5 ms·
It’s wrong to say NAT provides no security. NAT does provide some security, it’s just uncertain, unreliable and has no effect on outbound connections.
by sjwright 6y ago
It’s wrong to say NAT provides no security. NAT does provide some security, it’s just uncertain, unreliable and has no effect on outbound connections.
- kevincox 6y agoNAT necessitates a stateful firewall which does provide some security. You can easily have the stateful firewall without the NAT, and on IPv6. That is why this argument is silly.
- sjwright 6y agoThat’s exactly right. My only point is to push back on the inference that NAT has absolutely zero impact on security posture. I liken NAT to a Ha-ha wall: it sometimes makes inbound more difficult under certain circumstances. It’s not real security. But it’s also not nothing. https://en.m.wikipedia.org/wiki/Ha-ha https://en.m.wikipedia.org/wiki/Ha-ha
- Dagger2 6y agoIt doesn't even give that. Stateful NAT necessitates state tracking but doesn't require a stateful firewall. I've tested it -- NATing the outbound connections from your router has no impact whatsoever on inbound connections (which makes sense, but people have a really hard time wrapping their heads around the idea).
- sjwright 6y agoRegardless of its appropriateness or effectiveness, however weak it may be, in the real world where normal people live, NAT is the first line of defence against inbound attacks for most personal computers and personal devices on the internet. The real criticism is that the presence of NAT has created dangerous complacency among consumers and operating system vendors, relying upon its pseudo-firewall properties for "security" that can be described as barely good enough, arguably not even that.
- Dagger2 6y agoNAT can't prevent inbound connections, so... no, the first line of defence for most personal computers and personal devices on the internet, in the real world where normal people live, cannot be NAT. It's just not a thing that it does.
- sjwright 6y agoHow interesting. So tell me, how do you craft an inbound connection to an arbitrary port on an arbitrary device that is behind NAT?
- Dagger2 6y ago`telnet <IP of destination device> <port>` will do the job.
- sjwright 6y agoOkay then, the IP is 10.1.5.12 and the port is 80. Go for it. Do you even know what NAT is?
- Dagger2 6y agoThat's an RFC1918 IP. I'm not going to be able to reach it from here. So long as you aren't also running a firewall, your ISP or anyone on your immediate upstream network could reach it just fine though. If you get me access to that network then I'd be happy to demonstrate. Yes, I know what NAT is.
- sjwright 6y agoYou think my ISP can reach my local network “just fine”? Yeah, that’s completely wrong and absurd. I’m pretty sure you don’t know what NAT means.
- 6y ago