Re: Systems behind NAT - port scanning etc.

From: Lik Mai Sak (cuddlybear101@yahoo.com)
Date: 10/29/02


From: Lik Mai Sak <cuddlybear101@yahoo.com>
Date: Tue, 29 Oct 2002 17:34:14 +1100

Melinda Shore wrote:

> In article <PLiv9.112727$Hj7.58788@rwcrnsc53>,
> Network Tiger Teams <information@networktiger.com> wrote:
> >So maybe we're just confused over semantics...
>
> I'm not confused about anything (at least not in this
> discussion). If you have a full cone NAT with a NAT table
> entry mapping internal address 192.168.1.4.4056 to external
> address 132.236.4.6.5678, any packet arriving at
> 132.236.4.6.5678, regardless of source address, will be
> forwarded to 192.168.1.4.4056. You should spend some time
> experimenting with a bunch of different NATs - you'll see a
> range of behaviors, many of them surprising.

Depends on the features of the router/NAT device. Some only allow
connections from/to all addresses, some allow you to specify source/target
addresses.
You pretty much get what you pay for tho. As someone pointed out earlier,
NAT/SPI is a good *part* of a secure setup, but it's not the whole deal.
E.



Relevant Pages

  • Re: Systems behind NAT - port scanning etc.
    ... >>Melinda Shore wrote: ... > security rather than enhancing it. ... > want a NAT to manage a complex address space problem. ... more secure by default than software, ...
    (comp.security.firewalls)
  • Re: New to the Group
    ... don't recall anyone saying NAT is groovy - merely that ... "Melinda Shore" NAT ... identity by posting from behind a NAT. ... Melinda Shore - Software longa, ...
    (rec.pets.dogs.behavior)
  • Re: Systems behind NAT - port scanning etc.
    ... >So maybe we're just confused over semantics... ... If you have a full cone NAT with a NAT table ... range of behaviors, many of them surprising. ...
    (comp.security.firewalls)
  • Re: category theory and FP
    ... set of functions from Nat to Nat -- there is uncomputable "junk" in the set of functions which will screw up our theorems. ... So you need some other structure to give a semantics to programmable functions. ...
    (comp.lang.functional)
  • Re: Zebedee setup through a firewall
    ... Lets not get into a semantics argument. ... fully open to the internet. ... I have no control of the NAT box. ...
    (comp.security.firewalls)

Loading