you are viewing a single comment's thread
view the rest of the comments
[–] 2 points 9 months ago

Lots of text here but a firewall with inbound deny default rule is considerably easier to manage than port and ip address translation. It’s also possible to get unexpected inbound traffic with NAT. It’s how Tailscale works for example. Sounds like a security failure to me.

  • source
  • parent