Re: Help! 1 to 1 NAT on Linksys RV082 opens up firewall!

From: Duane Arnold (notme_at_notme.com)
Date: 02/13/04


Date: Fri, 13 Feb 2004 18:08:49 GMT

jimdawson@myrealbox.com (Jim Dawson) wrote in
news:e1f9bda.0402130451.1fbf919b@posting.google.com:

> I am trying to set up 1 to 1 NAT on a linksys RV082 router. I have the
> need to access a few computers over the internet using specific ports.
> I configured 1 to 1 NAT on the RV082 and I was able to access the
> device on the LAN side of the router but it apparently removed all
> firewall protection in the process. I was able to ping IP address,
> connect to a Windows share, and even establish a pcAnywhere connection
> without defining any firewall rules to let me do so. I double checked
> and the firewall was enabled on the device. I am using the default
> firewall rules: Allow all traffic from LAN -> WAN, deny all traffic
> WAN -> LAN.

>
> According to the manual: "One to one NAT does not change the firealll
> functions work. Access to machines on the LAN from the Internet will
> not be allowed unless Network Access Rules are set, or Authenticated
> user sessions are established"

I just read a little bit on the user manual on this device. This one to
one Nat feature looks to be opening access to private side IP(s) behind
the router to the public Internet. I think when you do this mapping, the
protection of the router using SPI and the router's protection for those
IP being mapped to is out of the picture and the machine is wide open to
the Internet. The other machines on the LAN side this 1 to 1 NAT are not
being done for are still protected by the SPI and the router.

It's the same thing with me doing Port Forwadring of ports to a LAN IP on
my Linksys BEFW11S4 router. When I do that mapping I have to have a host
based FW on the machine setting rules on the machine as to what public IP
(s) can access the machine on the inbound ports to the machine.

I could be wrong, but you may have to do the same with any LAN side
IP/machine that this one to one NAT is enabled on and protecting it with
a host based FW. I am talking like with BlackIce, ZA, Sygate, etc, etc.
or if using IPsec that's on the Win2K and XP O/S(s) you can do it as well
to protect the machine.

Duane :)



Relevant Pages

  • Re: ISA 2004 - How to allow Guest and Client access from wireless
    ... internet access and now wireless that are a pain in the rear. ... That could plug into another port on the router. ... The router has 4 "internal" ports; one is taken up by the cable ...
    (microsoft.public.windows.server.sbs)
  • Re: Changing the Default Gateway
    ... I agree that I can't see how the WAN side of the router would have anything ... is saying that the folks changed the internal LAN IP of the router to .222. ... this new MPLS internet connetion and phase out the Frame router. ... All tests passed on this DNS server ...
    (microsoft.public.windows.server.sbs)
  • RAS - Routingproblem? DNS? Wins?
    ... ging übers Kabelmodem ins Internet und die andere ins LAN. ... Adapter und über diesen nam der Router externe Anrufe unseres Aussenlagers ... anderen PCs ganz normal mit 1 Netzwerkkarte im LAN angehängt ist. ...
    (microsoft.public.de.german.windowsxp.networking)
  • RAS - Routingproblem? DNS? Wins?
    ... ging übers Kabelmodem ins Internet und die andere ins LAN. ... Adapter und über diesen nam der Router externe Anrufe unseres Aussenlagers ... anderen PCs ganz normal mit 1 Netzwerkkarte im LAN angehängt ist. ...
    (microsoft.public.de.german.windowsxp.networking)
  • [VulnWatch] 3Com OfficeConnect Remote 812 ADSL router exposes internal LAN computers ports during ou
    ... ports during outbound and inbound TCP and UDP sessions. ... The 3Com 812 is a widely-deployed router, found in many ISPs ADSL lines. ... for internet access. ...
    (VulnWatch)