Comment on Google Fiber goes big with 20-gig plan

<- View Parent
frezik@midwest.social ⁨1⁩ ⁨year⁩ ago

Because hiding addresses does very little. A gateway firewall does not need NAT to protect devices behind it.

In fact, NAT tends to make things more complicated, and complication is the enemy of security. It’s one extra thing that firewalls have to account for. Firewalls behind NAT also don’t know where traffic is originally coming from, meaning they have one less tool at their disposal. This gets even worse with CGNAT, which sometimes has multiple levels of NAT.

Security is a very common objection to getting rid of NAT, and it’s wrong.

source
Sort:hotnewtop