!tCyGickeVqkHsYjWnh:nixos.org

NixOS Networking

920 Members
Declaratively manage your switching, routing, wireless, tunneling and more.278 Servers

Load older messages


SenderMessageTime
21 Aug 2021
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zoneMaybe you misunderstand what I'm doing? There's no hole punching happening.02:38:53
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zoneAt least I can't see how I'm punching holes through anything.02:39:11
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zoneAre you telling me to turn off ipv6? 02:39:15
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zone * Are you telling me to turn off ipv6 for security reasons?02:39:29
@6aa4fd:tchncs.de6aa4fdno I'm saying I wouldn't open a port for ssh02:39:39
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zoneOh. In my view that is definitely overly paranoid.02:39:54
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zoneBut that is only my view.02:39:59
@6aa4fd:tchncs.de6aa4fdespecially not both ssh and VPN, it all adds to your attack surface02:39:59
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zoneYou have to open something. When you use a VPN you are also exposing some sort of port.02:40:20
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zoneYou simply prefer the VPN binary and its ports and networking. I prefer OpenSSH.02:40:35
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zoneBut both are binaries, both use networking, both require a single open port.02:40:51
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zoneDon't get me wrong, I like Wireguard and Tailscale, but those are only ran on machines I fully control.02:41:25
@6aa4fd:tchncs.de6aa4fdyeah sure, its a free country. anyways you can use any number of VPNs to get your 6 traffic through, and I guess not provide a default gateway for ipv6. now I'm not sure how granular some of these SLAAC/dhcpv6 tools are where you can force the default gateway off02:41:48
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zoneI don't have a 6 address. There is no traffic to "get through".02:42:09
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zoneMy ISP doesn't support ipv6, so I used 6in4 to give myself one, from hurricane electric.02:42:24
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zoneSo I don't know what you mean by that, I'm confused.02:42:36
@6aa4fd:tchncs.de6aa4fdyeah, I am saying VPN into a location where you do have a 6 prefix02:42:57
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zoneIf I could just set up a vpn, there'd be no point in using ipv6.02:42:59
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zoneipv6 means you don't need a vpn.02:43:07
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zoneIf I set up a vpn, there would be absolutely no need for this 6in4 business02:43:24
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zone * If I set up a vpn, there would be absolutely no need for this 6in4 business I am doing 02:43:26
@6aa4fd:tchncs.de6aa4fddude, your average coffee shop won't deliver your ipv6 traffic02:43:32
@6aa4fd:tchncs.de6aa4fdmaybe in the UK, not in the us02:43:51
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zoneDo you know what 6in4 is though?02:43:55
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zoneWhat control does the coffee shop have over my ipv6 traffic?02:44:05
@6aa4fd:tchncs.de6aa4fdit is a VPN02:44:06
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zoneYou could try to explain these things to me, rather than assume I know :P02:44:30
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zoneIf there's something I don't know about 6in4 that means it's not as cool as I think it is, please tell me02:44:50
@6aa4fd:tchncs.de6aa4fdyou said you want to take your computer out to other networks and use ipv6, I'm saying you need to have ipv6 support at the specific location02:44:54
@matthewcroughan:defenestrate.itmatthewcroughan - nix.zonethat is not true with 6in402:45:10

Show newer messages


Back to Room ListRoom Version: 6