Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> I explicitly don't want any IP addresses in my green zone to be directly accessibly from my red zone.

This is exactly what the job of a firewall is.

NAT is a hack due to IP address exhaustion. Any security is a side effect. Nothing that says "NAT" on the tin is obligated to protect you.

NAT on your own network if you really drink that kool-aid is fine. I'm more concerned about CGNAT. If ISPs implement NAT (called CGNAT), it means you can't accept incoming connections without your ISP approving/supporting it. I don't want to have to beg my ISP to open ports for me and question/approve why I'm doing it.



> This is exactly what the job of a firewall is.

Well, I agree (if you include the router in that). I never asserted otherwise. In fact, this is how I've implemented my NAT.




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: