Re: PAT is really secure?

From: John (jwholmes@earthlink.net)
Date: 03/07/03


From: "John" <jwholmes@earthlink.net>
Date: Fri, 07 Mar 2003 20:38:13 GMT

On Fri, 07 Mar 2003 16:22:29 +0000, Antonio.P wrote:

> Hi to all in group.
> I have installed a new flat adsl line with a router configured in PAT (port
> address traslation). I have several private IP address in my internal lan
> and only an address on the Internet.
> I can see the Internet from my lan pcs but nobody can connect to my lan pc
> from Internet.
>
> So I don't need a firewall becouse the PAT configuration protect my lan or I
> also need a firewall??
>
> Thank you.

PAT (port address translation) allows more than 1 computer to share a
single address by substituting the port and address of the original device
with that of the PAT device. It can also be used for port redirection, as
in a proxy server. It is a different subject from a firewall which permits
or denies traffic. The two are often found together but don't think that
means they are the same thing. You will gain some security for the
computers behind the router by hiding their true address but this does
little for the router and only "by chance" shields the pc. In other words,
if you needed a firewall before, you probably still do. PAT increased your
security, but only a little bit.



Relevant Pages

  • Re: Routers Firewall
    ... I ask him do you have a firewall and he says yes. ... I still have an IDS/firewall on all my machines behind the router. ... > to connect to a port your public IP address the router would reject the ... > An open port on the router could be connected to a service running on the ...
    (comp.security.firewalls)
  • Re: Possible Mail Relay or just new usages of returned mail by spammers
    ... If you have ANY type of firewall, be it a NAT router or true firewall ... ISA can be used in conjunction with the router/firewall, but if you do, you ... to be done twice...once in ISA, and once in the router to port forward to ...
    (microsoft.public.windows.server.sbs)
  • Re: Home firewall Hits
    ... >Port 162 with a UDP message. ... than theres nothing blocking access from the internet to your router. ... >Subject: Home firewall Hits ... >simplify the management and deployment of PGP and reduce overall PGP costs ...
    (Security-Basics)
  • Re: Routers Firewall
    ... > indicates that it has firewall technology, then the router doesn't have a ... What your router does have is NAT. ... ZA is a fine product which will protect a computer ... Port 80 is the WEB access port and port 21 is the FTP ...
    (comp.security.firewalls)
  • Re: Bypassing the firewall
    ... Firewall in the router but i think it comes with Zone Alarm. ... >> The one thing you MUST remember is that an open port is an open port no ... >> So start your game and then start TCPview to see the ports the game is ...
    (comp.security.firewalls)