Re: Hiding NATs with PF

From: Greg Hennessy (me_at_privacy.org)
Date: 09/28/05


Date: Wed, 28 Sep 2005 21:15:50 +0100

On 28 Sep 2005 17:29:40 GMT, jpd <read_the_sig@do.not.spam.it.invalid>
wrote:

>> How do they 'enforce' this policy exactly ? I've worked in environments
>> with ridiculous policies because some clueless idiot copied something out
>> of a textbook.
>
>Not to mention the time it would take humans to go out and try and
>detect this.

Quite, and it requires 'specialist' (read expensive) know how to do this.

>> Dictating the network architecture of an external 3rd party would fit the
>> 'ridiculous' category.
>
>Ah, but if the OP is on a campus or something, _his_ network may
>very well be counted part of the network the policy is set for.

That's true.

>
>I know of such networks where there is a strict ``no nat'' policy
>because they don't want to deal with abuse hidden by that and the
>resulting expected gefingerpointing. I can't blame them for their
>motives.

Much easier to police using a default deny policy :-)

greg

-- 
"Access to a waiting list is not access to health care"


Relevant Pages

  • Re: Hiding NATs with PF
    ... >>which has a strict limit of 1 IP address per person but also ... > with ridiculous policies because some clueless idiot copied something out ... Ah, but if the OP is on a campus or something, _his_ network may ... very well be counted part of the network the policy is set for. ...
    (comp.unix.bsd.openbsd.misc)
  • Re: No Shut Down or Restart for Domain Admins
    ... run rsop.msc from your DC and check which policy is responsible to this. ... I have created a group policy in a development network and imported it ... NT AUTHORITY\Authenticated Users Read (from Security Filtering) No ... Enforce user logon restrictions Enabled ...
    (microsoft.public.windows.server.active_directory)
  • Re: EventID 1054 from Userenv for startup script
    ... So if you said "some machines don't have full access to the network ... at startup" the GPO's seems not to apply correct. ... startup script policy. ...
    (microsoft.public.windows.group_policy)
  • Re: COBOL is Number One
    ... used for policy discussions across companies and continents. ... The Network empowers this. ... about the users using spreadsheets but was more worried about the fact ... My point was that there is increasing computer literacy in the work ...
    (comp.lang.cobol)
  • Re: Hang @ Applying Computer Settings/Applying Your Personal Setti
    ... It would appear the you have ruled out network connectivity problems ... >> Policy that has had changes but that should not happen every time unless ... >> computers having a gigabit network adapter. ... Policies are being created and maintained only on ...
    (microsoft.public.windows.group_policy)