3 ms·
NAT isn't a nice feature, it's a necessary evil to deal with address exhaustion in v4 and causes many problems of its own. Using it in v6 makes no sense. It do
by Dagger2 3y ago
NAT isn't a nice feature, it's a necessary evil to deal with address exhaustion in v4 and causes many problems of its own. Using it in v6 makes no sense.
It doesn't have a "default deny" behavior -- NAT doesn't block connections at all. It doesn't separate your LAN either, that's done by having a router. If you want those things then NAT isn't the thing you want.
- hot_gril 3y agoYou're right that in a technical sense, NAT isn't block connections, more like it allows connections in the first place that would otherwise not be possible. But that's the best part. It's very hard for a misconfigured NAT to result in devices being exposed, unlike a true firewall, which is actively blocking connections to devices that would otherwise be totally reachable. NAT is sucky in plenty of server-side situations and is thus avoided, but in homes and offices, yeah I wouldn't want it any other way.
- Dagger2 3y agoIt's sucky in homes and offices too. It's not hard to test if your firewall is working. Using NAT to avoid that is not the sensible approach.