RE: NAT, Internet access and security

From: David McGovern (dmmcgove@hotmail.com)
Date: 01/10/02


From: "David McGovern" <dmmcgove@hotmail.com>
To: security-basics@securityfocus.com
Date: Thu, 10 Jan 2002 14:20:50 -0500

Being that FTP is one of the most insecure protocols, it might be a better
idea to use ssh.

Just a thought.

-Dave

>From: "Thomas M. Welch" <twelch@samcrc.com>
>To: "Kartik Trivedi" <kvt@eudoramail.com>, "irado furioso com tudo"
><irado@nettaxi.com>
>CC: <security-basics@securityfocus.com>
>Subject: RE: NAT, Internet access and security
>Date: Tue, 8 Jan 2002 17:58:23 -0600
>
>No Problem...
>
>Just map port 21 (assuming you are using port21) to your internal redhat
>box running the ftp daemon.
>
>It is also called port forwarding. When a FTP request comes to your
>router over port 21 your router will forward that request to the
>internal machine you specify.
>
>Hope this helps.
>-Tom
>
>
>
>-----Original Message-----
>From: Kartik Trivedi [mailto:kvt@eudoramail.com]
>Sent: Tuesday, January 08, 2002 5:05 AM
>To: irado furioso com tudo
>Cc: security-basics@securityfocus.com
>Subject: Re: NAT, Internet access and security
>
>
>hey guys,
>
>Any idea how can i run an FTP server behind a NAT.
>
>I share DSL connection with my roommates using a router. But i want to
>connect to my machine (RH Linux 7.2 which has an ftp daemon running)
>from outside.
>
>Any idea?
>
>Thanks
>-neo
>----- Original Message -----
>From: "irado furioso com tudo" <irado@nettaxi.com>
>Cc: <security-basics@securityfocus.com>
>Sent: Monday, January 07, 2002 3:46 AM
>Subject: Re: NAT, Internet access and security
>
>
>surelly, I am missing something. In a widely open network as this, how
>can it be secure ??
>
>
>
>Iain McAleer wrote:
>
> > Hey guys,
> >
> > To be honest, if your system is secure a firewall is redundant. I am
> > aware of a company here in Perth that is part of a multi-million
> > dollar corporation. They have NO firewalls in place and are not
> > implimenting NAT. Infact they have live IP's for all their
> > workstations. The reason they
>have
> > no firewall and can keep running with this is because their system is
> > secure. The biggest security risk is always going to be exploits and
> > your own clients idiocy.
> >
>
>
>
>
>saudações,
>
>Irado Furioso com Tudo
>Linux (SuSE) User 179402
>se abrirem as portas de *todas* as prisões, os roubos ainda serão em
>menor volume do que os de nossos políticos. Na verdade, mal
>perceberíamos a diferença (think about)!.
>
>
>

_________________________________________________________________
MSN Photos is the easiest way to share and print your photos:
http://photos.msn.com/support/worldwide.aspx



Relevant Pages

  • Re: Cable Vs. DSL
    ... Well, its likely that he is using a Linksys or D-link NAT enabled router, ... >>is what the clients are seen to have from the internet. ... >security measure, it's merely a way to broaden the available address ...
    (Security-Basics)
  • Re: How exposed am I?
    ... > addition to NAT? ... For a small business solution, you may want to look at a WatchGuard FW ... I don't think you can take security on the Internet lightly in today's ...
    (comp.security.firewalls)
  • Re: Open Ftp on AS/400
    ... Static NAT is only slightly better than no protection at all - ... PIX does both. ... FTP sends clear-text user-id and passwords - make sure at least ... connecting to the Internet with little or security considerations ...
    (comp.sys.ibm.as400.misc)
  • [fw-wiz] ***SPAM*** Re: IPv6 support in firewalls
    ... Patrick, ... My crystal ball only says that if I'm building inter-organizational tunnels to connect parties outside my operational control directly to assets on my internal network I probably have much worse security problems to fret about than IP addresses. ... I would never suggest using NAT as the only security measure. ... Internet. ...
    (Firewall-Wizards)
  • Re: Performance improvement for NAT in IPFIREWALL
    ... NAT is not a security feature. ... provides no better security than the packet-filtering firewall would alone. ... any network topology, which connects to the Internet, IMHO. ...
    (freebsd-net)

Quantcast