3 ms·
> usual mistake of implying that disabling NAT results in "exposed" LAN devices (NAT has nothing to do with it, that's the firewall's job) However technically
by vundercind 2y ago
> usual mistake of implying that disabling NAT results in "exposed" LAN devices (NAT has nothing to do with it, that's the firewall's job)
However technically correct from a certain point of view you may be, I was supporting home users for a small ISP in the very early 2000s and you’re wrong in any way that matters. In practice NAT on its own made remote attacks on home networked devices far harder.
- nulbyte 2y agoNAT didn't make remote attacks harder, the default inbound deny rule did. NAT is not the firewall itself, it's just one of the things the firewall can do. Telephone companies are also ISPs, and they are and continue to be quite inept when it comes to securing their own networks, so NAT without a default inbound deny rule is not secure. This matters in a very meaningful way. Have you seen how many enterprising but clueless consumers click random buttons until whatever they are trying to do works? They often don't know or care about other ramifications until it's too late.