The second is whether to use the "WAN" address or some address within the /29 as the NAT egress address for all traffic egressing from that subnet.
I suppose there's no reason not to do that but I really fail to see sufficient advantage over a properly configured firewall to be worth the head-scratching.
Just because you can NAT at that boundary does not mean that you should. Use it as a DMZ, if you wish to run 'net accessible servers and have your main network on RFC1918 addresses if you wish, that is perfectly sensible. But NAT is not a security device and should not be used as such.
Edited by mr_bean (Tue 25-Jan-22 20:43:30)



Pages in this thread:
Print Thread
mr_bean