@p @phnt @slashb @bonifartius NAT is just packet mangling though, so if wan side of things comes in with a spoofed address matching your local subnet, they have access to your LAN, unless you do in fact have a firewall (pretty much everyone's box is setup that way except maybe the bullshit like exposed OpenWRT boxes, see /luci/ on shodan.io).