ietf
[Top] [All Lists]

Re: Domain Centric Administration, RE: draft-ietf-v6ops-natpt-to-historic-00.txt

2007-07-02 12:09:56

On Jul 2, 2007, at 8:14 AM, Hallam-Baker, Phillip wrote:

My point here is that the principal objection being raised to NAT, the limitation on network connectivity is precisely the reason why it is beneficial.

There is no other device that can provide me with a lightweight firewall for $50.

Teredo enabled NATs are likely how IPv6 address use becomes common place. This creates interesting security problems as this bypasses normal policies. Even so, many exploits are not prevented by NATs and peripheral defenses. Exploits simply depend on the lines of code found within browsers and their many hooks into OS services and applications.

The problem has become so pervasive as to require extensive retooling. For example, SMTP reputations must be made more progressive in an attempt to accommodate a pervasive level of 0wned systems. The battle rages where NATs are not a complete solution, but instead represent a new challenge.

-Doug



_______________________________________________
Ietf mailing list
Ietf(_at_)ietf(_dot_)org
https://www1.ietf.org/mailman/listinfo/ietf

<Prev in Thread] Current Thread [Next in Thread>