Thanks Jamie. Nice direct answer. Have not seen one of those in awhile.
However, I did get 'kooties' once, even with circles and dots drawn on arms
1) Anyway, your first answer is right on, and IMHO, the most relevant. If
you port forward, that is it. The NAT (by itself) does no other filtering
or inspection - that is the grey goose.
2) Your second one I did not follow. "Second, and a bit more of
general concern, if a would be intruder has, or can gain, access to other
hosts on your NAT's segment, the intruder can masq (or spoof) packets to
appear to originate from within your NATs private segment"
If an intruder gets on the a host on the DMZ (lets say) they can masq
packets to appear as originating from private side? Could you provide an
example to illustrate that? Do you mean something like; ping a host on
public NAT side that is mapped to private IP and make source IP a private
one - now reply will go to other private host, not come back to real source
(i.e. DOS attack ?)
3) "but it could be easily compromised depending on the rule sets you
Yes, but that is true of any security measure. Only as good as the rules
you define and enforce.

Thanks for the info Jamie.

William Stacey, MCSE

