Comment by bigstrat2003

18 days ago

> The truth of the matter is that NAT absolutely _is_ a firewall in _practice_.

No it's not. NAT is not ever a firewall. By definition it is not.

What is the definition of a "firewall"?

And it doesn't really matter. You can call it "alksjfaliskdfgh" if you wish. The fact is, NAT adds a security barrier that is incredibly effective in practice.

  • But it really doesn't. If you turned off NAT your computers would have the exact same security as they do with NAT.

    • Wrong. If I turn off the NAT on my router, my computers will not be able to get online. If I turn off the IPv6 firewall on my router, I won't see anything unusual.

      And yes, this has happened to me when I forgot to compile the IPv6 conntrack module.

      1 reply →