3 ms·
That would imply that NAT is some kind of firewall. It's not. NAT doesn't block connections, so it's not a firewall. In the first place, NAT is something you a
by Dagger2 3y ago
That would imply that NAT is some kind of firewall. It's not. NAT doesn't block connections, so it's not a firewall.
In the first place, NAT is something you apply to outbound connections, not inbound ones, so how can it change the behavior of inbound connections?
- unethical_ban 3y ago>That would imply that NAT is some kind of firewall. It's not. NAT doesn't block connections, so it's not a firewall. I know. I am arguing with the people who think NAT is a good security mechanism. I called it an accidental firewall because without configuring NAT, you do not have a path from the Internet to a private network. I'm speaking on their terms. >In the first place, NAT is something you apply to outbound connections, not inbound ones Where in the literature did you read this? You absolutely can NAT in any direction you wish. Source NAT, Destination NAT, many-to-one NAT, 1:1 NAT, etc. Source: multi-decade network and security engineer
- Dagger2 3y agoI'm talking about the kind of NAT that everybody else is talking about here, the one you get in Linux by running "iptables -t nat -A POSTROUTING -o wan0 -j MASQUERADE". It has "-o wan0" so it only applies to outbound connections. > I know. I am arguing with the people who think NAT is a good security mechanism. I called it an accidental firewall because without configuring NAT, you do not have a path from the Internet to a private network. I'm speaking on their terms. But you do normally have that. Your ISP gives you address space to use for your network and routes that space to your router, and your router routes it to your end machines. People far prefer using the Internet this way over using proxies. Of course, if your ISP can't give you enough address space then you're stuck using RFC1918 (which is very common on v4, but it's hardly a normal way to run a network, just one you're forced into due to v4 being so exhausted.) The Internet won't be able to reach your network... but this isn't due to NAT because RFC1918 isn't NAT. It's not a firewall either because any inbound connections that do reach your network will work fine. At this point, you'll add NAT so you can actually make working outbound connections. This is the opposite of a firewall. Your ISP will still be able to connect in too. If you really wanted to, you could add NAT even when not using RFC1918. Any inbound connection that worked before you added it would keep working afterwards. Having or not having NAT doesn't make any difference on who can connect in. That's why it's not a firewall, accidental or otherwise.