3 ms·
NAT is a workaround for the small amount of address space that was allocated originally. That's not the case on IPv6. I'm sure you can NAT stuff but why the hel
by hvgk 5y ago
NAT is a workaround for the small amount of address space that was allocated originally. That's not the case on IPv6. I'm sure you can NAT stuff but why the hell would you want to do that and have to maintain all the stateful pain in the ass stuff required such as NAT tables which are going to be much larger.
- awestroke 5y agoTo prevent the machines in the network from being exposed publicly
- nybble41 5y agoIf you have machines in the network which you don't trust to handle their own incoming connections securely you can block those connections at the firewall, without port or address translation. Ideally you'd put those on hosts on their own locked-down VLAN. NAT (or NAPT) doesn't add any security (see: NAT traversal) and having different internal vs. external addresses significantly increases the complexity of the system—not just the router but applications as well, which are forced to deal with their public addresses and ports differing from the ones they were assigned.
- awestroke 5y agoI'd rather blacklist devices that I believe are somehow secure than blacklist devices that I think are insecure. How would you even keep on top of that in a large company network? Better to just default to hiding all devices behind the NAT
- hvgk 5y agoThat’s what firewalls are for.