Live data from Hacker News

My NAS exposes itself over the internet without permission

kn100.me

251–260 of 311 posts

Re: My NAS exposes itself over the internet without permission

#251

Earlier quoted context omitted.

It does depend on the game. A P2P game like Call of Duty will have problems when played simultaneously on more than one console because the external port can not be shared. What happens though is that another external port gets forwarded to 3074 instead. 3074 -> 3074 3075 -> 3074 3076 -> 3074 etc. Its likely uPnP does this automatically as even uPnP won't be able to map multiple devices to the same external port but…

That’s not how NAT works though. It uses random ports, and there are no collisions, unless you have thousands of Xboxes behind a NAT. Also, remember that CGNAT is a thing, with hundreds of households( with dozens of game consoles) all behind a single IP address. Essentially, the people talking about game consoles not working are wrong.

Yes, CGNAT is causing a lot of issues not being able to host multiplayer games, as I've experienced myself (with PC games, though server-client ones, not peer to peer ones).

Anyway, these days, if you don't have an IPv6 /56, you don't have a real Internet connection.

Re: My NAS exposes itself over the internet without permission

#252

Earlier quoted context omitted.

It'll be fine. They'll be on two pretty arbitrary public ports, but it works just fine if you have a vaguely sane nat implementation in your router. That's the whole point of nat punching. And even if you have an incredibly broken nat implementation that won't accept UDP packets from other sources than the server you originally connected to, there's a fallback pathway at the first layer of that port 3074 protocol tha…

This Xbox help article explains how having a "Moderate" or "Strict" NAT can affect you and how it can be solved: https://support.xbox.com/en-GB/help/hardware-network/connect... I don't think anything has fundamentally changed in this area since the days of the Xbox 360. Back then it was a PITA to get two or more consoles working properly without UPnP, and I can't see anything about the problem that would be different…

How does it work with IPv6-only networks?

Re: My NAS exposes itself over the internet without permission

#253

Earlier quoted context omitted.

For most ISPs the IPv4 acts exactly the same way, being almost but not quite stable. I don't understand how that's a downside to IPv6.

Because "most ISPs" are actually wrong, it's "most American ISPs". In rest of the world, unless you're explicitly requested static IPs, your IPv4 (and IPv6) addresses are being rotated (usually either daily or weekly). There's a reason why dynamic DNS services are popular. P.S. If your security paradigm relies on IP addresses being semi-stable, you need to overhaul it.

This is wrong, at least in Europe, static IP is considered to be best practice.

Re: My NAS exposes itself over the internet without permission

#254
post #43

Earlier quoted context omitted.

I find it amusing that many people are convinced that IPv6 is less safe, because there is no NAT, and at the same time use UPnP. No, NAT isn't designed for security, the blocking of incoming traffic is just side effect, you should use a firewall for security.

IPv6 can be a privacy issue, sure, but it's no less secure, my firewall is still blocking all incoming IPv6 traffic. The issues with IPv6, in my experience come from its relative complexity, compared to IPv4, and also from forgetting to manage it at all, as it often uses different tools, firewalls, e.g. ip6tables vs iptables, or the fact that Ubiquiti EdgeRouters don't expose ANY IPv6 firewall configuration in the GU…

No firewall or opt-in firewall (which only a tiny fraction of people turn on) is pretty common for IPv6. It's also somewhat an open question whether router firewalls are even a good idea on IPv6 (since the security advantages are not that certain, and it can prevent the adoption of new protocols).

Re: My NAS exposes itself over the internet without permission

#255

Earlier quoted context omitted.

Aren't these two points slightly contradictory? > the author depends on NAT as a security feature, when it was never designed to be one > UPnP is a convenience feature, and is disabled in all security focused networks. uPnP punches holes in a NAT. If you shouldn't be trusting NAT to protect you anyway, why bother disabling a feature that's designed to punch holes in it? Just set up your firewall to protect your netwo…

UPNP doesn't "punch holes in NAT." It is dynamically configuring NAT to provide a specific translation. The same kind of dynamic translation happens the other way for any allowed outgoing traffic, and lots of old NAT traversal tricks made use of that before UPNP was a thing. The hole was always there. People get this topic confused all the time because the majority of network devices doing NAT are also acting as fire…

There are at least some non-firewall or opt-in firewall (which amounts to the same for most people) for IPv6 routers provided by major ISPs.

Re: My NAS exposes itself over the internet without permission

#256

Earlier quoted context omitted.

The basics of the client side are simple. But the routing is not simple. I'm pretty well versed in networking generally - even IPv6, but a quick glance over something like: http://ipv6now.com.au/primers/IPv6RoutingSecurity.php Makes it obvious why it still hasn't gotten anywhere, _no one_ wants to dig through all that unless they really really have to. Security depends on securing the routing and address allocation.…

Usually, inbound IPv6 are firewalled by the ISP router just fine. As far as I know, there is UPnP with IPv6 though there seems to be some work into that direction. Also, current CGNAT setups tend to close connections before they should according to RFCs: https://anderstrier.dk/2021/01/11/my-isp-is-killing-my-idle-... All the IPv6 routing security has to be done with IPv4 as well. ARP -> NDP, prevent source address sp…

Pretty often, IPv6 is NOT firewalls (or the firewall is opt-in which in practice amounts to the same thing).

Re: My NAS exposes itself over the internet without permission

#257
post #147

Earlier quoted context omitted.

> IPv6 is overly complex I'm being a bit pedantic about this since you're right that in practice, setting up stuff for IPv6 is in-fact complex since support for it is all over the place. But I want to stress that IPv6 as a protocol is much simpler, more intuitive and much more versatile than IPv4. I'd even go so far as to say that it's actually fantastically suited for local networks, especially so in complicated set…

The basics of the client side are simple. But the routing is not simple. I'm pretty well versed in networking generally - even IPv6, but a quick glance over something like: http://ipv6now.com.au/primers/IPv6RoutingSecurity.php Makes it obvious why it still hasn't gotten anywhere, _no one_ wants to dig through all that unless they really really have to. Security depends on securing the routing and address allocation.…

Well, the governments are starting to get the stick out : you don't have IPv6 support? No 5G authorisation for you!

Re: My NAS exposes itself over the internet without permission

#258
post #39

Earlier quoted context omitted.

Which ones? I have it turned off and haven't had any issues with games.

Games that use Peer-to-peer lobbies instead of dedicated servers, more popular with multiplayer co-op games. Typically, it can be possible to join another lobby, but impossible to host (insofar as other people can't connect to it)

This is also a problem with games using the client/server model where one of the players is the server.

Re: My NAS exposes itself over the internet without permission

#259
post #207
post #37

Earlier quoted context omitted.

Yeah, you can’t really “manage your firewall” when consumer software doesn’t open fixed ports and assumes upnp.

Why not? Which consumer software breaks? Normally people say games. I have disabled upnp on my firewall and there're two gaming PCs, a PS3, a PS4 and a PS5 running happily behind it. I just finished a Demon Soul's session with voice chat with friends with no problems. NAT type 2, because I managed my firewall to enable this.

Have you tried a client/server style game not relying on Steam multiplayer?

Re: My NAS exposes itself over the internet without permission

#260
post #123

Earlier quoted context omitted.

Honest question - what would I use UPnP for? I discovered a similar issue as the blog poster with my QNAP NAS which was easily remedied by disabling UPnP. I’ve not noticed any issues. We can do all the same things we did before. My Xbox and Switch still do online multiplayer just fine. I remember hearing Xbox/PS3-4 and UPnP mentioned together but it’s been a while.

UPnP allows devices to open up firewall ports for themselves to allow traffic to reach them inbound. Games (for example) that that host a server on the users local machine may require an open port to allow access inbound so UPnP can help with this. Now-a-days it's not used much and quite frankly it was always a fairly bad idea.

Nowadays you should use IPv6 anyway, which doesn't need NAT.
Post reply on HN