3 ms·
You are correct. The reason NAT is seen as security on home networks is that, absent a firewall, it acts as a default deny to inbound traffic.
by unethical_ban 1mo ago
You are correct.
The reason NAT is seen as security on home networks is that, absent a firewall, it acts as a default deny to inbound traffic.
- tptacek 1mo agoIn other words, the reason NAT is seen as security is that it provides security (imperfectly, like almost everything else).
- unethical_ban 1mo agoIn such a way that it can partially break connectivity and in a way that fails to have users think about security explicitly, yes. Imperfectly.
- tptacek 1mo agoYes when has a security mechanism ever pissed off Unix-on-the-desktop nerds like us before.
- Dagger2 1mo agoNo, the reason is that people incorrectly believe it provides security. It doesn't actually do that.
- tptacek 29d agoI know that's an article of faith among networking people but it's not actually true.
- Dagger2 29d agoIt is true. NAT only changes the source address used for outbound connections, it doesn't deny inbound ones. You don't need to take that on faith either -- you can just test it.
- tptacek 29d agoGo ahead, make an inbound connection to my dev laptop. I'll even give you the IP address: it's 192.168.8.21.
- Dagger2 29d agoGet me onto the network that's on the WAN interface of your router, disable the firewall on it, and I will. How do you want to go about doing this? Although, 100% of the time people have asked me to do this they chicken out at actually doing it, so I suppose you will too. You might prefer to test with some network namespaces instead.