4 ms·
The destination IP will be for the router itself, so the router can either re-deliver the packet to itself or drop it. I don't see how NAT isn't an effective i
by quicklyfrozen 8y ago
The destination IP will be for the router itself, so the router can either re-deliver the packet to itself or drop it.
I don't see how NAT isn't an effective inbound firewall by itself in the normal case where it's in front of local non-internet-routable IP addresses.
- Dagger2 8y agoIt won't necessarily be for the router. The packet could be addressed to one of the machines on your LAN, in which case nothing NAT does will stop the router from happily forwarding it right through. NAT does nothing to stop a router from forwarding any given packet -- and that's something that's still true regardless of what IP range you're using on the LAN side.