original----- > >> De: Michael R. Cole [mailto:[email protected]] > >> Enviada em: terga-feira, 31 de dezembro de 2002 09:20 > >> Para: [email protected] > >> Assunto: Re: ReN: (ngtrans) IPv6 tranisition issues > >> > >> > >> Your claim would also say that a timesharing system with > >> only 1 public IPv4 address would not work which is what > >> a cone NAT mimics. That is, a cone NAT fools that public > >> Internet into thinking that a LAN or other subnet is in > >> actuality a single machine. > > > >That's a gross oversimplification that eliminates the > >actual problem, so of course it doesn't sound bad when you > >put it that way. > > > >When a computer has a global address, you open a socket > >and get a port, and you can tell anyone anywhere in the > >world using any communications medium that they can reach > >you there. You can call someone on the telephone and tell > >them, "My cool new game server is at port 1982 on > >1.2.3.4!" and it works. You can send the info via snail > >mail, and it works. One friend can tell another friend, > >and it works. > > > Virtually every NAT device I have seen is fully capable of > statically configuring any port to pass-thru to a specific > machine. In other words, the single virtual machine can > offer it service on any port and then use any of its > component machines to implement that service. > > So the statement that a NAT creates a single virtual machine > is both very accurate, and highlights very precisely its > limitations. > > The next question is how well that Virtual Machine > communicates internally. There are indeed NATs that have no > mechanism to dynamically determine the external port > associated with a given connection, or to dynamically create > a mapping. That is indeed a poor interface, but to be fair > it is a poor interface *within* the virtual machine. There > is nothing wrong with the interface presented to the public > Internet. The left hand not communicating with the right > hand is something any Internet host can achieve, whether it > is composed of a single or multiple machines. > > The real point is not that "NAT is evil". There are > legitimate reasons for presenting a single virtual machine > to the public network. Rather the issue is that networks are > forced to use IPv4 NAT to solve other problems such as a > shortage of public IPv4 addresses and keeping the identity > of specific machines within a private network confidential. > > NAT "breaks" applications when the hosts it is masquerading > are not actually part of an integrated whole. Properly > deployed, IPv6 allows each host within a private network to > have permanent and/or temporary public addresses as > required. > > I believe NAT bashing is counter-productive to IPv6 > deployment. Too many comments make it sound as though IPv6 > advocates believe that only fools would use a NAT. A lot of > non-fools had very valid reasons to deploy NAT. The best way > to convince them that IPv6 offers better solutions to those > problems is by starting with acknowleding their legitimate > problems and understanding why they chose to deploy NATs in > the first place. > > Caitlin Bestler > http://asomi.com/CaitlinBestler/ > Thank you very much for explaining why one of the NAT+gateway packages that I have tried works so well (that I am tempted to buy it) and the commercial version has features that should NOT be omitted from any connectivity software. However, with only a 33.6 Kbps dialup connection I cannot justify buying a package yet. I can only justify playing around with a package for the 30-day trial period.