Comment on Let's talk about free/FOSS routing platforms for the homelab

<- View Parent
h3ndrik@feddit.de ⁨9⁩ ⁨months⁩ ago

Ah. Thanks for explaining :-)

Yeah, the …keeping the mess somewhere else and not doing it on the important firewall… makes sense.

I also like to keep it clean so everything is a bit more modular and better to maintain.

I think the double-NAT is a bad idea. Such things just cause pain and break in unexpected ways. I’d rather focus on getting the firewall right. And the NAT doesn’t add anything here. A firewall is the correct tool to filter packets between two network segments. A NAT is a crude thing that happens to drop incoming connections from the other side. But you could as well instruct your firewall to drop those packets.

source
Sort:hotnewtop