Re: NAT vs. True Firewalls

From: Leythos (void@nowhere.com)
Date: 01/31/02


From: Leythos <void@nowhere.com>
Date: Thu, 31 Jan 2002 00:29:30 GMT

In article <a39hpu$16lflg$1@ID-59806.news.dfncis.de>, km@km.com says...
> > Thanks for the responses. Specifically what I am referring to is NAT
> > solutions that are marketed as firewall security products such as Windows
> > 2000 server NAT and Linksys (and other clone) DSL/Cable routers. I
> > understand that NAT is a router function, however I am looking for an in
> > depth comparison of the two.
>
> Linksys and other cable/DSL routers do perform NAT, but they also have added
> firewall capability, such as port mapping, IP filtering, etc. Anything
> added over top of the NAT could conceivably qualify the system as a
> firewall. To my knowledge, no router vendor markets NAT alone as a
> firewall. And Windows 2000 NAT can be used in conjunction with filters, but
> is not marketed as a firewall.

Port mapping has nothing to do with fire walling. The IP filtering of
the cable/dsl routers is on the internal side, it doesn't have a block
list for external IP's. Port mapping is needed in NAT and PROXY type
devices, it has nothing to do with being a firewall. Many of the NAT
routers have snap-in's for Zone Alarm and other firewall apps, but the
devices (LinkSys) are NOT firewalls and do NOT offer any form of true
firewall protections.

-- 
--
Leythos999@columbus.rr.com
(Remove 999 to reply to me)



Relevant Pages

  • Fwd: Re: [Full-Disclosure] Microsoft urging users to buy Harware Firewalls
    ... In my exprerience, these boxes just work. ... So why should we have to stick a firewall in front of a machine ... NAT boxes and hardware firewalls are tools. ... I myself put my windows boxes ...
    (Full-Disclosure)
  • Re: Router/ Firewall
    ... Do all wireless routers even cheap ones act as firewalls. ... With all due respect to anyone else, the routers use something called NAT, ... A firewall can tell the difference between HTTP and any other traffic over ...
    (microsoft.public.windowsxp.general)
  • Re: Kann mysql dump nicht importieren: auto_increment Problem
    ... NAT, Netzwerk etc. hat das drunter liegende OS zu erbringen. ... Entweder der Hersteller sagt das Produkt läuft auf Windows, ... Ein Server, der nebenbei Firewall mit NAT macht, zeugt davon, daß ... Windows in Verbindung mit MySQL sei ...
    (de.comp.datenbanken.mysql)
  • Re: home network behind NAT and firewall ?
    ... > First, lets get one thing clear, a ROUTE that provides NAT and implements ... > SPI is not a firewall. ... If I think that so many wireless routers are in default ... A hardware firewall without NAT protects your system better than a NAT ...
    (comp.security.firewalls)
  • Re: Firewall needed behind router?
    ... An appliance, even a NAT box, is very ... > AllegroSurf, combined with a software firewall, ... > native Windows ICS is. ... firewall you need stop considering NAT as a firewall solution. ...
    (comp.security.firewalls)