RE: [fw-wiz] Home Environment Cisco

From: James Baumgardner (jbaumgardner_at_primarycarenet.org)
Date: 05/30/03

  • Next message: Noonan, Wesley: "RE: [fw-wiz] Home Environment Cisco"
    To: <firewall-wizards@honor.icsalabs.com>
    Date: Fri, 30 May 2003 16:16:59 -0500
    

    How capable are those routers when it comes to stopping IP spoofing?
    I've never heard and have been wondering. (I use a netgear router,
    also)

    -----Original Message-----
    From: hermit921 [mailto:hermit921@yahoo.com]
    Sent: Friday, May 30, 2003 12:29 PM
    To: firewall-wizards@honor.icsalabs.com
    Subject: RE: [fw-wiz] Home Environment Cisco

    Given all this discussion, I have to ask about NAT. I have a small
    Netgear
    DSL router (using NAT) at home. I consider it a great firewall because
    it
    doesn't let in any packets at all when I run nmap scans from the
    outside. It syslogs to my unix machine. What more could I want in a
    firewall for a home environment?

    hermit921

    At 10:26 PM 5/29/2003 +0200, Ben Nagy wrote:
    > > -----Original Message-----
    > > From: firewall-wizards-admin@honor.icsalabs.com
    > > [mailto:firewall-wizards-admin@honor.icsalabs.com] On Behalf
    > > Of salgak@speakeasy.net
    > > Sent: Thursday, May 29, 2003 9:39 PM
    > > To: nathan.grandbois@cerdant.com;
    firewall-wizards@honor.icsalabs.com
    > >
    > > > -----Original Message-----
    > > > From: Nathan [mailto:nathan.grandbois@cerdant.com]
    > > > He has a Solaris ultra 60, and two win98 workstations at
    > > > home he wants to be able to communicate, as well as have access to
    the
    > > > internet (NAT).
    >[deleted]
    > >
    > > Reminder: a 50-dollar router from BestBuy also includes a
    > > Firewall. A Cisco 1600 or 2500-series will not. And NAT is
    > > NOT a firewall.
    >
    >[deleted]
    >
    >I'm not going to run over the NAT / FW discussion again, I think my
    opinion
    >on the matter is pretty well documented in the archives, but I am more
    than
    >happy to use _dynamic_ NAT as a pretty effective security mechanism for
    home
    >users. I do normally back it up with ACLs anyway, but that's just out
    of
    >general principle.
    >
    >ben

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Noonan, Wesley: "RE: [fw-wiz] Home Environment Cisco"

    Relevant Pages

    • Re: Static Translations Disappearing
      ... this router and see if they have the same behavior. ... you are running into a NAT bug. ... It wouldn't hurt to change IOS and ... ....where it just shows all translations being dynamic (0 static, ...
      (comp.dcom.sys.cisco)
    • Re: IP Route Tables - Point to Point Connection - Only Routing 1 way
      ... Your ksshorley1 router is performing network address translation (NAT) on ... default route command. ...
      (comp.dcom.sys.cisco)
    • Re: NAT is not a mechanism for securing a network.. but.. HELP!
      ... > Linksys NAT router at the time and the machines behind the router ... > responded to the ping test. ... > Not once did the Linksys NAT router in its syslog using Wallwatcher ... "if the firewall responds to pings, there is an easy path for hackers into the network" ...
      (comp.security.firewalls)
    • Re: Establish external trust over a NAT device
      ... suggesting hardware over Windows built-in functionality for a VPN solution. ... even a fairly cheap router will likely have much better throughput ... L2TP and routing over it with or without NAT on that connection. ...
      (microsoft.public.win2000.active_directory)
    • Re: Would a firewall prevent Sasser worm?
      ... >> the same level of protection that I would have with any NAT router? ... >There are a variety of known attacks which can crash routers, ... >Firewall capability allows you to modify the NAT behaviour to allow selected ...
      (comp.security.misc)