Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Is IPV6/IPV4 (noNAT) "stateful" from the firewall perspective?

    Scheduled Pinned Locked Moved Firewalling
    3 Posts 2 Posters 364 Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • N8LBVN Offline
      N8LBV
      last edited by

      I'm a bit new to IPV6. And extremely new at trying to get a better understanding.
      I have been managing IPV4 and NAT since around the year 2000.
      IPV6 gets rid of NAT.

      IPV6 is simply routed through PFsense (or so I thought).
      Same deal if we were routing IPV4 with no NAT.

      Without NAT does ever routed packet/connection maintain a state on the firewall?
      I feel like and idiot for even having to ask.

      And do you have similar rules available when not using NAT? Like outbound connections ok inbound connections originated NOT ok etc?
      I'm guessing maybe this is default behavior and exceptions would have to be made.
      This is embarrassing how much I have become dependent on NAT and never even think about it.
      But starting to play with IPV6 and learn it.
      And a silly as this is I need to get back in touch with not using NAT.
      It's ben MANY years. :)

      Thanks
      Steve

      I feel more like I do now.

      S 1 Reply Last reply Reply Quote 0
      • S Offline
        SteveITS Rebel Alliance @N8LBV
        last edited by

        @n8lbv Yep. See Diagnostics/States. Firewall rules apply on whichever interface they are set. WAN defaults to no rules i.e. block all, as do all interfaces besides LAN.

        Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
        When upgrading, allow 10-15 minutes to reboot, or more depending on packages, and device or disk speed.
        Upvote 👍 helpful posts!

        N8LBVN 1 Reply Last reply Reply Quote 0
        • N8LBVN Offline
          N8LBV @SteveITS
          last edited by

          @steveits It's pretty funny as I sort of know this.
          But feel I had to ask or double check.
          I've been using NAT since 23 years ago.
          It feels strange to actually route something.
          :)

          I feel more like I do now.

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.