Can only one VLAN have unrestricted NAT? What if main router NAT is restricted?

Started by Default4408, January 09, 2025, 05:57:08 AM

Previous topic - Next topic
Hi, I'm trying to run a standalone Tor snowflake (proxy) and would like to make my firewall's NAT unrestricted only on the unpriviledged VLAN. If
this is possible, how can I achieve it? Also if my network layout is modem > ISP router > OPNsense > personal router (in bridge mode), would it matter if I set OPNsense's NAT to unrestricted if the ISP router has a restricted NAT? Also, how much of a security risk is it to have an unrestricted NAT?

Edit: I read that my ISP uses carrier-grade NAT and opting out of it would require a business account (which is more expensive). I'm assuming there's no way around this?

What is restricted/unrestricted NAT?
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do. (Isaac Asimov)