Security of NAT on Netopia Routers?

From: Brad Cox (bcox@virtualschool.edu)
Date: 08/20/01


Date: Mon, 20 Aug 2001 12:22:34 -0400
From: Brad Cox <bcox@virtualschool.edu>
To: "Albert Lederer" <alederer@gatewaytel.com>
Subject: Security of NAT on Netopia Routers?
Message-Id: <20010820122234.669ff48e.bcox@virtualschool.edu>

On Mon, 20 Aug 2001 11:49:31 -0400
"Albert Lederer" <alederer@gatewaytel.com> wrote:

> NAT in itself is pretty secure, as it will only let IP sessions established
> from the internal interface to go through(in it's default setup), so it's
> pretty secure. I think with NAT you'd almost have to discuss a certain
> vendors implementation.

Does anyone have experience with the NAT implementation in Netopia's routers in the default NAT configuration? Mine comes up clean with the security probes I've thrown at it so far (Nessus, Symantec's, grc.com) but I'm far from a security expert.

This is their low-cost box with dual analog modems for external access.

I'm running Linux and MacOSX inside and all of which currently rely totally on NAT for security.

-- 
Brad J Cox, Ph.D. bcox@virtualschool.edu, 703 361 4751
For industrial age goods there were checks and credit cards
For everything else there is http://virtualschool.edu/mybank
Java Web Application Architecture: http://virtualschool.edu/jwaa



Relevant Pages

  • Re: Systems behind NAT - port scanning etc.
    ... >security considerations section of the STUN document goes ... probably be filter-blocked on any firewall relying on NAT for security. ... >understand network architecture or network security). ...
    (comp.security.firewalls)
  • Re: Systems behind NAT - port scanning etc.
    ... >>So what exactly is your problem with NAT? ... Here are a couple nice security principles I've learned over the years: ... Once your site is secure enough to make it not worth attacking, ... - proper password security, spyware avoidance, etc. ...
    (comp.security.firewalls)
  • Re: Performance improvement for NAT in IPFIREWALL
    ... NAT is not a security feature. ... provides no better security than the packet-filtering firewall would alone. ... any network topology, which connects to the Internet, IMHO. ...
    (freebsd-net)
  • Re: Systems behind NAT - port scanning etc.
    ... >>Melinda Shore wrote: ... > security rather than enhancing it. ... > want a NAT to manage a complex address space problem. ... more secure by default than software, ...
    (comp.security.firewalls)
  • Re: Must I be forced to Upgrade from SBS 4.5?
    ... Just sometimes with security you need to be political, a NAT only customer ... "wrong" if no "industrial strength" firewall is not installed, ... The good thing about ISA is that it can be updated ...
    (microsoft.public.backoffice.smallbiz)

Quantcast