RE: IPv4 flag day

Gary Sparkes via NANOG <[email protected]> Thu, 18 Jun 2026 18:52:03 +0000
Newsgroups gmane.org.operators.nanog
Message-ID <BN8PR10MB3185372B8B07EA83216A240FD5E32@BN8PR10MB3185.namprd10.prod.outlook.com>
Correct, I specified both firewalls have an inbound default deny, accept only related/established.

The standard CPE configuration for any NAT scenario, and the usual standard for any non-NAT scenario as well. 

NAT allows me to *bypass* this. 

-----Original Message-----
From: William Herrin <[email protected]> 
Sent: Thursday, June 18, 2026 2:49 PM
To: Gary Sparkes <[email protected]>
Cc: North American Network Operators Group <[email protected]>
Subject: Re: IPv4 flag day

On Thu, Jun 18, 2026 at 11:41 AM Gary Sparkes <[email protected]> wrote:
> Simply, the inbound firewall rules prevent it from working.

What inbound firewall rules? The requirement was that the firewalls are identical except for NAT. If there's an inbound firewall rule, it's present on the NAT firewall too.

Regards,
Bill Herrin



--
For hire. https://bill.herrin.us/resume/
_______________________________________________
NANOG mailing list 
https://lists.nanog.org/archives/list/[email protected]/message/GHQHNSAUZNFFYRZM337A7MACH4YG4FSN/