Re: suggestions on router w/firewall
From: Leythos (void_at_nowhere.org)
Date: 11/07/04
- Next message: Beauregard T. Shagnasty: "Re: Loose Internet Connection Overnight"
- Previous message: Kerodo: "Re: Kerio 2.1.5 vulnerability"
- In reply to: CZ: "Re: suggestions on router w/firewall"
- Next in thread: CZ: "Re: suggestions on router w/firewall"
- Reply: CZ: "Re: suggestions on router w/firewall"
- Reply:(deleted message) Micheal Robert Zium: "Re: suggestions on router w/firewall"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Sun, 07 Nov 2004 01:58:44 GMT
In article <AUejd.18738$6q2.16252@newssvr14.news.prodigy.com>,
CZ@no99spam.com says...
> My wording for the above would be:
> Some end user NAT-router products only have simple packet filtering (if even
> that) for a firewall (some have SPI, which appears to be DoS protection for
> the WAN port).
I see now, and this is where we differ, I would never make the mistake
of using NAT, even with SPI, as a firewall method. You continue to
describe standard NAT (with or without SPI) as a firewall service.
> A simple packet filtering firewall can only make a forward/drop decision
> based on static rules and info in the packet headers at OSI layer 3 & 4
> (primarily IP address & port #).
What you are describing is not a property of a firewall, it's a property
of Port Forwarding, and while Firewalls can forward ports, port
forwarding does not make them firewalls.
The NAT device vendors seem hell bent on changing the definition of what
a firewall is, and as far as I can see, the only reason for it is to
increase sales. a device that can't tell the difference between HTTP and
FTP is not a firewall.
-- -- spamfree999@rrohio.com (Remove 999 to reply to me)
- Next message: Beauregard T. Shagnasty: "Re: Loose Internet Connection Overnight"
- Previous message: Kerodo: "Re: Kerio 2.1.5 vulnerability"
- In reply to: CZ: "Re: suggestions on router w/firewall"
- Next in thread: CZ: "Re: suggestions on router w/firewall"
- Reply: CZ: "Re: suggestions on router w/firewall"
- Reply:(deleted message) Micheal Robert Zium: "Re: suggestions on router w/firewall"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|