Re: [fw-wiz] ***SPAM*** Re: IPv6 support in firewalls
- From: Dave Piscitello <dave@xxxxxxxxxxx>
- Date: Mon, 27 Aug 2007 13:24:54 -0400
Patrick M. Hausen wrote:
First you should not rely on NAT as a security measure, anyway,
because it isn't.
I advocate using every measure possible to provide security. IP masquerading helps thwart information gathering. I would never suggest using NAT as the only security measure. By IP masquerading, I avoid having a RIR identify the address blocks I use internally, as they would if I were to use public space. Explain why you feel this is wrong?
Third, this is the _only_ way to get rid of the "net 10 considered
harmful" nightmare
It's only a nightmare for people who do not exercise discipline in assigning addresses. I could just as easily err with public addresses and assign the same block of addresses to multiple sites. The fact that an RIR allocates you a block of IPv6 addresses does not guarantee you will not botch assignment within your networks.
Even Forrest Gump knows, "stupid is as stupid does".
IMHO theses are the combined reasons to start over and
kill NAT forever.
Won't happen in my lifetime, nor my childrens' lifetime. begin:vcard
fn:David Piscitello
n:Piscitello;David
adr;dom:;;3 Myrtle Bank Lane;Hilton Head;SC;29926
email;internet:dave@xxxxxxxxxxx
x-mozilla-html:FALSE
url:http://hhi.corecom.com/weblogindex.htm
version:2.1
end:vcard
_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
- Follow-Ups:
- Re: [fw-wiz] ***SPAM*** Re: IPv6 support in firewalls
- From: Paul D. Robertson
- Re: [fw-wiz] IPv6 support in firewalls
- From: Patrick M. Hausen
- Re: [fw-wiz] ***SPAM*** Re: IPv6 support in firewalls
- References:
- [fw-wiz] New to Cisco PIX/ ASA
- From: Keith A. Glass
- [fw-wiz] IPv6 support in firewalls
- From: Dave Piscitello
- Re: [fw-wiz] IPv6 support in firewalls
- From: Marcus J. Ranum
- Re: [fw-wiz] IPv6 support in firewalls
- From: Darren Reed
- Re: [fw-wiz] IPv6 support in firewalls
- From: Marcus J. Ranum
- [fw-wiz] ***SPAM*** Re: IPv6 support in firewalls
- From: Dave Piscitello
- Re: [fw-wiz] IPv6 support in firewalls
- From: Patrick M. Hausen
- [fw-wiz] ***SPAM*** Re: IPv6 support in firewalls
- From: Dave Piscitello
- Re: [fw-wiz] ***SPAM*** Re: IPv6 support in firewalls
- From: Patrick M. Hausen
- [fw-wiz] New to Cisco PIX/ ASA
- Prev by Date: Re: [fw-wiz] Query: Why bother with an application proxy over stateful packet filtering?
- Next by Date: Re: [fw-wiz] Query: Why bother with an application proxy over stateful packet filtering?
- Previous by thread: Re: [fw-wiz] IPv6 support in firewalls
- Next by thread: Re: [fw-wiz] IPv6 support in firewalls
- Index(es):
Relevant Pages
|