3 ms·
> nothing behind this style NAT can receive unsolicited traffic This isn't really 100% true though. Since IPv4 NAT was never standardized, many many variation
by packet_nerd 8y ago
> nothing behind this style NAT can receive unsolicited traffic
This isn't really 100% true though. Since IPv4 NAT was never standardized, many many variations exist in the wild and some can be exploited to send unsolicited traffic inside the network defeating the implicit "firewall" aspect of NAT.
NAT translates IPs. Firewalls allow or block traffic based on a policy. In some configurations (static NAT, port forwarding, etc. etc.), there's no firewall aspect to NAT at all. In others (PAT, what this discussion is mostly about), there's often an implicit firewall, but different implementations have widely variable behavior, and it basically should not be depended on as a firewall.
If you want to deny inbound unsolicited traffic, then you need a firewall.