Re: Routing issue: several interfaces with the same inet6 prefix

Paul de Weerd <[email protected]> Sat, 11 Jun 2005 00:04:29 +0200
Newsgroups gmane.os.openbsd.ipv6
Message-ID <[email protected]>
On Fri, Jun 10, 2005 at 03:43:22PM -0500, eric wrote:
| On Thu, 2005-06-09 at 23:15:10 +0200, Paul de Weerd proclaimed...
|
| > pf rocks. It *does* nat v6.
| >
| > Try it. I have it running and it works splendidly. The setup I
| > described in my original e-mail to ipv6@ is exactly what I have
| > working on my workstation at the office where I have a 'private'
| > backend network behind a second NIC. This NATs all traffic to the
| > address on the primary interface (which can not be configured with
| > router sollicitation). But it does work.
|
| Not directly to Paul...but....
|
| One of the points of IPv6 is NOT TO NAT. You don't need it. It does nothing
| for security, and all it does is break things.

In fact, I *do* need it. Not for security, but because I have only one
v6 address. And it doesn't break things either (not for me, in my
setup at least). What you could do, in fact, is simply use site-local
addresses on the backend side of your network and then only change the
first 64 bits of your address (the network address) to the one on your
frontend side, possibly using the 'bitmask' option of pf.

Of course, such a solution would only work in certain setups and may
require some creative coding, but it can work. It would not work in
Christians setup; which is another fine example of a useful place for
IPv6 NAT.

| Let NAT DIE! Learn about networking.

I would agree that NAT is not the best solution around to certain
problems (and certainly that IPv6 solves many of the problems NAT was
invented for in a better or more elegant manner), but that doens't
mean it's useless. I have learned about networking, and I have learned
that NAT has its uses, even though it creates some problems of its
own. Please use the tools you have in as creative a manner as you see
fit. No need to destroy tools because they can not be used for certain
jobs.

Cheers,

Paul 'WEiRD' de Weerd

--
>++++++++[<++++++++++>-]<+++++++.>+++[<------>-]<.>+++[<+
+++++++++++>-]<.>++[<------------>-]<+.--------------.[-]
                 http://www.weirdnet.nl/

[demime 1.01d removed an attachment of type application/pgp-signature]