2 ms·
IP packets have a "destination IP" header field that specifies where the packet goes. The router reads that to figure out where to send the packet. The only th
by Dagger2 2y ago
IP packets have a "destination IP" header field that specifies where the packet goes. The router reads that to figure out where to send the packet.
The only thing NAT does is rewrite the dst or src headers of packets. If there's no rule or state entry that applies to a packet, it doesn't drop the packet. It just leaves the original headers on it.
- ninkendo 2y agoHow would a packet with a destination IP of my internal RFC1918 address have landed on my WAN interface in the first place? It would require my ISP to have a routing rule that sends it to my router. Is that the threat model you’re thinking about?