{"id":7358,"date":"2021-12-28T14:34:55","date_gmt":"2021-12-28T22:34:55","guid":{"rendered":"https:\/\/blogs.infoblox.com\/?p=7358"},"modified":"2025-04-02T12:03:35","modified_gmt":"2025-04-02T19:03:35","slug":"you-thought-there-was-no-nat-for-ipv6-but-nat-still-exists","status":"publish","type":"post","link":"https:\/\/www.infoblox.com\/blog\/ipv6-coe\/you-thought-there-was-no-nat-for-ipv6-but-nat-still-exists\/","title":{"rendered":"You Thought There Was No NAT for IPv6, But NAT Still Exists"},"content":{"rendered":"<p>One of the primary goals of humanity is not to repeat the same mistakes made in the past. The desire is to &#8220;fail forward&#8221; frequently in different ways on the path to continual improvement. Achieving <a href=\"https:\/\/www.infoblox.com\/solutions\/ipv6-readiness\/\" target=\"_blank\"><strong>IPV6 Readiness<\/strong><\/a> is a critical step for organizations seeking to modernize their networks and avoid the pitfalls of legacy protocols. When it comes to IPv6, the protocol designers wanted to avoid repeating the mistakes of IPv4; specifically, its limited address space that necessitates <a href=\"https:\/\/en.wikipedia.org\/wiki\/Network_address_translation\">Network Address Translation<\/a> (NAT). IPv6\u2019s 128-bit addresses ensure that the address space is large enough to provide unique addressing to every network and avoid any potential address overlaps, solidifying <a href=\"https:\/\/www.infoblox.com\/glossary\/ipv6\/\" target=\"_blank\"><strong>IPV6<\/strong><\/a> as the future of networking.<\/p>\n<p>IPv6 advocates have extolled the benefits of restoring the end-to-end model of communication originally conceived of by the early IPv4 protocol designers. IPv6 evangelists have also cautioned against using NAT with IPv6. However, many network and security architects are comfortable with the concept of NAT and may wonder why NAT doesn&#8217;t exist for IPv6.<\/p>\n<h3>Resisting the Urge to NAT IPv6<\/h3>\n<p>For decades, IPv6 purists have fought against establishing a standard for IPv6 NAT (e.g., IPv6 to IPv6 Network Address Translation or NAT66). Today, there isn&#8217;t even a pending draft of NAT66, much less a published IETF RFC. In addition, there is an IETF RFC titled &#8220;Local Network Protection for IPv6&#8221; (<a href=\"https:\/\/tools.ietf.org\/html\/rfc4864\">RFC 4864<\/a>) that lists all the reasons why NAT is not needed for IPv6.<\/p>\n<p>The primary argument against NAT66 is that IPv6 has plentiful address space that is globally unique, so the need for more address space is not an issue. There is no need for <a href=\"https:\/\/en.wikipedia.org\/wiki\/Network_address_translation#MASQUERADING\">Port Address Translation<\/a> (PAT) (a.k.a. NAPT\/one-to-many NAT\/masquerading) functionality in IPv6 to extend the address space or avoid address conflicts.<\/p>\n<p>Another argument against NAT66 is aimed at security architects that conflate the stateful packet filtering performed by firewalls with IPv4 NAT functionality. Stateful packet filtering can provide the same level of security for IPv6 as it does for IPv4, just without the NAT function. It is a myth that &#8220;<a href=\"https:\/\/www.internetsociety.org\/blog\/2015\/01\/ipv6-security-myth-3-no-ipv6-nat-means-less-security\/\">No IPv6 NAT Means Less Security.<\/a>\u201d<\/p>\n<p>We are well aware of how NAT adds complexity for IPv4 networks. NAT ends up <a href=\"https:\/\/blogs.infoblox.com\/ipv6-coe\/ipv4-addresses-are-only-locally-significant\/\">making IPv4 addresses &#8220;locally significant&#8221;<\/a> as address overlaps are commonplace. NAT can cause problems for applications that require end-to-end native connectivity and embed addresses inside the protocol payload (e.g., FTP, IPsec, SIP, RTSP, SAP, SCTP, DCCP, etc.). Other protocols, like HTTP and HTTPS, are designed to tolerate NATs along the traffic path.<\/p>\n<p><a href=\"https:\/\/www.networkworld.com\/article\/2228420\/cisco-subnet-when-it-comes-to-ipv6-go-native.html\">IPv6 native connectivity<\/a> can exist between nodes on both private networks behind firewalls as well as across the Internet. NAT can be avoided in IPv6 networks and NAT is not needed or recommended.<\/p>\n<h3>Network Prefix Translation for IPv6 (NPTv6)<\/h3>\n<p>There actually were early IETF drafts for <a href=\"https:\/\/tools.ietf.org\/html\/draft-mrw-behave-nat66-02\">IPv6-to-IPv6 Network Address Translation (NAT66)<\/a> put forth for consideration, but the decisions were to not repeat the IPv4 NAT mistake. What the IETF eventually agreed upon was something called &#8220;IPv6-to-IPv6 Network Prefix Translation&#8221; (RFC 6296). Note the subtlety in the RFC title where the word &#8220;Prefix&#8221; takes the place of the word &#8220;Address&#8221;.<\/p>\n<p>Instead of performing a stateful NAT66 function, NPTv6 statelessly translates source address from one prefix to another prefix. This is a 1:1 mapping of the source address to the destination, and back again. NPTv6 simply copies the low-order part of the IPv6 address in packets traversing its two interfaces, while the rest of high-order part of the IPv6 address remains. Below is a picture that shows the part of the IPv6 address that is translated and the part that is copied.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-7359\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/NAT-1.png\" alt=\"\" width=\"3900\" height=\"1692\" srcset=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/NAT-1.png 3900w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/NAT-1-300x130.png 300w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/NAT-1-1024x444.png 1024w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/NAT-1-768x333.png 768w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/NAT-1-1536x666.png 1536w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/NAT-1-2048x889.png 2048w\" sizes=\"auto, (max-width: 3900px) 100vw, 3900px\" \/><\/p>\n<p>The diagram above shows use of fd00::\/8 IPv6 Unique Local Addresses (ULA) (<a href=\"https:\/\/datatracker.ietf.org\/doc\/html\/rfc4193\">RFC 4193<\/a>).\u00a0 This type of a scenario is often shown as a method for small-medium sized businesses (SMBs) to avoid vendor lock-in if their one ISP furnishes them with Provider Assigned (PA) IPv6 addresses.\u00a0 For larger enterprises, it is recommended to use global unicast IPv6 addresses without NAT, <a href=\"https:\/\/blogs.infoblox.com\/ipv6-coe\/ipv6-ula-and-nat-is-it-better-than-global-unicast\/\">rather than to use ULA IPv6 addresses with NAT<\/a>.\u00a0 Furthermore, <a href=\"https:\/\/blogs.infoblox.com\/ipv6-coe\/3-ways-to-ruin-your-future-network-with-ipv6-unique-local\/\">using ULA IPv6 addresses is frequently discouraged<\/a>.<\/p>\n<p>There are some network and security devices that now support NPTv6.\u00a0 Following are the vendors and their products that my research has discovered (but there could be others).<\/p>\n<ul>\n<li>You can configure <a href=\"https:\/\/urldefense.com\/v3\/__https:\/\/docs.vyos.io\/en\/equuleus\/configuration\/nat\/nptv6.html__;!!JYsgTRAg6ZQ!b_miNF8EukjB4Ob5UQQ9zscd4E5mV50PaCIgoW2-rsJXnS0Bv4w0Uz6C_bEPfer4$\">NPTv6 on a router running VyOS<\/a>.<\/li>\n<li>Palo Alto Networks firewalls running <a href=\"https:\/\/docs.paloaltonetworks.com\/pan-os\/8-1\/pan-os-admin\/networking\/nptv6\/nptv6-overview.html\">PAN-OS support NPTv6<\/a>, but they can\u2019t do NAT66.<\/li>\n<li><a href=\"http:\/\/www.cisco.com\/c\/en\/us\/td\/docs\/ios-xml\/ios\/ipaddr_nat\/configuration\/xe-16\/nat-xe-16-book\/iadnat-asr1k-nptv6.html\">NPTv6 is supported on various Cisco routers<\/a> (ASR1k\/CSR1k\/ISR4k) running IOS-XE.<\/li>\n<li><a href=\"https:\/\/www.juniper.net\/documentation\/us\/en\/software\/junos\/interfaces-next-gen-services\/topics\/topic-map\/nptv6-usf.html\">Juniper routers running Junos<\/a> can perform NPTv6.<\/li>\n<li>A10 Networks devices <a href=\"http:\/\/acos.docs.a10networks.com\/axapi\/521\/interface_ethernet_nptv6.html\">can perform NPTv6<\/a>.<\/li>\n<li>OPNsense <a href=\"https:\/\/docs.opnsense.org\/manual\/nptv6.html\">firewall and routing software can do NPTv6<\/a>.<\/li>\n<li>pfSense firewalls <a href=\"https:\/\/docs.netgate.com\/pfsense\/en\/latest\/nat\/npt.html\">run what they call NPt<\/a>.<\/li>\n<\/ul>\n<h3>NAT66 Can Be Useful<\/h3>\n<p>Leveraging IPv6 capabilities provides enhanced <a href=\"https:\/\/www.infoblox.com\/products\/network-insight\/\" target=\"_blank\"><strong>Network Insight<\/strong><\/a>, enabling network operators to maintain efficiency and security in dual-stack environments.\u00a0 Since most organizations are familiar and comfortable with IPv4 NAT (a.k.a. NAT44), they can\u2019t be blamed for wanting to have that same functionality in their IPv6 implementation.<\/p>\n<p>In reality, NAT66 can be beneficial is some circumstances.\u00a0 For example, NAT66 could be used when there is a desire to maintain routing symmetry, similar to how NAT44 is being used in a network today.\u00a0 There could be a situation when an organization has a \u201cpool\u201d of clustered redundant firewalls (or middle-boxes) and IPv4 NAT is used to help maintain state.\u00a0 Some extremely large organizations may have large firewall \u201cfarms\u201d and it may be undetermined which firewall the traffic goes through.\u00a0 The NAT44 functionality ensures that the return traffic comes back through the firewall that was used to forward the traffic, thus maintaining state and routing symmetry.<\/p>\n<p>With IPv6 and global addresses, and no NAT, the traffic could leave one firewall and come back to a different firewall because NAT66 isn\u2019t being performed. \u00a0In this situation the IPv6 traffic may not work well during a firewall failure scenario, or traffic could be asymmetric.\u00a0 If NAT66 was a configurable option, then the same highly available network firewall architecture would allow for congruent traffic paths for IPv4 and IPv6.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-7360\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/NAT-2.png\" alt=\"\" width=\"3900\" height=\"1559\" srcset=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/NAT-2.png 3900w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/NAT-2-300x120.png 300w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/NAT-2-1024x409.png 1024w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/NAT-2-768x307.png 768w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/NAT-2-1536x614.png 1536w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/NAT-2-2048x819.png 2048w\" sizes=\"auto, (max-width: 3900px) 100vw, 3900px\" \/><\/p>\n<p>Many smaller organizations, like SMBs, don\u2019t use the Border Gateway Protocol (BGP) routing protocol with an Autonomous System Number (ASN) and only have a single ISP.\u00a0 As we mentioned earlier, if the Regional Internet Registry\u2019s (RIR\u2019s) policies won\u2019t provide them a Provider Independent (PI) IPv6 address block, or their ISP won\u2019t route a PI block for them, then the SMB would experience vendor lock-in using the ISP\u2019s Provider Assigned (PA) IPv6 address space.\u00a0 Some SMBs use dual ISP links for redundancy (one primary, one backup) and they have one default route advertised internally by the primary firewall, and a second backup default route advertised by the secondary firewall.\u00a0 They use NAT44 to keep the returning traffic coming back to the stateful NAT44 device that allowed the originating outbound connection.\u00a0 If the primary firewall fails, the secondary firewall takes over and connectivity is maintained.\u00a0 You can see why an SMB may want to have NAT66 in a situation like this.<\/p>\n<p>It is still possible to use traditional stateful proxies and Application Layer Gateways (ALGs) to broker connections from one IPv6 network to another IPv6 network.\u00a0 It should also be mentioned that outbound web proxies (like web content filters, a.k.a. Secure Web Gateways (SWGs)) and inbound reverse proxies (like server load balancers) perform a NAT-like behavior.\u00a0 These systems aren\u2019t performing a NAT66 function, per se.\u00a0 They are actually terminating the TCP connection on one interface and establishing a new TCP connection using the other interface.\u00a0 This has the effect of changing the source address as the connection is made through the proxy.<\/p>\n<h3>NAT66 Exists<\/h3>\n<p>Contrary to popular belief, there are ways to perform NAT with IPv6, and vendors have implemented NAT66 into their products \u2013 even touting NAT66 on their product data sheets.\u00a0 Even though the IPv6 purists cringe when NAT66 is mentioned, and the IETF has not formally created an RFC to define how it should function, implementations of NAT66 still exist.<\/p>\n<p>These vendors have implemented NAT66 in their products without there being a formal standard to guide their code development to ensure interoperability.\u00a0 The concern here is that each vendor\u2019s products may not behave the same and that there could be resulting interoperability issues.<\/p>\n<p>It should also be mentioned that the IETF has laid some groundwork for NAT66.\u00a0 The <a href=\"https:\/\/en.wikipedia.org\/wiki\/Port_Control_Protocol\">Port Control Protocol<\/a> (PCP) (<a href=\"https:\/\/datatracker.ietf.org\/doc\/html\/rfc6887\">RFC 6887<\/a>) specification does allow for an IPv6 host to learn how NAT is performed.\u00a0 PCP can also be used to share the NAT64 PREF64 with IPv6-only nodes so they can use DNS64\/NAT64 to reach IPv4-only services (<a href=\"https:\/\/datatracker.ietf.org\/doc\/html\/rfc7225\">RFC 7225<\/a>).\u00a0 There is even a DHCPv4 and DHCPv6 option for PCP (<a href=\"https:\/\/datatracker.ietf.org\/doc\/html\/rfc7291\">RFC 7291<\/a>).<\/p>\n<p>Here is a list of the various systems that support NAT66 and how to configure them.<\/p>\n<ul>\n<li>Fortinet FortiGate firewalls support <a href=\"https:\/\/help.fortinet.com\/fos50hlp\/52data\/Content\/FortiOS\/fortigate-firewall-52\/Concepts\/NAT%2066.htm\">NAT66<\/a> along with <a href=\"https:\/\/docs.fortinet.com\/document\/fortigate\/6.0.0\/handbook\/754171\/nat66-nat64-nat46-and-dns64\">NAT64 and NAT46<\/a>.<\/li>\n<li>Cisco <a href=\"https:\/\/www.cisco.com\/c\/en\/us\/td\/docs\/security\/asa\/asa96\/configuration\/firewall\/asa-96-firewall-config\/nat-reference.html\">ASA firewalls<\/a> also support NAT66<\/li>\n<li>NAT66 is configurable on <a href=\"https:\/\/www.juniper.net\/documentation\/en_US\/junos\/topics\/task\/configuration\/nat-static-source-translation-ipv6-networks.html\">Juniper Junos routers<\/a>.<\/li>\n<li>Juniper <a href=\"https:\/\/www.youtube.com\/watch?v=PIWfScx6EQs&amp;ab_channel=JuniperNetworks\">SRX firewalls also support IPv6 source NAT<\/a>.<\/li>\n<li>NAT66 is configurable on an <a href=\"https:\/\/devcentral.f5.com\/s\/question\/0D51T00006j4hZw\/nat-ipv6-to-ipv6-nat66\">F5 BIG-IP (LTM) system<\/a>.<\/li>\n<li>Check Point firewalls running <a href=\"https:\/\/community.checkpoint.com\/t5\/General-Topics\/IPv6-NAT-Support\/td-p\/5012\">R76 or newer support NAT66<\/a>.<\/li>\n<li>NAT66 is <a href=\"https:\/\/openwrt.org\/docs\/guide-user\/network\/ipv6\/ipv6.nat6\">supported on OpenWrt<\/a>.<\/li>\n<li>NAT66 works on a H3C SecPath Firewall (<a href=\"http:\/\/www.h3c.com\/en\/Support\/Resource_Center\/EN\/Home\/Security\/00-Public\/Command\/Command_References\/H3C_SecPath_Firewall_CR(V7)-6W400\/00\/\">command ref<\/a> and <a href=\"http:\/\/www.h3c.com\/en\/Support\/Resource_Center\/EN\/Home\/Security\/00-Public\/Configure\/Configuration_Guides\/H3C_SecPath_Firewall_CG(V7)-6W400\/00\/\">config guide<\/a>).<\/li>\n<li>NAT66 can be <a href=\"https:\/\/www.sonicwall.com\/support\/knowledge-base\/lan-to-wan-ipv6-traffic-need-manually-add-nat-policy\/170505534672880\/\">configured on a SonicWall<\/a>.<\/li>\n<\/ul>\n<h3>Configuring NAT66 with ip6tables<\/h3>\n<p>One of the easiest ways to configure NAT66 is using a Linux system running <a href=\"https:\/\/www.netfilter.org\/\">netfilter<\/a> (ip6tables).\u00a0 On Linux systems, ip6tables has supported NAT since version 1.4.18.\u00a0 There are some useful examples (by <a href=\"https:\/\/blog.apnic.net\/2018\/02\/02\/nat66-good-bad-ugly\/\">Marco Cilloni<\/a> and <a href=\"https:\/\/packetpushers.net\/thank-goodness-for-nat66\/\">Jeff Loughridge<\/a>) of how to configure NAT66 with ip6tables.<\/p>\n<p>To start, simply configure the system with IPv6-enabled interfaces and verify IPv6 network reachability.\u00a0 Configure an IPv6 default route (::\/0) toward the outside interface and internal IPv6 routes as necessary.<\/p>\n<p>Next, enable IPv6 forwarding in the kernel using this command.<\/p>\n<p><strong>sysctl -w net.ipv6.conf.all.forwarding=1<\/strong><\/p>\n<p>And, to make IPv6 forwarding permanent, uncomment this line in the \/etc\/sysctl.conf file.<\/p>\n<p><strong>vi \/etc\/sysctl.conf<\/strong><\/p>\n<p><strong>net.ipv6.conf.all.forwarding=1<\/strong><\/p>\n<p>The next step is to configure ip6tables to perform a &#8220;masquerade&#8221; function, just like is commonly performed with iptables.<\/p>\n<p><strong>ip6tables -t nat -A POSTROUTING -o $OUTSIDE -j MASQUERADE<\/strong><\/p>\n<p><strong>ip6tables -A FORWARD -i $OUTSIDE -o $INSIDE -m state &#8211;state RELATED,ESTABLISHED -j ACCEPT<\/strong><\/p>\n<p><strong>ip6tables -A FORWARD -i $INSIDE -o $OUTSIDE -j ACCEPT<\/strong><\/p>\n<p>Now we can check the ip6tables configuration and look at connections passing through this system with the following commands.<\/p>\n<p><strong>ip6tables -S -t nat<\/strong><\/p>\n<p><strong>ip6tables -t nat -nvL<\/strong><\/p>\n<p><strong>conntrack -f ipv6 \u2013L<\/strong><\/p>\n<p>Voila!\u00a0 NAT66.<\/p>\n<h3>Summary<\/h3>\n<p>Organizations that currently have symmetric routing with IPv4 NAT may want the same functionality in IPv6 with NAT66.\u00a0 IPv6 purists would do well to remember Aesop\u2019s fable about <a href=\"https:\/\/en.wikipedia.org\/wiki\/The_Oak_and_the_Reed\">the oak and the reed<\/a>: It may be better to bend and allow NAT66, rather than be steadfast and break in resisting the goals and desires of numerous network operators who feel their working lives will be made easier with NAT66.<\/p>\n<p>Whether we wanted NAT66 or not, we already have it.\u00a0 Vendors have gone ahead and implemented NAT66 in the absence of a standard method for this functionality.\u00a0 The IETF can either standardize NAT66 or we must be content with a world where there are numerous different implementations of NAT66. Establishing an <a href=\"https:\/\/www.infoblox.com\/solutions\/ipv6-readiness\/ipv6-center-excellence\/\" target=\"_blank\"><strong>IPv6 Center of Excellence<\/strong><\/a> ensures standardized practices and effective IPv6 deployment, preventing fragmentation in implementation.<\/p>\n<p>But should you deploy NAT66? While it is important to acknowledge its existence, it should be re-iterated that using global IPv6 addresses without NAT is still the recommended approach.\u00a0 NAT66 really isn&#8217;t needed, except in some rare corner cases, and should be avoided where at all possible.\u00a0 But it is important to admit\u2026 that NAT66 does exist.<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>One of the primary goals of humanity is not to repeat the same mistakes made in the past. The desire is to &#8220;fail forward&#8221; frequently in different ways on the path to continual improvement. Achieving IPV6 Readiness is a critical step for organizations seeking to modernize their networks and avoid the pitfalls of legacy protocols. [&hellip;]<\/p>\n","protected":false},"author":321,"featured_media":7079,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"_genesis_hide_title":false,"_genesis_hide_breadcrumbs":false,"_genesis_hide_singular_image":false,"_genesis_hide_footer_widgets":false,"_genesis_custom_body_class":"","_genesis_custom_post_class":"","_genesis_layout":"","footnotes":""},"categories":[17],"tags":[617,38,618,619],"class_list":{"0":"post-7358","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-ipv6-coe","8":"tag-nat","9":"tag-ipv6","10":"tag-nat66","11":"tag-rfc-6296","12":"entry"},"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.3 (Yoast SEO v27.3) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>You Thought There Was No NAT for IPv6, But NAT Still Exists<\/title>\n<meta name=\"description\" content=\"There are recommended approaches to best utilize global IPv6 addresses with NAT66. Read this article to find out when NAT66 can be used most appropriately.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.infoblox.com\/blog\/ipv6-coe\/you-thought-there-was-no-nat-for-ipv6-but-nat-still-exists\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"You Thought There Was No NAT for IPv6, But NAT Still Exists\" \/>\n<meta property=\"og:description\" content=\"There are recommended approaches to best utilize global IPv6 addresses with NAT66. Read this article to find out when NAT66 can be used most appropriately.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.infoblox.com\/blog\/ipv6-coe\/you-thought-there-was-no-nat-for-ipv6-but-nat-still-exists\/\" \/>\n<meta property=\"og:site_name\" content=\"Infoblox Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-12-28T22:34:55+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-04-02T19:03:35+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/survivability-4.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1275\" \/>\n\t<meta property=\"og:image:height\" content=\"734\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Scott Hogg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Scott Hogg\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/ipv6-coe\\\/you-thought-there-was-no-nat-for-ipv6-but-nat-still-exists\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/ipv6-coe\\\/you-thought-there-was-no-nat-for-ipv6-but-nat-still-exists\\\/\"},\"author\":{\"name\":\"Scott Hogg\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/person\\\/ee71ac61fe2ea349f6e991e628d22f4c\"},\"headline\":\"You Thought There Was No NAT for IPv6, But NAT Still Exists\",\"datePublished\":\"2021-12-28T22:34:55+00:00\",\"dateModified\":\"2025-04-02T19:03:35+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/ipv6-coe\\\/you-thought-there-was-no-nat-for-ipv6-but-nat-still-exists\\\/\"},\"wordCount\":1952,\"publisher\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/ipv6-coe\\\/you-thought-there-was-no-nat-for-ipv6-but-nat-still-exists\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/survivability-4.jpg\",\"keywords\":[\"NAT\",\"IPv6\",\"NAT66\",\"RFC 6296\"],\"articleSection\":[\"IPv6 CoE\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/ipv6-coe\\\/you-thought-there-was-no-nat-for-ipv6-but-nat-still-exists\\\/\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/ipv6-coe\\\/you-thought-there-was-no-nat-for-ipv6-but-nat-still-exists\\\/\",\"name\":\"You Thought There Was No NAT for IPv6, But NAT Still Exists\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/ipv6-coe\\\/you-thought-there-was-no-nat-for-ipv6-but-nat-still-exists\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/ipv6-coe\\\/you-thought-there-was-no-nat-for-ipv6-but-nat-still-exists\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/survivability-4.jpg\",\"datePublished\":\"2021-12-28T22:34:55+00:00\",\"dateModified\":\"2025-04-02T19:03:35+00:00\",\"description\":\"There are recommended approaches to best utilize global IPv6 addresses with NAT66. Read this article to find out when NAT66 can be used most appropriately.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/ipv6-coe\\\/you-thought-there-was-no-nat-for-ipv6-but-nat-still-exists\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/ipv6-coe\\\/you-thought-there-was-no-nat-for-ipv6-but-nat-still-exists\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/ipv6-coe\\\/you-thought-there-was-no-nat-for-ipv6-but-nat-still-exists\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/survivability-4.jpg\",\"contentUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/survivability-4.jpg\",\"width\":1275,\"height\":734},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/ipv6-coe\\\/you-thought-there-was-no-nat-for-ipv6-but-nat-still-exists\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"IPv6 CoE\",\"item\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/category\\\/ipv6-coe\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"You Thought There Was No NAT for IPv6, But NAT Still Exists\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/\",\"name\":\"infoblox.com\\\/blog\\\/\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#organization\",\"name\":\"Infoblox\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/infoblox-logo-2.svg\",\"contentUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/infoblox-logo-2.svg\",\"width\":137,\"height\":30,\"caption\":\"Infoblox\"},\"image\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/person\\\/ee71ac61fe2ea349f6e991e628d22f4c\",\"name\":\"Scott Hogg\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/blogs.infoblox.com\\\/wp-content\\\/uploads\\\/avatar_user_321_1574118215-96x96.jpg\",\"url\":\"https:\\\/\\\/blogs.infoblox.com\\\/wp-content\\\/uploads\\\/avatar_user_321_1574118215-96x96.jpg\",\"contentUrl\":\"https:\\\/\\\/blogs.infoblox.com\\\/wp-content\\\/uploads\\\/avatar_user_321_1574118215-96x96.jpg\",\"caption\":\"Scott Hogg\"},\"description\":\"Scott Hogg has 30 years of network and security experience and is president of Hogg Networking with. Scott Hogg specializes in teaching Internet Protocol version 6 (IPv6) and providing implementation guidance. Scott is CCIE #5133 (Emeritus) and CISSP #4610. Scott is Chair Emeritus of the Rocky Mountain IPv6 Task Force (RMv6TF), a member of the IPv6 Center of Excellence (COE), and co-author of the Cisco Press book on IPv6 Security.\",\"sameAs\":[\"https:\\\/\\\/hexabuild.io\"],\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/author\\\/scott-hogg\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"You Thought There Was No NAT for IPv6, But NAT Still Exists","description":"There are recommended approaches to best utilize global IPv6 addresses with NAT66. Read this article to find out when NAT66 can be used most appropriately.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.infoblox.com\/blog\/ipv6-coe\/you-thought-there-was-no-nat-for-ipv6-but-nat-still-exists\/","og_locale":"en_US","og_type":"article","og_title":"You Thought There Was No NAT for IPv6, But NAT Still Exists","og_description":"There are recommended approaches to best utilize global IPv6 addresses with NAT66. Read this article to find out when NAT66 can be used most appropriately.","og_url":"https:\/\/www.infoblox.com\/blog\/ipv6-coe\/you-thought-there-was-no-nat-for-ipv6-but-nat-still-exists\/","og_site_name":"Infoblox Blog","article_published_time":"2021-12-28T22:34:55+00:00","article_modified_time":"2025-04-02T19:03:35+00:00","og_image":[{"width":1275,"height":734,"url":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/survivability-4.jpg","type":"image\/jpeg"}],"author":"Scott Hogg","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Scott Hogg","Est. reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.infoblox.com\/blog\/ipv6-coe\/you-thought-there-was-no-nat-for-ipv6-but-nat-still-exists\/#article","isPartOf":{"@id":"https:\/\/www.infoblox.com\/blog\/ipv6-coe\/you-thought-there-was-no-nat-for-ipv6-but-nat-still-exists\/"},"author":{"name":"Scott Hogg","@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/person\/ee71ac61fe2ea349f6e991e628d22f4c"},"headline":"You Thought There Was No NAT for IPv6, But NAT Still Exists","datePublished":"2021-12-28T22:34:55+00:00","dateModified":"2025-04-02T19:03:35+00:00","mainEntityOfPage":{"@id":"https:\/\/www.infoblox.com\/blog\/ipv6-coe\/you-thought-there-was-no-nat-for-ipv6-but-nat-still-exists\/"},"wordCount":1952,"publisher":{"@id":"https:\/\/www.infoblox.com\/blog\/#organization"},"image":{"@id":"https:\/\/www.infoblox.com\/blog\/ipv6-coe\/you-thought-there-was-no-nat-for-ipv6-but-nat-still-exists\/#primaryimage"},"thumbnailUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/survivability-4.jpg","keywords":["NAT","IPv6","NAT66","RFC 6296"],"articleSection":["IPv6 CoE"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.infoblox.com\/blog\/ipv6-coe\/you-thought-there-was-no-nat-for-ipv6-but-nat-still-exists\/","url":"https:\/\/www.infoblox.com\/blog\/ipv6-coe\/you-thought-there-was-no-nat-for-ipv6-but-nat-still-exists\/","name":"You Thought There Was No NAT for IPv6, But NAT Still Exists","isPartOf":{"@id":"https:\/\/www.infoblox.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.infoblox.com\/blog\/ipv6-coe\/you-thought-there-was-no-nat-for-ipv6-but-nat-still-exists\/#primaryimage"},"image":{"@id":"https:\/\/www.infoblox.com\/blog\/ipv6-coe\/you-thought-there-was-no-nat-for-ipv6-but-nat-still-exists\/#primaryimage"},"thumbnailUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/survivability-4.jpg","datePublished":"2021-12-28T22:34:55+00:00","dateModified":"2025-04-02T19:03:35+00:00","description":"There are recommended approaches to best utilize global IPv6 addresses with NAT66. Read this article to find out when NAT66 can be used most appropriately.","breadcrumb":{"@id":"https:\/\/www.infoblox.com\/blog\/ipv6-coe\/you-thought-there-was-no-nat-for-ipv6-but-nat-still-exists\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.infoblox.com\/blog\/ipv6-coe\/you-thought-there-was-no-nat-for-ipv6-but-nat-still-exists\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.infoblox.com\/blog\/ipv6-coe\/you-thought-there-was-no-nat-for-ipv6-but-nat-still-exists\/#primaryimage","url":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/survivability-4.jpg","contentUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/survivability-4.jpg","width":1275,"height":734},{"@type":"BreadcrumbList","@id":"https:\/\/www.infoblox.com\/blog\/ipv6-coe\/you-thought-there-was-no-nat-for-ipv6-but-nat-still-exists\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.infoblox.com\/blog\/"},{"@type":"ListItem","position":2,"name":"IPv6 CoE","item":"https:\/\/www.infoblox.com\/blog\/category\/ipv6-coe\/"},{"@type":"ListItem","position":3,"name":"You Thought There Was No NAT for IPv6, But NAT Still Exists"}]},{"@type":"WebSite","@id":"https:\/\/www.infoblox.com\/blog\/#website","url":"https:\/\/www.infoblox.com\/blog\/","name":"infoblox.com\/blog\/","description":"","publisher":{"@id":"https:\/\/www.infoblox.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.infoblox.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.infoblox.com\/blog\/#organization","name":"Infoblox","url":"https:\/\/www.infoblox.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/infoblox-logo-2.svg","contentUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/infoblox-logo-2.svg","width":137,"height":30,"caption":"Infoblox"},"image":{"@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/person\/ee71ac61fe2ea349f6e991e628d22f4c","name":"Scott Hogg","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/avatar_user_321_1574118215-96x96.jpg","url":"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/avatar_user_321_1574118215-96x96.jpg","contentUrl":"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/avatar_user_321_1574118215-96x96.jpg","caption":"Scott Hogg"},"description":"Scott Hogg has 30 years of network and security experience and is president of Hogg Networking with. Scott Hogg specializes in teaching Internet Protocol version 6 (IPv6) and providing implementation guidance. Scott is CCIE #5133 (Emeritus) and CISSP #4610. Scott is Chair Emeritus of the Rocky Mountain IPv6 Task Force (RMv6TF), a member of the IPv6 Center of Excellence (COE), and co-author of the Cisco Press book on IPv6 Security.","sameAs":["https:\/\/hexabuild.io"],"url":"https:\/\/www.infoblox.com\/blog\/author\/scott-hogg\/"}]}},"_links":{"self":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts\/7358","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/users\/321"}],"replies":[{"embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/comments?post=7358"}],"version-history":[{"count":6,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts\/7358\/revisions"}],"predecessor-version":[{"id":11361,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts\/7358\/revisions\/11361"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/media\/7079"}],"wp:attachment":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/media?parent=7358"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/categories?post=7358"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/tags?post=7358"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}