Also with respect, what you say about PAT is indeed true if you are using the device to hide many users accessing the Internet from an internal source out on one public IP address. This is how the proxy or firewall maintains a statefull list of connections and can return responses from the web to the correct internal clients.
I manage several firewalls for my organisation and it is possible to change both network address and port number in either direction through the firewall.
Admittedly it is not often used as NAT is generally enough, but some organisations will use different ports other then standard for added security, and rely on PAT to present the service on the standard port “on the outside”
![]()
Golam




Reply With Quote