NAT Firewall Security Debate

Comments debate the misconception that NAT provides security like a firewall, stressing that NAT is an IPv4 address workaround and firewalls are essential for protection in both IPv4 and IPv6 environments.

➡️ Stable 0.9x Security
3,574
Comments
19
Years Active
5
Top Authors
#3955
Topic ID

Activity Over Time

2008
7
2009
4
2010
35
2011
58
2012
44
2013
91
2014
128
2015
97
2016
139
2017
171
2018
228
2019
273
2020
241
2021
324
2022
319
2023
414
2024
323
2025
298
2026
384

Keywords

AFAIK ISP e.g NAT SCTP SYN OP TCP BT i.e nat firewall ipv6 ipv4 security ip router packets firewalls destination

Sample Comments

ArchOversight Mar 6, 2023 View on HN

That's what a firewall is for, NAT does nothing here.

_ikke_ Oct 19, 2018 View on HN

NAT is not a firewall, it's a hack to keep ipv4 working today.

aPoCoMiLogin Jul 19, 2023 View on HN

NAT doesn't protect anything, firewall does that

msbarnett Oct 28, 2019 View on HN

NAT is not a security measure. You want a firewall regardless of whether you’re running IPv4 or IPv6

iwwr Jun 9, 2011 View on HN

You can no longer rely on NAT to provide a default firewall, can you?

fulafel Oct 23, 2016 View on HN

Home routers are doing IPv6 firewalling by default, no need for NAT. NAT is strictly inferior to firewalling.(Of course you shouldn't put things on your internet-connected network that need the firewall, just look at it as a porous defense-in-depth element, just like with IPv4)

Spivak May 25, 2017 View on HN

Your appliance 'router' can (and probably does) run a firewall to give you that kind of control. NAT never really gave you that.

dev_hugepages Nov 19, 2024 View on HN

NAT is not a security measure but a way to save on IP space or avoid remaking a topology on network addresses changes. For actual security you need a firewall

Gigachad Jan 21, 2026 View on HN

The lack of NAT has no bearing on security. Despite an old mistaken belief.

lamontcg Feb 12, 2021 View on HN

AFAIK NAT goes away but firewall don't (but then firewalls have a horrible fail-open problem since all IPs are routable).