Re: Iptable rules to protect my box from the internet

From: Andrew Schulman (andrex_at_deadspam.com)
Date: 12/28/04

  • Next message: fritz-bayer_at_web.de: "Re: Iptable rules to protect my box from the internet"
    Date: Tue, 28 Dec 2004 11:53:33 -0500
    
    

    > Is it safe to suggest that connecting a router on top of the cable
    modem
    > is better/safer than just the modem?

    Safer, definitely. Any NAT router makes an instant, no-configuration
    firewall that will defeat all but a small fraction of network attacks.

    Better-- that depends on your needs. One problem with NAT is that it
    interferes with some popular network services, such as FTP and
    filesharing. So people start to use the port forwarding features to
    open holes. Now you're into the business of configuring a firewall.
    For simple needs, the router's firmware can probably do what you need.
    But to get maximum flexibility, I turn off my router's NAT feature and
    have my Debian box perform the NAT and firewalling itself, using hand-
    built iptables scripts.

    -- 
    To reply by email, replace "deadspam.com" by "alumni.utexas.net"
    

  • Next message: fritz-bayer_at_web.de: "Re: Iptable rules to protect my box from the internet"

    Relevant Pages

    • Re: New modem and iptables...
      ... The router performs firewall and NAT functions ... If you want to persuade me it's a modem, ... it's a router and _it_ has your public Internet address. ... It also does NAT (otherwise you couldn't have a private IP address on ...
      (Fedora)
    • Re: Would a firewall prevent Sasser worm?
      ... >> the same level of protection that I would have with any NAT router? ... >There are a variety of known attacks which can crash routers, ... >Firewall capability allows you to modify the NAT behaviour to allow selected ...
      (comp.security.misc)
    • Re: Would a firewall prevent Sasser worm?
      ... >> the same level of protection that I would have with any NAT router? ... >There are a variety of known attacks which can crash routers, ... >Firewall capability allows you to modify the NAT behaviour to allow selected ...
      (comp.security.firewalls)
    • Re: Would a firewall prevent Sasser worm?
      ... >> the same level of protection that I would have with any NAT router? ... >There are a variety of known attacks which can crash routers, ... >Firewall capability allows you to modify the NAT behaviour to allow selected ...
      (alt.computer.security)
    • Re: IP Addressing
      ... Address of the ISA server? ... firewall and router). ... On the firewall create a static NAT entry as I wrote ...
      (comp.dcom.sys.cisco)