Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The problem is that all NAT related issues are not because of NAT itself, but because of the required stateful firewalling for NAT.

To be able to NAT and un-NAT, you first need to classify traffic (that NEW, ESTABLISHED, RELATED,... stuff in Linux netfilter), changing the destination or source ip addresses is only the second part of that process.

Protocols don't break only because of NAT, but mostly because of stateful firewalling, you'll face the same problems with IPv6 if you enable it.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: