Re: Systems behind NAT - port scanning etc.

From: Lik Mai Sak (cuddlybear101@yahoo.com)
Date: 10/30/02


From: Lik Mai Sak <cuddlybear101@yahoo.com>
Date: Thu, 31 Oct 2002 06:30:55 +1100

Melinda Shore wrote:

> In article <3DBF87CF.EB80EF6B@yahoo.com>, Lik Mai Sak <alt.test> wrote:
> >So what exactly is your problem with NAT?
>
> 1) By breaking one IP fundamental design point it interferes
> with application protocols and prevents applications from
> securing themselves
> 2) The techniques that have been developed for allowing
> application protocols to traverse NATs introduce
> additional insecurities, some of them quite serious
> 3) Some of those mechanisms, such as STUN, cannot themselves
> be secured at all because a NAT is indistinguishable from
> a man-in-the-middle attack
> 4) The people recommending NATs as security devices don't
> understand the differences in NAT behaviors. To ascribe
> those differences to "crappy vendor implementations" is
> to fail to understand why different kinds of NATs (full
> cone, partial cone, symmetric) behave they do.

Bugger. Looks like I've got some more reading to do.
Thanx for an informative answer.
E.



Relevant Pages

  • Re: Racoon Problem & Cisco Tunnel
    ... Single TCP socket (UDP requires special NAT code to work correctly). ... > Or maybe a list of protocols that don't work well with NAT? ...
    (FreeBSD-Security)
  • RE: Racoon Problem & Cisco Tunnel
    ... T. Hain, "Architectural Implications of NAT", Internet Draft,July 1998. ... Matt Holdrege, Pyda Srisuresh, "IP Network Address Translator ... Protocol Issues", Internet Draft, August 1998. ... >Or maybe a list of protocols that don't work well with NAT? ...
    (FreeBSD-Security)
  • RE: Racoon Problem & Cisco Tunnel
    ... Interference with protocols like IPSec is one of the reasons ... When it comes to NAT, I'm with Vint Cerf--avoid it if at all ... Let's hasten the deployment of IPv6. ... large network from IPv4 to IPv6 had Vint Cerf's money. ...
    (FreeBSD-Security)
  • Re: How to find NATed address
    ... >to use those protocols are more likely to be looking at getting public ... solution to the problems that NAT introduces, ... response from company Splortsoft who tells me that their ... to defeat local firewall policy - after all, ...
    (comp.security.firewalls)
  • Re: Racoon Problem & Cisco Tunnel
    ... Or maybe a list of protocols that don't work well with NAT? ... The five DSL setups with which I'm familiar all grant at least one ... I have some sympathy for protocols like IPSec that came to be ...
    (FreeBSD-Security)

Quantcast