4 ms·
It's just normal routing. If you send packets to a router, it'll route them. More concretely, they can run the equivalent of `ip route add 192.168.1.0/24 via <
by Dagger2 6mo ago
It's just normal routing. If you send packets to a router, it'll route them.
More concretely, they can run the equivalent of `ip route add 192.168.1.0/24 via <your WAN IP>` on a machine that's connected to your WAN network, and then their machine will send packets with a dest of 192.168.1.x to your router. Your router will route them onto your LAN because that's what its own routing table says to do with them.
Anyone on your immediate upstream network can do this, not just your ISP. Also, if you use ISP-assigned GUAs then this inbound route will already exist and anyone on the Internet can connect. Applying NAT to your outbound connections will change their apparent source address, but it won't make that inbound route disappear.
- mittensc 6mo agoHave you tried that? I have yet to see a router that allows that forwarding unless explicitly configured. Still, i'm using mostly openwrt/opnsense/mikrotik Default is to disallow/block forwarding packets from public wan to private range lan. ISP can still inject packets on ports that NAT opens if it spoofs the source address/port, so you still have some validity to argument.
- Dagger2 6mo agoYup, repeatedly. It's true that almost everything comes with a firewall rule that blocks new connections from the WAN to the LAN, so in practice these connections will be blocked on most things by default. But they come with this rule precisely because NAT doesn't do the job.
- mittensc 6mo ago> Yup, repeatedly Cool, me too :) Anyway, the other side of the argument: It is the default and default is secure. Users don't have to reason about it, they can assume it works, how doesn't matter and they may lack training/willingness to figure out. You can't say the same for IPv6 where default is allow (have things changed?, havent checked in a long time)
- Dagger2 6mo agoOf course you can say the same for v6. Blocking connections that go from WAN to LAN by default has the same effect on both protocol families. If you assume that having the appropriate firewall rule to do that is the default then inbound connections will also be blocked on v6 by default. NAT contributes nothing to your security in this scenario, and instead makes it harder (not easier) to understand and reason about what your router is doing.
- mittensc 6mo ago> If you assume that having the appropriate firewall rule to do that is the default That's the thing, it's not the default, default is public ipv6 for everyone and its the users duty to configure firewall... I could definitely set this up easily, someone like my parents or friends would ask me 'what's IPv6?'
- Dagger2 6mo agoAh, okay. In that case v4 doesn't have a firewall by default either. That's precisely why routers come configured with a firewall that blocks inbound connections from the WAN -- because the protocol itself doesn't have a firewall by default, and neither does NAT.