skip to content

What are the security costs of letting devices open NAT port mappings automatically with UPnP IGD or NAT-PMP, and how do you contain them?

level: seniorimportance: should knowfreq 24%

answer

  1. no authentication on the LAN side
  2. mapping for whom
  3. requests from the WAN side
  4. leases that never expire
  5. PCP's Simple Threat Model

basics

~20 s

Automatic mapping lets any LAN software, including malware, expose itself to the internet without the owner's knowledge. Risks grow with mappings for other hosts, WAN-side requests and unlimited leases; contain it by disabling, restricting, leasing, segmenting and auditing.

solid answer

~40 s

A NAT's inbound blocking comes from having no mapping, and UPnP IGD and NAT-PMP let any host on the inside interface create one without authentication. So a compromised device can make itself reachable from the internet. The damage grows when a gateway accepts mappings for hosts other than the requester (NAT-PMP forbids it, PCP allows it only with `THIRD_PARTY` on a fully trusted network), answers requests on its WAN side (both RFCs forbid it), grants unlimited leases that outlive the device and land on whoever gets its address next, or exposes other settings, as UPnP IGD's control over the DHCP-advertised DNS servers does. Contain it: turn it off where services are known, otherwise prefer leased protocols, restrict which hosts may ask, segment those hosts, and audit the mapping table.

go deeper

for a junior

Recall that UPnP lets devices open ports on the router by themselves, without asking anyone, and that this can expose them to the internet.

for a middle

Explain why the protocols trust the inside interface, and what NAT-PMP's source-address rule and leases prevent compared with UPnP IGD.

for a senior

Show how you would assess and harden a gateway: WAN-side exposure, third-party mappings, stale leases, segmentation and auditing of the mapping table.

for a principal

Set the policy for when automatic mapping is acceptable at all, balancing applications that need inbound reachability against unreviewed exposure.

## What automatic provisioning gives away On a typical NAT, an unsolicited inbound packet is stopped because **no mapping exists** for it, not because a policy forbids it. A manual forward removes that for one port, deliberately, after someone decided to. A port-mapping protocol lets **any software on the LAN** do the same at any time, usually without the owner seeing it. UPnP IGD and NAT-PMP have no authentication: the gateway trusts whatever reaches it on its internal interface. A compromised camera, a malicious program or a careless application can make itself reachable from the whole internet. ## The concrete risks - **Malware reachability.** A compromised device opens a port to itself so the attacker can connect in, relay traffic through it or control it, without breaking through anything. - **Mappings for other hosts.** If a request may name an internal host other than the requester, one device can expose another. NAT-PMP forbids this: the request's source address MUST be the mapping's internal address. PCP allows it only through the `THIRD_PARTY` option, which MUST NOT be implemented or used unless the network is fully trusted. - **Requests from the WAN side.** A gateway that answers mapping requests on its external interface lets anyone on the internet create mappings into the LAN. A NAT-PMP gateway MUST NOT accept them, and a PCP server MUST silently ignore requests that arrive on an interface other than the one it normally hears that client on. Gateways that got this wrong have been found answering from the internet, an implementation defect rather than a protocol feature. - **Control beyond port mappings.** UPnP IGD is a general gateway-administration protocol. RFC 6886 gives the example of an IGD request changing the DNS server addresses the gateway hands out by DHCP, so one piece of malicious content can persistently redirect every client's name lookups. - **Mappings that never expire.** UPnP IGD clients in practice request unlimited leases. When the device leaves and DHCP gives its address to another host, the new host receives the old device's inbound traffic. NAT-PMP leases expire unless renewed (7200 seconds recommended), and RFC 6886 lets a combined DHCP and NAT gateway delete a client's mappings when its address lease expires. - **Protocols nobody asked for.** A gateway that creates both a TCP and a UDP mapping when asked for one exposes a protocol the client did not want; RFC 6886 says such gateways MUST NOT implement NAT-PMP. - **The exposed service itself.** Devices that open ports automatically often run small embedded services with weak authentication, now reachable by internet-wide scanning. ## How PCP frames the risk PCP's **Simple Threat Model** (RFC 6887, section 18.1) sets the bar: a PCP server is secure under it if it never configures an explicit mapping it would not configure implicitly. That holds when all hosts are in one administrative domain, explicit mappings get the same lifetime as implicit ones, and `THIRD_PARTY` is unsupported; a server can also offer `MAP` safely if its policy would permit endpoint-independent filtering anyway. The **mapping nonce** ties a mapping to its creator: under the Simple Threat Model, a request for the same internal endpoint with a different nonce is rejected with `NOT_AUTHORIZED`. The `FILTER` option lets an application admit only named remote peers. | Property | UPnP IGD in practice | NAT-PMP (RFC 6886) | PCP (RFC 6887) | |---|---|---|---| | Who may be the internal host | the request names it | only the requester | requester, or anyone with `THIRD_PARTY` | | WAN-side requests | must not be answered; some implementations have | MUST NOT be accepted | silently ignored | | Expiry | often never | leased | leased | | Scope of control | much of the gateway | port mappings only | mappings and filtering | ## Containing it 1. **Decide whether you need it.** On networks where the services are known, such as offices and server networks, turn automatic provisioning off and keep static, reviewed forwards. 2. **If you keep it, prefer leased mappings** (PCP or NAT-PMP) over unlimited ones, and confirm from outside that the WAN side does not answer. 3. **Restrict who may ask.** Many gateways can limit automatic mappings to certain hosts or port ranges, or refuse low ports, an implementation feature; RFC 6886 notes a gateway may refuse a port for policy reasons. 4. **Segment** devices that need inbound mappings, so a mapping exposes one isolated segment rather than the trusted LAN. 5. **Audit** the gateway's mapping table and log mapping creation; an unexplained mapping is an incident lead.

  • Why does a stale mapping become dangerous when the DHCP server reuses the address?
    A mapping points at an internal address, not at a device. If the device that requested it leaves and its address is leased to another host, inbound traffic meant for the old service reaches the new host, which never asked for it. Leased mappings expire without renewal, and RFC 6886 lets a combined DHCP and NAT gateway delete a client's mappings when its address lease ends.
  • Would you allow automatic port mapping on an office network?
    Usually not. An office knows which services must be reachable, so they belong in static forwards that go through review, and automatic mapping only adds a path for malware or a careless application to expose itself. If an application truly needs it, put the hosts that use it on their own segment and allow requests only from there.

saying these in an interview costs you the question

  • UPnP IGD requires a password before a host can add a mapping.
  • Mappings created by applications disappear when the application exits.
  • A NAT-PMP host may open ports for any device on its LAN.
  • Blocking UPnP on the WAN side removes all of its risk.
  • The NAT's blocking of unsolicited traffic stays in force for auto-mapped ports.