Re: beginner question-routers

From: Walter Roberson (roberson_at_ibd.nrc-cnrc.gc.ca)
Date: 02/23/05


Date: 23 Feb 2005 19:51:22 GMT

In article <Xns96069315DE1EAleavemealone@130.81.64.196>,
peon1000002 <work@big.box> wrote:
:from a website i was reading...

:"The solution is to separate your Internet traffic from your LAN (file
:sharing) traffic. To do this, a special networking device or software can
:be placed between your computers and the Internet. In addition, attempts
:by hackers to access your computers are stopped by a broadband router."

:my 1st question is does the router automatically "out of the box" separate
:the internet traffic from the LAN or do i need to configure it to do so?

You would, at a minimum, need to configure the inside and outside IP
address range for the router. After that, *most* routers will, by default,
pass all traffic through between the inside and the outside and
vice versas, not stopping it at all.

:the second sentence is referring to the firewall capability right?
:if i dont activate the router firewall hackers could access the computer
:even with a router (if i didnt have mcafee).

That second sentance is just plain wrong. Broadband routers do not
stop anyone from accessing anything. If you have a cable modem, then
traffic -content- between the ISP and you might travel encrypted
[but the IP layer would normally be unencrypted for cable], and in
that case the cable modem is supposed to prevent others from being able
to usefully sniff the content of your traffic.... but anyone on your
block would still be able to look at the IPs and figure out where
you are connecting to.

What the sentance -might- be referring to is that most consumer
broadband devices use NAT (Network Address Translation). There is
a common belief that if you have NAT then your network is safe.
It doesn't work that way, though: if you have NAT but do not have a
"stateful packet inspection" firewall then depending on the implimentation
and configuration, it might range from providing no protection at all
to providing access only to systems you are already connected to
[keep in mind that if you are running filesharing software or Skype
that you are connecting to hundreds or thousands of machines that
you don't realize you are connecting to!]

NAT by itself is not a particularily strong security layer.
It can cut down the noise a fair bit, but still leaves you open
for anyone who takes a bit more time to target you.

If you want information on why some people think that NAT is a very
poor idea, then I suggest checking out postings by Melinda Shore.

-- 
   Warhol's Law: every Usenet user is entitled to his or her very own
   fifteen minutes of flame                  -- The Squoire


Relevant Pages

  • Re: HELP ME VPN SERVER SETUP ON WIN2K SERVER
    ... How can I browse the LAN im connecting to as if I was on a wired LAN client ... Leave the hardware router as the gateway of the LAN, ... Make the server the gateway of your LAN. ...
    (microsoft.public.win2000.ras_routing)
  • Understanding voip and NAT
    ... PC on my local lan - via a NAT D-link 604 broadband router to the net, ... I have a spare linux server on this network to run some form of server etc. ...
    (Debian-User)
  • Re: Linksys WRT54G and Firewall software
    ... and it is completely unprotected on the LAN side. ... But what I have meant is that a average router is a very vulnerable ... NAT router's are not "secured" per se by default. ... NAT tries to match incoming packets to established connections and conversations. ...
    (comp.security.firewalls)
  • Re: Wireless laptop
    ... some with 4 (for connecting to your existing PC). ... You may need a LAN card for your PC if it doesn't already have one. ... when I was looking for one recently I found a lot of devices described as "ADSL/Broadband Router" or similar wording. ... This implies that they are a modem/router, when in fact they are only a router - you could use these with your Speedtouch but I'd recommend replacing it. ...
    (uk.comp.misc)
  • Re: Which home user router has a decent firewall inside it?
    ... Not for your LAN. ... The NAT translation on the router will ... NAT will inspect any packets if at all. ... public IP addresses in your LAN) and keep the firewall active. ...
    (comp.security.firewalls)