Hacker News new | past | comments | ask | show | jobs | submit login

It's different because not only does it deny inbound connections, it breaks the end-to-end principle[1] of the internet. You can have the security boundary without NAT by using a firewall, so if that's all you want, don't use NAT.

1: https://en.wikipedia.org/wiki/End-to-end_principle




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: