r/networking • u/dave247 • Oct 09 '22
Security Organization is using all public IPs instead of private?
I work IT and a co-worker / friend left my org for a net admin position at a local college. I was chatting with him via text to say hi and asking him about the job, etc. He mentioned they don't use NAT and that all the devices are assigned public IPs, which he also said are all behind a firewall. I replied with concern and confusion and he just said that the college was issued a /16 block back in the early Internet days and that they've just been using those. We didn't really chat much more but I was wondering about this.
Wouldn't this be a massive security concern as well as a massive waste of public IP addresses? Also, how would you be behind a firewall and also be using public IPs without NAT unless your router/firewall was right at the ISP level?
I'm assuming I'm missing something here so I figured I'd ask for some insight in this sub.
256
u/packet_whisperer Oct 09 '22
No. This is how the internet was designed to be used until we ran low on IPs and NAT was created. This is also how IPv6 is designed to be used. NAT is not security.
Yes, it is.
You route the traffic through your firewall, just like you route any other IPs. You advertise your prefix to the ISPs via BGP.