4 ms·
> I don't want any random machines behind my router to be able to open ports to the internet at large. The solution to this is a firewall, not NAT. As has alwa
by noinsight 2y ago
> I don't want any random machines behind my router to be able to open ports to the internet at large.
The solution to this is a firewall, not NAT. As has always been.
NAT is not a security feature and never has been. The fact that it blocks uninitiated inbound connectivity is an implementation detail, not its purpose.
- JohnFen 2y ago> NAT is not a security feature and never has been. True, and I don't think of it as such -- after all, NAT or not, it's my firewall doing the protecting. What NAT would buy me here is convenience, not security. I could have the same level of security without NAT, but managing it properly is easier and less error-prone with it.
- kstrauser 2y agoHaving managed both, it is absolutely, 100%, not easier to manage NAT than a firewall. For example, here's a valid OpenBSD pf configuration: pass out on $ext_if from any to any That's it. That's the entire stateful firewall config: Don't allow anything inbound at all, except directly in response to an outbound connection. If your firewall has a GUI, it'll be as easy to configure that as it is the NAT. If your firewall has a CLI, I guarantee there's no NAT in the world that's easier to configure than the above stateful firewall.
- JohnFen 2y agoWell, it's not quite that simple given my LAN's topology -- but you're right that it isn't incredibly complicated. I just prefer to manage it a different way. The end result is the same, so I'm not sure what the issue is here.
- ranger_danger 2y agoDepending on your threat level and exact firewall configuration, any bidirectional connection can be used to punch through in some way.
- kiririn 2y agoFirewalls don’t fail safe, NAT does. With a disabled/broken/misconfigured firewall, there is a good chance that everything works sans security. With a disabled/broken/misconfigured NAT, you may as well have unplugged the ethernet cable
- p_l 2y agoOr allowed one of the many NAT-busting methods to connect through.
- Dagger2 2y agoIt doesn't even do that much. NAT is something you apply to outbound connections, not to inbound ones. Unless there's a firewall blocking it, you can connect inwards over a router that's NATing its outbound connections.