I think Network Address Translation (NAT), which translates private and public IP addresses, is unnecessary overhead that will go away with IPv6. The elimination of NAT with IPv6 will offer major technical benefits by restoring the end-to-end principal of the Internet. With IPv6, enterprises will also get closer to end-to-end protection since the IPsec tunnel can initiate and terminate on the respective communication nodes; no intermediate gateway termination must take place. Additionally, the Authentication Header (AH), a core component of the IPsec protocol, is now an integral part of the connection. AH, which cannot be used in NAT environments, provides source authentication and integrity protection.
Users should make sure that their VPN providers offer true dual-stack IPsec implementations, supporting both IPv4 and IPv6 at the same time. Transport Relay Translator (TRT) nodes, as described by RFC 3142, do not support IPsec across those protocol relays which can pose challenges to VPN network traffic.
Email your VPN-related questions to firstname.lastname@example.org.
This was first published in November 2011