Re: Systems behind NAT - port scanning etc.

From:
Date: 10/28/02


Date: 28 Oct 2002 17:01:15 -0500

In article <Tqiv9.152865$La5.500214@rwcrnsc52.ops.asp.att.net>,
Network Tiger Teams <information@networktiger.com> wrote:
>That's the point I was making about router or firewall (whichever is
>handling the NAT allocations) re-direction or mapping. It still potentially
>leaves an internal host open. However, if there are no configured mappings,
>then the machine is relatively safe from a direct penetration..

Again, it depends on the NAT type and how many network
"connections" (don't like that word) you've initiated from
the outside. Some NATs will forward all incoming traffic on
a port for which there's a mapping installed, regardless of
source address. Presumably that's not a good thing.

-- 
     Melinda Shore - Software longa, hardware brevis - shore@panix.com
          If you send me harassing email, I'll probably post it



Relevant Pages

  • Re: Does ICS or Firewall have a NAT
    ... >>>A friend of mine said that there's a NAT functionality built into the ICS ... that a NAT creates a mapping of an intranet computers ... >request out to the Internet. ... the Windows Firewall to forward the desired traffic to a specific port ...
    (microsoft.public.windowsxp.network_web)
  • Re: 2000, NAT & port forwarding...
    ... see the mapping happening in NAT --> Show mappings? ... gateway: a.b.c.62 ... I installed NAT and added to INET´s Special Ports ... Incoming port: 80 ...
    (microsoft.public.win2000.ras_routing)
  • Re: Does ICS or Firewall have a NAT
    ... that a NAT creates a mapping of an intranet computers ... When a response arrives from the internet, ... This is all OK and does not require static mapping. ...
    (microsoft.public.windowsxp.network_web)
  • Re: How to Lookup NAT Mapping?
    ... > Well, NAT generally doesn't rewrite destination addresses, but source ... so that the reply packets reach the NAT router. ... Obviously the rewrite has ... handle the reverse mapping. ...
    (comp.os.linux.networking)