4 ms·
Are you sure your router has PCP or NAT-PMP disabled, which _could_ expose ports on your external IPv4 IP without any interaction? Do you expect the average com
by kbaker 8y ago
Are you sure your router has PCP or NAT-PMP disabled, which _could_ expose ports on your external IPv4 IP without any interaction? Do you expect the average computer user to configure PCP securely on their router?
Various NAT traversal options are already pretty widespread. Having only a firewall keeps things much simpler.
- craftyguy 8y ago> Having only a firewall keeps things much simpler. Yes, for you and for attackers. Security strategies require layers, since no one layer can be depended upon to stand on its own. Removing NAT is removing a layer of security. Suddenly your firewall has to stand on its own. Good luck! Edit: Why is my comment bad?
- zAy0LfpBZLC8mAC 8y agoNAT is not a layer of security. At all. A billion layers of no security is still no security. (And actually, NAT is a negative contribution to security as it hides the lack of a firewall when it isn't there or doesn't work, which would be trivial to detect without NAT.)