Re: Why a software firewall?

From: Duane Arnold (notme_at_notme.com)
Date: 07/10/04


Date: Fri, 09 Jul 2004 23:40:55 GMT


"CZ" <CZ@no99spam.com> wrote in news:IjEHc.935$Mi7.769
@newssvr22.news.prodigy.com:

>> BTW, I prefer to run the ISA server behind a standalone NAT-router <G>
>
> Me too. :-)
>
> Bill:
>
> Makes you appreciate those simple, but effective NAT-routers!
>
>
>

I have certainly seen a couple probes come through the Linksys router at
port 1434 SQL server like the NAT router was not even there. The port was
not being forwarded either. BlackIce didn't react on the desktop or
laptop for no reason and reported the events with the desktop that is on
24/7 and the laptop that was on 24/7 at the time both having SQL Server
running. I have also seen at least on other person report on a probe
coming past the NAT router.

Duane :)

 



Relevant Pages

  • Re: Reporting a hack attempt?
    ... these subseven probes are merely some kiddie ... report serves as notice that there is a defect in their network...I'm no ... W32.leave is an example of a worm that propagated via sub7 scans: ... encourage folks to report through an aggregation system such as ...
    (comp.security.firewalls)
  • Re: Why a software firewall?
    ... >>I have certainly seen a couple probes come through the Linksys router ... >>at port 1434 SQL server like the NAT router was not even there. ...
    (comp.security.firewalls)
  • Re: Ports getting hammered?
    ... Duane Arnold wrote: ... If the router doesn't have SPI, then probes can come past the NAT router and I have had that happen on a Linksys I owned that didn't have SPI, which BlackIce I was using at the time blocked the probes. ...
    (comp.security.firewalls)
  • Re: Why a software firewall?
    ... >>coming past the NAT router. ... > Haven't you already dealt with problem ports? ... > to a non-existent IP on the NAT router. ... > probes on those ports hit the software firewall before I did that. ...
    (comp.security.firewalls)