Is NAT can provide some kind of protection?

Owen DeLong owen at delong.com
Thu Jan 13 20:54:15 UTC 2011


On Jan 13, 2011, at 11:44 AM, Lamar Owen wrote:

> On Wednesday, January 12, 2011 12:16:27 pm Valdis.Kletnieks at vt.edu wrote:
>> 140 million compromised PC's, most of them behind a NAT, can't be wrong. :)
> 
> How many more would there be if most PC's were not behind NAT or stateful firewalling?  
> 
Here you've hit the key... "or stateful firewalling". Stateful firewalling provides the security.
NAT just mangles the header. Overloaded NAT depends inherently on the stateful firewall
and this has lead to confusion where people don't realize that the term "NAT" is often
(mis)used to refer to the combined process.

Owen





More information about the NANOG mailing list