Invisible to the internet
Gateways only make outbound connections. They never listen for traffic from the internet, so there are no open ports to find and nothing to attack. You don’t touch your firewall at all. If a direct path isn’t possible, traffic goes through the nearest of 34 relay clusters, so it stays fast on any network.
you@laptop: ~
$ nmap -Pn -p- gateway.corp.example
Starting Nmap 7.95
Nmap scan report for gateway.corp.example
All 65535 scanned ports are in ignored states.
Not shown: 65535 filtered tcp ports (no-response)
Nmap done: 1 IP address (1 host up)


