A quick discussion around NAT
Open
feature
- Dominant language
- Rust
- Stars
- 2.8k
- Forks
- 115
- Avg merge
- 1d 4h
- Merged PRs (30d)
- 51
Description
Hey Defguard team!
Network Engineer here!
When it comes to security in depth you want to define security zones in your larger network architecture to define security boundaries. One way of accomplishing this when it comes to VPNs is by making sure the subnet assigned to the VPN users is routable and that the source IPs are easily identifiable as coming from the VPN security boundary.
It would be amazing if defguard had a quick toggle on a per location basis to enable NAT (either use underlying host address or a specifically defined address) OR disable NAT and force all source IPs to remain intact.
Contributor guide
Assessment
This issue has not been assessed yet.