Remix.run Logo
ssl-3 18 hours ago

Lack of NAT doesn't imply lack of firewall, though.

And home routers have firewalls that block inbound connections by default -- including with no-NAT IPv6.

DrewADesign 16 hours ago | parent [-]

But lots of people want to do things like open up a few ports for a gaming console. You can obviously do it, but the inside network/outside network/poke a hole/simple ip addresses mental model makes it harder for people to just get frustrated and disable it. Of course absolutely nothing is impossible or more difficult from a technical networking perspective using IPv6. People want to learn as little as humanly possible to solve their problems. If the default easiest path is ‘disable the firewall, and suddenly you can use the LAN pvp mode with your 6th grade classmate’ then you better fucking believe that’s exactly what they’re going to do. The “well it’s not really that complicated” perspective is the main reason adoption of user-facing FOSS is lightyears behind commercial options.

inigyou 8 hours ago | parent | next [-]

I have ipv6 here in Europe. The router firewall configuration works basically the same as IPv4 port forwarding. You can add a firewall exception as easily as you can add a port forward. You can also turn the firewall off, globally or per device.

redeeman 8 hours ago | parent | prev [-]

how is it a different mental model? instead of opening the port in NAT via forward feature, you open the port in the firewall. it is in fact significantly simpler while overall being the same actions you take when you want to "forward"

DrewADesign an hour ago | parent [-]

You’re right. That’s why everybody uses it and nobody is confused by it.

inigyou an hour ago | parent [-]

Everyone whose ISP offers it uses it, yes.