I was wondering what are the options available for IPv6 to IPv6 NAT (nat66). It looks like it is not very common practice so there is not much information available. I am interested in setting up a nat pool to hide internal ipv6 addresses.
The reason for nat pool is that it still keeps the internal address anonymous. I have read a few things about NPTv6 but it seems like it does not allow for nat pool. I guess there are other options available for nat66 other than nptv6.
I also want to know if it is feasible and scalable to use ULA for internal network and do NAT66 for going out.
I also noticed that NPTv6 has a hardware limitation. It is only supported on CSR, ISR and ASR platforms. Is this also true for nat66?
With IPv6 Privacy Addressing, the ongoing changing of IPv6 addresses (interface ID) maintains privacy by periodically shifting the Interface ID, so you already have privacy, without need to use NAT.
NPTv6 just changes the network prefix, keeping the interface ID intact on both sides. This is a low-resoruce, stateless form of NAT. Regardagless, that should not be needed here.
Before you look in to NAT66 for ":anonymity" and "privacy" you should unpack what the need behind the need is. What is the use case you are defending against? You may find that NAT does not provide the anonymity that you imagine it does.
NPTv6 is designed for VERY high volume traffic (service provider) so needs hardware support. NAT6 has no such restriction, but it is resource intensive.
What you are proposing is not the best practice for IPv6 networks.
Learn how Cisco wireless assurance provides real-time and historical analytics for deep network visibility and simplified troubleshooting.
Learn how you can easily manage all of your connected devices and services and identify and solve issues before they...
I have a device connected to an access switch port. I would like to configure a net flow to gather the amount of traffic going via the interface. I will be sending all that data to SolarWinds. My question is how do I configure a netflow on WS-C6506. I tri...
Hello, We are working on a spare switch (with 12 fibre modules), which needs to be used as the failover switch in our company data centre. Cisco switch model : WS-C3750-12S(PowerPC405) Can you confirm the below : i. Does this switch su...
PRTG system in place running other sensors on the same host, which are working. Ive added syslog receiver sensor and receiving PRTG data from switch that increases drops, errors and warning stats that disappear after a few minutes. Within mess...
Hi, here is an example how to configure IP-NAT, GRE, IPSEC. I've seen plenty of questions and this might be a good solution! (Mostly the use of commands that might remind u) IP NAT======================================================================...