3 ms·
> This is a lie. A "session through the NAT" does not really expose the host to the outside world, because in 99% of the cases this is a TCP session, and the NA
by alfons_foobar 2y ago
> This is a lie. A "session through the NAT" does not really expose the host to the outside world, because in 99% of the cases this is a TCP session, and the NAT machine would drop all "out of order" packets.
No, it's not. NAT only translates addresses and does not inspect the TCP "internals" (like sequence number etc, which would allow it to block certain packets).
What you are describing is a stateful firewall that allows "reply packets" for an established TCP-session.
- aboardRat4 2y ago>No, it's not. NAT only translates addresses and does not inspect the TCP "internals" (like sequence number etc, which would allow it to block certain packets). Yes it is. How would it forward response packets back if it doesn't track connections? In real life I haven't seen "stateless NAT" for about 20 years. But cgnat machines usually go beyond that and even verify sequence numbers.