Re: great article on NAT router security

From: Kleeb (Kleeb_at_localhost.localdomain)
Date: 06/19/04

  • Next message: Eddie Benton: "usb removable storage encryption"
    Date: Sat, 19 Jun 2004 15:04:53 GMT
    
    

    Good post.

    Regarding the remote login service of many NAT routers, I have set my port 80
    (HTTP) to a non-existent address on my (minature) network. Is this necessary ?

    I own a Linksys BEFSR41 router, and find that if I type in my WAN (Internet) IP
    address, I get the login prompt for my router. I'm assuming others would get
    the same.

    To counter this, I've set port-forwarding for port 80 to an invalid
    address, such as 192.168.1.130. This seems to just hang any requests to port 80
    on my Internet IP address. I can still login to my router of course, so long as
    I do it from an internal address.

    Maybe this is all unnecessary as even if I type my WAN (Internet) address into
    a web browser, and get the login prompt, the router still 'knows' it's a
    request from an internal address, and so allows it ?

    I do have remote management disabled.

    Regards,

    Kleeb.


  • Next message: Eddie Benton: "usb removable storage encryption"

    Relevant Pages

    • Re: Using Remote Desktop From an SBS Domain
      ... when you tried to RDP while attached directly to a port on your router? ... Internet to initiate an IP conversation with your computer. ... This situation is different than if you ran your own NAT connection sharing ...
      (microsoft.public.windows.server.sbs)
    • Re: Publish Web Server behind SBS 2003 Standard
      ... I ended up plugging another router into the WAN. ... How to configure Internet access in Windows Small BusinessServer2003http://support.microsoft.com/kb/825763/en-us ... network interface on right (By default the interface name should be ... input 80 in Outgoing port box. ...
      (microsoft.public.windows.server.sbs)
    • Re: CEICW failure
      ... The port forward thing I had tried just out of desperation. ... The router is 192.168.1.1 subnet 255.255.255.0 ... > port 80 from the Internet to your Server. ... >> SBS box has the 2 NICs. ...
      (microsoft.public.windows.server.sbs)
    • Re: how do you setup a wireless connection without using DNS in the NIC?
      ... I CURRENTLY HAVE NODES CONNECTED TO A SWITHC - NETOPIA ROUTER CONNECTED TO ... THE SWITCH AND FROM THE WAN PORT ADTRAN T1 ROUTER. ... PUBLIC CHANGE THEIR NIC TO RECOGONIZE THE DNS IP. ... building) and have them access the Internet via their lap top. ...
      (microsoft.public.windows.server.setup)
    • Re: =?iso-8859-1?Q?ports_=F6ffnen?=
      ... solltest du hinter einem DSL Router ... Dann musst du nämlich den betroffenen Port vom Router auf deinen PC ... Internet aus erreichbar wird, ist er auch direkt angreifbar aber das nur so ... Next by Date: ...
      (microsoft.public.de.german.windowsxp.sonstiges)