Re: Why does Debian allow all incoming traffic by default

Le 22/09/2018 à 09:39, Joe a écrit :

Two layers of NAT work just fine, for anything but IPSec.

1) Even one single layer of NAT can cause trouble with other applications that IPSec : FTP, SIP...

2) IPSec works through NAT, provided that you enable UDP encapsulation aka NAT-T.