Live data from Hacker News

NAT Is the Enemy of Low Power Devices

blog.golioth.io

151–160 of 180 posts

Re: NAT Is the Enemy of Low Power Devices

#151
post #146
post #136

Earlier quoted context omitted.

I found it weird that IPv6 folks are so against NAT as a cultural thing when it works perfectly well on IPv6. They're not fundamentally opposed. I could have all of my servers in public subnets and give them all public IP addresses, but I still prefer to put everything I can in private. Not only does the firewall not allow traffic in, but you can't even route to them. It now becomes really hard to accidentally grant…

I'm not opposed to anyone voluntarily using a NAT at all. I just hate it when somebody makes that decision for me, and that unfortunately still happens all the time. If it's a well-reasoned decision, sure, but I do suspect that more often than not it's a lack of knowledge about alternatives that makes people still opt for NATs, and that just makes me sad on top of being annoyed with the inconvenience of having to tun…

How do you feel about NPT?

Re: NAT Is the Enemy of Low Power Devices

#152
post #142

Earlier quoted context omitted.

Almost 50% of internet traffic is IPv6. Obviously, those average people have a suitable firewall provided by default on their routers.

I think the vast majority of that is from phones?

It will vary by country, but for example all but one of the large broadband ISPs in the UK use IPv6.

Re: NAT Is the Enemy of Low Power Devices

#153
post #149

Earlier quoted context omitted.

Indeed, that sounds like an obvious feature. Hard to believe it hasn't been implemented! I'd love to have that feature on Linux desktop/laptops. I think you could make lots of applications behave a whole lot better.

the arguments from folks on the "architecture review boards" was that multiple connections are always bad and that developers can't be trusted. i'm willing to accept that they did get beat up quite a bit over power at various points when at times applications were a big part of the problem. That said this is also a gross misunderstanding of the problem and overall solution space, as well as very much gatekeeping.

Dump the entire queue to a google server (confirm receipt and shut down the connection) and then have the google server forward all the data to its destinations?

Seems to me that would be the lowest power, lowest developer trust, lowest number of connections, maximum gatekeeping method.

Re: NAT Is the Enemy of Low Power Devices

#154

Wasn't IPv6 suppose to solve all this? I don't understand why that stalled. Also considering the state of iot security its probably not a great idea to have everything accessible anyway. But that's a slightly different problem to solve.

It’s not going to solve a stateful firewall timing out.

You try to continue a tcp session that’s timed out on my firewall and the packets will be dropped.

This applies a fair amount t to me when I suspend my laptop, my ssh session will drop as both the server and the firewalls drop the session while it sits there peacefully. When it comes back the tcp packets get sent into the void.

Meanwhile my WireGuard connection which runs through two separate ipv4 nats works just fine, as it doesn’t rely on sessions or a server timing out a socket.

Nat is irrelevant to the problem.

Re: NAT Is the Enemy of Low Power Devices

#155
post #43

Earlier quoted context omitted.

An IPv6 router with a stateful firewall blocking incoming connections could have just the same issues with timeouts, I'd imagine. Switching to IPv6 doesn't just mean that anyone can make a P2P connection to anyone else (even STUN needs a third-party server to coordinate the two peers). (D)TLS session resumption (I'm not sure if their "Connection IDs" are that or something similar) seems like the most foolproof soluti…

But it'd be trivial to tell it to free the device from it, unlike with NAT, where you pretty much have to expire sessions to not run out of memory.

I have firewalls in v4 and v6 networks which don’t do any natting (well other than some 6-4 between them). They track sessions for security purposes, and they time them out for both security and memory reasons.

Re: NAT Is the Enemy of Low Power Devices

#156
post #35
post #20

The problem(-s) described in the blog post are really acute for IoT in general, especially if you want your device to run on batteries or you have a limited data budget. > Therefore, when you try to continue talking to the server over a previously established session, it will not recognize you. This means you’ll have to re-establish the session, which typically involves expensive cryptographic operations and sending…

What makes a separate cellular modem better than an internal cellular modem? Is it because software updates are available for the separate modems? I am evaluating some Nordic semiconductor parts for a project. They seem to have an internal modem but Nordic uses zephyr. Any thoughts?

Security.

On one hand, licensing requirements and regulation often mean that modems are locked down in terms of firmware updates, reference documentation, source, and capabilities. This often translates into a larger "black box" area, and one embedded inside your SoC instead of physically separate and connected over a serial bus.

On the other, on-chip modems often (not sure about those Nordics) have DMA.

The combination of those two is scary.

Re: NAT Is the Enemy of Low Power Devices

#157
post #91
post #49

Earlier quoted context omitted.

NAT was introduced by private company called Network Translation Inc. and successfully broke efforts to migrate off IPv4 (which was supposed to be EOLd by 1990) and permanently broke the "network of hosts" into asymmetric one of servers and clients. Note that we had a solution for address exhaustion by 1991, but it was just "good" and not "perfect" and worst of all it used the hated OSI protocol stack (TUBA - TCP & U…

People would have resisted TUBA the same ways they're resisting IPv6 now. It's not a technical problem.

It's partly technical (BSD Sockets being bad API that hard does low level proto ok details in applications) and partially business - vendors didn't want to do the work to upgrade software and hardware - especially with advent of CEF and similar hardware routing options. And by 1990s the government-led standardisation efforts that gave us widespread ethernet and IPv4 got axed, and efforts to make vendors update if only for federal contracts died in waiver hell.

The others kinds of problems are from there over time.

Re: NAT Is the Enemy of Low Power Devices

#158
post #136
post #100

Earlier quoted context omitted.

Sounds like you like the idea of a stateful firewall, and good news: There are stateful firewalls for IPv6! They have all the upsides of NATs (i.e. an option to block inbound connections by default), with none of the downsides (they preserve port numbers, can be implemented statelessly, they greatly simplify cooperative firewall traversal, you can allow inbound connections for some hosts).

I found it weird that IPv6 folks are so against NAT as a cultural thing when it works perfectly well on IPv6. They're not fundamentally opposed. I could have all of my servers in public subnets and give them all public IP addresses, but I still prefer to put everything I can in private. Not only does the firewall not allow traffic in, but you can't even route to them. It now becomes really hard to accidentally grant…

For a personal network where you decide to use NAT on ipv6? Sure, go ahead.

Being forced into a CGNAT on ipv6 is just a dick move though. And I believe that's the kinda NAT that has coloured the opinions of most NAT for ipv6 detractors.

Re: NAT Is the Enemy of Low Power Devices

#159
post #35

Earlier quoted context omitted.

What makes a separate cellular modem better than an internal cellular modem? Is it because software updates are available for the separate modems? I am evaluating some Nordic semiconductor parts for a project. They seem to have an internal modem but Nordic uses zephyr. Any thoughts?

cellular modems go nonfunctional/obsolete much faster than other systems. 3g is almost entirely gone worldwide. 4g is still around, but providers are already reducing how much their towers dedicate to it. The standards body is working on 6g, who knows when that will come and push out older stuff. If the case of my car I don't care - I have never found a use for the cellular connectivity it has (if any). However there…

4g should survive better than 2g and 3g, because the 5g standard allows for mixed mode deployments where the coordination channel runs as 4g, and the slots can be 4g or 5g dependening on what the client device is capable of. Running the coordination channel with 5g encoding could be a little more efficient, but it's not a big loss compared to running a minimum size 2g/3g allocation.

Re: NAT Is the Enemy of Low Power Devices

#160
post #97

What you can do is port forwarding. You have a bunch of devices behind a 1:N NAT, so they share one IP address. For specific services on those devices, you can pair dedicated ports with this IP address, binding them to internal IP:port pairs. It's not a perfect solution for every scenario, and requires configuration, but there it is. This is how people on residential lines run web servers, mail servers, ... they map…

With CG-NAT this doesn't work. Multiple customers are sharing the same IP address, all of which are sitting behind a NAT. Further the internet gateway is a NAT sitting behind the CG-NAT. And if you prefer to use a nice Mesh WiFi router, well that's a third NAT layer. Common suggestions I've heard: "Use a VPN" I tried to buy a computer from Apple directly. They detected the VPN and wouldn't let me purchase it. I turne…

I don't have my own external IP address (even if dynamic) + I want my devices to be spontaneously contactable from the network without polling anything from the inside = does not compute
Post reply on HN