Firewall Wizards mailing list archives

NAT Pseudo Security


From: "Lee T. Christie" <Lee.Christie () mosaicinfo org>
Date: Tue, 4 May 2004 09:25:09 -0500

I was wondering what everyone's thoughts were utilizing NAT as your only
security mechanism, for protection from the Internet.  I realize that NAT was
not designed for security purposes.  For instance, if network A is connecting
to the Internet behind a router performing NAT, no incoming address or port
forwarding, what are my risks, from outside hosts?  The way I see it by
implementing a SOHO firewall I gain a) Ingress and Egress packet control b)
Statefull inspection or proxy inspection c) A potentially hardened OS on the
unit d) Logging and Reporting e) Secure management

My question is how vulnerable would that network be from outside attacks?  Is
there anyway an outside user would be able to utilize source routing or
another mechanism to attack an internally NAT'd host?


Thanks in advance for your responses.

Lee
_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


Current thread: