Same on mine, manufacturers dumbing things down too much, because
there is a key difference between port forwarding and packet
filtering. In port forwarding, the internal host can use a different
port to what the public sees. With packet filtering, that's normally
not possible, because the router is doing nothing more than accepting
or blocking traffic to a specific port on a LAN host. It is not
rewriting packets.
So, when you're using IPv6, an extra constraint is that the host needs
to be listening on the same port that the public sees
(My router only has a single field for the port in IPv6).
Michiel van der Vlist wrote to Tony Langdon <=-
Same here. In my cable modem/router IPv4 port forwarding and IPv6 port unblocking are done on the same page in the web interface. There are 9 fields:
I don't like this way of presenting it. It is indeed dumbing things
down and it creates confusion for both the experienced and the dummies. He, why can't I enter external addresses and ports for IPv6?
So, when you're using IPv6, an extra constraint is that the host needs
to be listening on the same port that the public sees
Indeed, but explain that to a newbie... Considering IPv4 and IPv6 are
on the same page named "port forwarding".
(My router only has a single field for the port in IPv6).
Here I can enter a port range, but only one set for IPv6. For IPv4
there is an external and an internal range. (Which must be of equal
size of course).
Mine has separate pages, but uses (incorrectly) "port forwarding" terminology for IPv6.
I don't like this way of presenting it. It is indeed dumbing
things down and it creates confusion for both the experienced
and the dummies. He, why can't I enter external addresses and
ports for IPv6?
Join the club. It would have been better to have the IPv6 filtering
as part of the "firewall" settings, where you can allow and block
traffic to hosts, ports and protocols, since that is what is happening
on IPv6.
So, when you're using IPv6, an extra constraint is that the host
needs to be listening on the same port that the public sees
Indeed, but explain that to a newbie... Considering IPv4 and
IPv6 are on the same page named "port forwarding".
Exactly!
(My router only has a single field for the port in IPv6).
Here I can enter a port range, but only one set for IPv6. For
IPv4 there is an external and an internal range. (Which must be
of equal size of course).
I think I can enter a range, has been ages since I've tweaked my IPv6 firewall.
:)
... This is abuse, arguments are down the hall.
Michiel van der Vlist wrote to Tony Langdon <=-
Indeed, it is a firewall function. What, in my opinion, went wrong is that the IPv4 NAT was presented as a firewall. Which it isn't. Although in some way NAT /acts/ as a firewall in that it blocks unsollicited incoming packets, unless explicitly told what to do with it, it is not
a firewall. The blocking is just a emergent effect.
A real firewall is something different. If so configured, it also
blocks unsollicited incoming packets. But it can do more that that. It can also detect certain kind of attacks, port scans, flooding etc. Plus that a firewall can also act on outgoing traffic. OTOH, a firewall can not do translation. It is not a NAT.
I guess we will have to live with what seems to be evolving practice:
it is both called "forwarding"..
I am a bad teacher, I won't even try..
I put this new IPv6 capable modem/router into service six weeks ago. So
I had to delve into it again.
... This is abuse, arguments are down the hall.
I loved that sketch! ;-)
A real firewall is something different. If so configured, it also
blocks unsollicited incoming packets. But it can do more that that.
It can also detect certain kind of attacks, port scans, flooding etc.
Plus that a firewall can also act on outgoing traffic. OTOH, a
firewall can not do translation. It is not a NAT.
Again, agree. Packet filtering is only one function that a firewall
can perform, as you point out. Either way, it's not NAT. NAT has a different purpose - rewriting IP addresses to achieve some networking goal (most commonly share a single public IP among multiple hosts).
Markus Reschke wrote to Tony Langdon <=-
That would be a stateful firewall. The most common setup is to allow everything from LAN to the WAN, and only allow related packets from WAN
to LAN.
It can also detect certain kind of attacks, port scans, flooding etc.
And that's an IDS. But an IDS could be integrated in a firewall
product. Commonly they are labeled "UTM".
Plus that a firewall can also act on outgoing traffic. OTOH, a
firewall can not do translation. It is not a NAT.
A firewall is a special kind of router. So NAT is an optional feature
of a firewall.
Sometimes it's the side effect you're interested in :)
| Sysop: | Winzlo |
|---|---|
| Location: | Minnesota, USA |
| Users: | 11 |
| Nodes: | 16 (0 / 16) |
| Uptime: | 495943:56:13 |
| Calls: | 82 |
| Files: | 1,070 |
| D/L today: |
27 files (11,920K bytes) |
| Messages: | 287,032 |