NAT routers - is IP spoofing a risk?

From: if (if_at_nospam.uk.invalid)
Date: 11/20/05

  • Next message: Andy Walker: "Re: Download freeware RKR scanning software (detect Sony rootkit & others)"
    Date: 20 Nov 2005 14:38:23 GMT
    
    

    The firewall on my ADSL router sometimes reports stuff like the following:

                Firewall:IP Spoofing detected,from 192.168.2.28 to 10.0.0.3

    (my computer was on 10.0.0.3 at that point).

    But is such an attack even a risk on an ADSL router? That is, if the
    firewall had not been running, would an ADSL router actually allow WAN-side
    traffic through to the LAN just because it claimed to be from an IP address
    used by the LAN? It seems illogical that such a device could be fooled,
    since WAN traffic is self-evidently WAN traffic regardless of the IP
    address it presents to the router, since it arrives on a different physical
    connection.

    I have also heard people say that you should choose a non-obvious address
    range for machines on your LAN to guard against spoofing (or attempts to
    connect to specific LAN machines by guessing their IP address), but is
    there really a risk here or is NAT routing immune to such subterfuges?


  • Next message: Andy Walker: "Re: Download freeware RKR scanning software (detect Sony rootkit & others)"

    Relevant Pages

    • Re: Additionally
      ... By all means get the second NIC and utilise the new firewall/router. ... old ADSL router. ... Install second NIC into server. ... Configure new router to seperate LAN IP i.e 10.0.0.x. ...
      (microsoft.public.windows.server.sbs)
    • Re: Additionally
      ... Firewall/Router to place inbetween the ADSL Router and the LAN. ... The link I provided shows how to configure with 2 nics and is the ...
      (microsoft.public.windows.server.sbs)
    • Re: Additionally
      ... What about the problem of the ISP not giving a gateway IP? ... By all means get the second NIC and utilise the new firewall/router. ... old ADSL router. ... Configure new router to seperate LAN IP i.e 10.0.0.x. ...
      (microsoft.public.windows.server.sbs)
    • Re: Additionally
      ... By all means get the second NIC and utilise the new firewall/router. ... Store old ADSL router. ... Configure new router to seperate LAN IP i.e 10.0.0.x. ... I've never heard of an ISP not providing a gateway IP when they ...
      (microsoft.public.windows.server.sbs)
    • Re: PIX firewall with router problem
      ... > We have a PIX 501 firewall sitting between our LAN and an ADSL router. ...
      (comp.security.firewalls)