<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Nat on Damien Dye&#39;s Blog</title>
    <link>https://blogs.damiendye.uk/en/tags/nat/</link>
    <description>Recent content in Nat on Damien Dye&#39;s Blog</description>
    <generator>Hugo</generator>
    <language>en-GB</language>
    <lastBuildDate>Mon, 14 Sep 2026 09:00:00 +0100</lastBuildDate>
    <atom:link href="https://blogs.damiendye.uk/en/tags/nat/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Your Firewall Takes Instructions From Strangers. Turn Off the Protocol Helpers.</title>
      <link>https://blogs.damiendye.uk/en/networking/protocol-helpers-turn-them-off/</link>
      <pubDate>Mon, 14 Sep 2026 09:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/networking/protocol-helpers-turn-them-off/</guid>
      <description>A NAT helper reads the inside of your packets and opens inbound ports on what it finds there. Anyone can write that text — a web page has been enough since 2010. How helpers work, how crafted packets turn them into a port-opening service for strangers, what IPsec pass-through does, why they fail Cyber Essentials, and how to switch the lot off.</description>
    </item>
    <item>
      <title>IPsec Was a Good Idea. It Is Time to Turn It Off.</title>
      <link>https://blogs.damiendye.uk/en/networking/ipsec-was-a-good-idea-turn-it-off/</link>
      <pubDate>Sun, 13 Sep 2026 09:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/networking/ipsec-was-a-good-idea-turn-it-off/</guid>
      <description>IPsec bound security to the IP address, then the industry took the address away. NAT, double NAT under CGNAT, NAT64 that will not carry it at all, no ports so no load balancing, the MTU tax, L2TP, PPTP and Windows interop — with diagrams, Cisco and Juniper documentation, a full diagnostic method, and the case for retiring it.</description>
    </item>
  </channel>
</rss>
