Earlier quoted context omitted.
>Without UPnP, you specifically have to configure your NAT for this... While I realize that configuring nftables/iptables is beyond most folks, there are many firewalls out there that have a GUI/webui which makes this dead simple. Not sure why this should be an issue in 2021, except for users' trained-in helplessness.
> Not sure why this should be an issue in 2021, except for users' trained-in helplessness. Kids hosting games on random ports (terraria, etc.) benefit from UPnP. I'd rather enable it than manually enter firewall rules for each game or give them admin access to the firewall. UPnP is only an additional risk if you have malware inside your network already and then it mostly allows malware to host services in a simpler w…
I'm not sure where you get that idea. Once a hole is poked (depending on the perimeter device/software in use), it stays poked and you've expanded your attack surface.
I make sure that there's no dynamically defined external access to my network. Can you guarantee that no software in use on your network is free of vulnerabilities? I'm not talking about malware here, just your run-of-the-mill software bugs.
If you think the answer is no, then why don't you share your network details with us and let's have a go? Then we'll see how much of an extra risk upnp might be.
What's that? You'd prefer not to do so? If there's no risk, then it shouldn't be a problem, right?
My suggestion is (obviously, I hope) an idle one and more intended as food for thought.
>Kids hosting games on random ports (terraria, etc.) benefit from UPnP. I'd rather enable it than manually enter firewall rules for each game or give them admin access to the firewall.
That may be a valid use case for you. However, claiming that it doesn't increase your attack surface/risk profile doesn't magically make it so.
I'm not telling you what you should or shouldn't do, but I do disagree with your rationalizations about why allowing upnp to expose your perimeter doesn't increase your risk profile.