<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Cgnat on Damien Dye&#39;s Blog</title>
    <link>https://blogs.damiendye.uk/en/tags/cgnat/</link>
    <description>Recent content in Cgnat on Damien Dye&#39;s Blog</description>
    <generator>Hugo</generator>
    <language>en-GB</language>
    <lastBuildDate>Sun, 13 Sep 2026 09:00:00 +0100</lastBuildDate>
    <atom:link href="https://blogs.damiendye.uk/en/tags/cgnat/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>IPsec Was a Good Idea. It Is Time to Turn It Off.</title>
      <link>https://blogs.damiendye.uk/en/networking/ipsec-was-a-good-idea-turn-it-off/</link>
      <pubDate>Sun, 13 Sep 2026 09:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/networking/ipsec-was-a-good-idea-turn-it-off/</guid>
      <description>IPsec bound security to the IP address, then the industry took the address away. NAT, double NAT under CGNAT, NAT64 that will not carry it at all, no ports so no load balancing, the MTU tax, L2TP, PPTP and Windows interop — with diagrams, Cisco and Juniper documentation, a full diagnostic method, and the case for retiring it.</description>
    </item>
    <item>
      <title>We Never Ran Out of Addresses. We Ran Out of Effort.</title>
      <link>https://blogs.damiendye.uk/en/networking/we-never-ran-out-of-addresses/</link>
      <pubDate>Thu, 27 Aug 2026 18:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/networking/we-never-ran-out-of-addresses/</guid>
      <description>The UK has spent twenty years bolting workarounds onto IPv4 rather than turning on IPv6. I counted every UK network in the routing table to see who has actually done it, and the answer says this was never about money.</description>
    </item>
  </channel>
</rss>
