Comment on IPv6 & Opnsense & Not Exposing Machine-Specific IPv6s to Corpos

<- View Parent
Overspark@feddit.nl ⁨1⁩ ⁨week⁩ ago

NAT is not a firewall and it’s not that great for privacy either, it’s not hard to fingerprint individual devices behind NAT. There are no cases where NAT is better than the alternatives, except when you’re out of public IP’s, which isn’t an issue with IPv6.

So you’re much better off by not trying to reinvent the wheel and using IPv6 the way it was intended. Use privacy extensions for privacy. Use proper firewall rules for security. Revel in the fact that NAT isn’t fucking up your inbound connections. Do not under any circumstances force the horrible kludge that is NAT into your IPv6 network.

source
Sort:hotnewtop