[fw-wiz] re: NAT for a simple network

From: Robert E. Martin (rmartin_at_fishburne.org)
Date: 08/15/03

  • Next message: Dave Killion: "RE: [fw-wiz] Blocking MS Blaster"
    To: firewall-wizards@honor.icsalabs.com
    Date: Fri, 15 Aug 2003 13:37:26 -0400
    
    

    "in general, you should verify packets are
    not allowed to the device from the big bad Internet. you may also want to
    only allow local access from select IP addresses or subnets."

    So if I deny all from the outside coming in and allow all from the
    inside to go out, I should have the beginnings of a secure
    firewall.?!??!! This is not to say that it is a catch all but a start.
    Perhaps add rule stating only the internal subnet goes out and to deny
    all others. As I stated before, this is a simple network, no services
    coming in from the outside, just internet access for the subnet inside
    and dhcp running on the gateway.
    Thanks to all that replied to this original post. This is a valuable
    resource to me. Thanks again!!

    -- 
    Robert E Martin
    IT Manager
    Fishburne Military School
    rmartin@fishburne.org
    540.946.7726
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
    

  • Next message: Dave Killion: "RE: [fw-wiz] Blocking MS Blaster"

    Relevant Pages

    • Re: Local access only
      ... work fine on internet and then just goes to local access only. ... We connect with ADSL to internet through LAN. ... does disabling/enabling the network card restart ...
      (microsoft.public.windows.vista.networking_sharing)
    • Local access only
      ... work fine on internet and then just goes to local access only. ... We connect with ADSL to internet through LAN. ... loaded SP1 as well. ... We have reloaded Vista Business but the same prob occurs. ...
      (microsoft.public.windows.vista.networking_sharing)
    • Urgent-iMacG5 vs wireless phone-Help pleasae
      ... I would find the local access for earthlink (my isp) and use the Motorola ... T720 to access the internet via dial up. ... I presently have a 2gig iMac G5. ...
      (comp.sys.mac.apps)
    • removing local access
      ... I have an OBSD box I will be renting that will act as a internet ... gateway. ... I really do not want the users to monkey with it. ... is easy to change the root password if you have local access what is ...
      (comp.unix.bsd.openbsd.misc)
    • Re: Routing and RRAS Problem - Pleasehelp
      ... Traffic from your "internal" subnet can get ... out to the Internet by default routing, but the return traffic will fail. ... You need to add an extra route to the Linksys router so that it knows how to ...
      (microsoft.public.windows.server.networking)