5 ms·
Reading the comments: Why do so many people still think NAT equals firewall when they're not directly related? I guess it's because they're normally packaged
by api 1mo ago
Reading the comments:
Why do so many people still think NAT equals firewall when they're not directly related?
I guess it's because they're normally packaged together for practical reasons. They're both packet handling functions often performed in the same place. But they are NOT the same and you can have either one without the other. Most IPv6 networks have firewalls, and it's possible to have NAT that liberally passes anything.
I wonder how much this misconception has delayed V6 adoption? "But I'll be wide open without NAT!" No, you can have a firewall. Most IPv6 routers have stateful firewalls on by default.
- unethical_ban 1mo agoYou are correct. The reason NAT is seen as security on home networks is that, absent a firewall, it acts as a default deny to inbound traffic.
- tptacek 1mo agoIn other words, the reason NAT is seen as security is that it provides security (imperfectly, like almost everything else).
- unethical_ban 1mo agoIn such a way that it can partially break connectivity and in a way that fails to have users think about security explicitly, yes. Imperfectly.
- tptacek 1mo agoYes when has a security mechanism ever pissed off Unix-on-the-desktop nerds like us before.
- Dagger2 1mo agoNo, the reason is that people incorrectly believe it provides security. It doesn't actually do that.
- tptacek 1mo agoI know that's an article of faith among networking people but it's not actually true.
- Dagger2 29d agoIt is true. NAT only changes the source address used for outbound connections, it doesn't deny inbound ones. You don't need to take that on faith either -- you can just test it.
- tptacek 29d agoGo ahead, make an inbound connection to my dev laptop. I'll even give you the IP address: it's 192.168.8.21.
- Dagger2 29d agoGet me onto the network that's on the WAN interface of your router, disable the firewall on it, and I will. How do you want to go about doing this? Although, 100% of the time people have asked me to do this they chicken out at actually doing it, so I suppose you will too. You might prefer to test with some network namespaces instead.