DefGuard / DefGuard/defguard

A quick discussion around NAT

Open
#1,165 3 comments 0 reactions 0 assignees View on GitHub
feature
Dominant language
Rust
Stars
2.8k
Forks
115
Avg merge
1d 4h
Merged PRs (30d)
51

Description

Hey Defguard team!

Network Engineer here!

When it comes to security in depth you want to define security zones in your larger network architecture to define security boundaries. One way of accomplishing this when it comes to VPNs is by making sure the subnet assigned to the VPN users is routable and that the source IPs are easily identifiable as coming from the VPN security boundary.

It would be amazing if defguard had a quick toggle on a per location basis to enable NAT (either use underlying host address or a specifically defined address) OR disable NAT and force all source IPs to remain intact.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.