Re: [fw-wiz] IPv6 support in firewalls



On Monday, August 27, 2007 2:31 AM, Patrick M. Hausen wrote:

Snipped out the discussion about why IPv6 should be deployed to
every device, even those "inside the firewall" and that NAT should
be killed...

First you should not rely on NAT as a security measure, anyway,
because it isn't.

For a security-conscious IT professional, this may be a true statement.

But, for the vast majority of end users of IT, given the choice of a
Hardware NAT device vs. nothing for security, I'll pick the hardware
NAT device every time.
_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards



Relevant Pages

  • Re: Must I be forced to Upgrade from SBS 4.5?
    ... Just sometimes with security you need to be political, a NAT only customer ... "wrong" if no "industrial strength" firewall is not installed, ... The good thing about ISA is that it can be updated ...
    (microsoft.public.backoffice.smallbiz)
  • Re: router/firewall, wireless gateway recommendation for home user
    ... NAT will reduce all of the direct attacks unless you ... firewall appliance for under $100. ... to your wireless nodes, and to protect all internal hosts via NAT, you ... device to reduce direct attacks (additional security layer). ...
    (Security-Basics)
  • Re: Opinions: To NAT or not to NAT?
    ... >or not a firewall is present. ... If you go for bigger NAT boxes, you may need to have someone on had ... machines for security problems. ... without registering with the central DHCP server). ...
    (comp.security.firewalls)
  • Re: Systems behind NAT - port scanning etc.
    ... >>>Due to the upsurge in broadband, I encourage as many people as possible to go>>>to a router with NAT rather than a cable modem/soft client/ICS setup. ... Some people incorrectly say "it's a firewall"> because it blocks certain traffic. ... >> security device doesn't understand IP or security. ... A good consultant can explain things to a> client, in terms their little minds can comprehend. ...
    (comp.security.firewalls)
  • Re: Performance improvement for NAT in IPFIREWALL
    ... NAT is not a security feature. ... provides no better security than the packet-filtering firewall would alone. ... any network topology, which connects to the Internet, IMHO. ...
    (freebsd-net)