5 ms·
This reminds me of a company where the admin used public routable IPs for the internal subnet. The gap is always the human in the loop.
by Helmut10001 2y ago
This reminds me of a company where the admin used public routable IPs for the internal subnet. The gap is always the human in the loop.
- Symbiote 2y agoThere's nothing wrong with this, and it's common at universities that have large IPv4 allocations.
- Helmut10001 2y agoThe subnet that he used internally was "officially" used and owned by oracle and our printers regularly send traffic falsely to Silicon Valley.
- icedchai 2y agoThis was the norm for most of the 90's and earlier. NAT was supposed to be the exception, but it became the rule. Now we have an entire generation that doesn't understand that the Internet was always supposed to support end-to-end connectivity.
- WorldMaker 2y agoPlus too many of that generation see NAT as a "security feature" not an "IP bug" and can't seem to (re-)imagine traditional firewall/router design from the time before NAT. "end-to-end connectivity" is not the same thing as "open and unsecured connectivity", we have the security tools to deal with that and they are not and have never been named "NAT".
- icedchai 2y agoTo say NAT has nothing to do with "security" is a lie. The most common NAT (PAT) configurations are basically acting as stateful firewalls with a default deny policy for all unsolicited inbound traffic to a private, non-routeable network.
- Dagger2 2y agoThey aren't doing that though. The most common NAT (PAT) configurations don't deny unsolicited inbound traffic. They are of course commonly deployed together with a firewall that does deny that traffic, but claiming that NAT blocks connections because it's usually deployed together with a different technology that handles all of the blocking would also be lying.
- ninkendo 2y ago> The most common NAT (PAT) configurations don't deny unsolicited inbound traffic That doesn’t make sense. If I have a single routable IPv4 addresses and 100 machines behind it with RFC1918 addresses, how can any possible router “allow by default” say, port 22? Which machine would it route it to? Would it pick the first one? Randomly select one? Of course NAT has to drop incoming unsolicited packets. Unless you tell it which machine to route them too, it couldn’t possibly know how to “allow” them in the first place.
- Dagger2 2y agoIP packets have a "destination IP" header field that specifies where the packet goes. The router reads that to figure out where to send the packet. The only thing NAT does is rewrite the dst or src headers of packets. If there's no rule or state entry that applies to a packet, it doesn't drop the packet. It just leaves the original headers on it.
- ninkendo 2y agoHow would a packet with a destination IP of my internal RFC1918 address have landed on my WAN interface in the first place? It would require my ISP to have a routing rule that sends it to my router. Is that the threat model you’re thinking about?
- icedchai 2y agoHe's assuming your non-routeable RFC1918 addresses are actually routed from the Internet, which won't be happening in the normal consumer use case.