Hacker Newsnew | past | comments | ask | show | jobs | submit | lockywolf's commentslogin

Double NAT is now almost everywhere in the world, except maybe USA.


What kind of Nat though? You can use upnp, predictable mapping, etc. and still allow the traffic through. And that's only with ipv4, because you can run zerotier over IPv6.


> What kind of Nat though? You can use upnp, predictable mapping, etc. and still allow the traffic through.

Your computer can talk to your home router (CPE) and punch a hole for a connection, but if your WAN port does not have a public IP address, but rather itself also has a private address (probably 100.64/10), the CPE cannot talk to the ISP's router to punch a hole:

* https://en.wikipedia.org/wiki/Carrier-grade_NAT

The two layers of NAT (home network (192.168) -> CPE NAT (100.64/10) -> ISP NAT ('real' public IPv4)) prevent hole punching.


Double Nat on one side is not that universal. Across Europe and Australia I've seen it maybe once on a residential connection. I'm sure it's used, but the comment about the US in the post above just doesn't match my experience.


Great for you for not having to experience it, but that doesn't mean it sucks any less for those less fortunate:

> Our [Native American] tribal network started out IPv6, but soon learned we had to somehow support IPv4 only traffic. It took almost 11 months in order to get a small amount of IPv4 addresses allocated for this use. In fact there were only enough addresses to cover maybe 1% of population. So we were forced to create a very expensive proxy/translation server in order to support this traffic.

> We learned a very expensive lesson. 71% of the IPv4 traffic we were supporting was from ROKU devices. 9% coming from DishNetwork & DirectTV satellite tuners, 11% from HomeSecurity cameras and systems, and remaining 9% we replaced extremely outdated Point of Sale(POS) equipment. So we cut ROKU some slack three years ago by spending a little over $300k just to support their devices.

* https://community.roku.com/t5/Features-settings-updates/It-s...

* Discussion: https://news.ycombinator.com/item?id=35047624


You can't over double NAT because the second layer of NAT is not going to support UPnP


The vast majority of CGNATs across the world don't support the PCP protocol for predictable mapping.


foreseeable yet still somewhat surprising that having a clean v4 address on the cpe has become a very privileged position.

just the other day i was discouraging a youngster from manually populating his hosts-file in order to circumvent a dmca-related dns block.... what has the world come to.


My ISP deployed ipv6 via serving ULAs to clients behind the ISP box, and doing a NAT to a single dynamic public IP.

Another one just blocks all incoming connections on ipv6 entirely.


The comments are brilliant and nail this idiotic research perefectly.

One more thing to note: 6 women aged 22-25, so the title should have included "young fertile women".

And still one more: a research on 25 subjects is laughable. 25 000 would make a little more sense.


Wordpress is easy... if you want it to do what it expects you to want.

Writing an article in WordPress is easy... if you have persistent Internet access. I often don't.

Or, suppose, you want to migrate to a different hosting provider. Something very easy suddenly becomes very hard.

Or you find out that something you were writing about would become illegal. Good luck taking down your wordpress and reading through the content in the browser, with no grep.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: