Lots of text here but a firewall with inbound deny default rule is considerably easier to manage than port and ip address translation. It’s also possible to get unexpected inbound traffic with NAT. It’s how Tailscale works for example. Sounds like a security failure to me.
Lots of text here but a firewall with inbound deny default rule is considerably easier to manage than port and ip address translation. It’s also possible to get unexpected inbound traffic with NAT. It’s how Tailscale works for example. Sounds like a security failure to me.