Re: Hiding NATs with PF

From: Max Bolingbroke (batterseapower_at_hotmail.com)
Date: 09/28/05


Date: 28 Sep 2005 14:06:43 -0700


? wrote:
> NAT can hide zombied boxes from regular scans for their currently known
> subset of zombied boxes.
> In addition NAT can prevent them from using existing exploits to install
> spyware.
> Some NAT devices were (and may still be) susceptable to being
> compromised.

I would understand this, but surely the problem would be just as bad if
firewalls were being used on a single non-NAT host connected to the
same part of the network? Actually, firewalls are mandatory in this
network, so it makes even less sense.

> As a general rule the 11th commandment (Thou shalt not get caught) applies.
> Do not announce the presence of a NAT device.
> Do not obviously abuse it.
> Be prepared to switch to connecting directly with zero notice.
>
> Remember it's easier to seek forgiveness than permission :-).

Sage advice :)

Thanks for your input,

Max



Relevant Pages

  • Re: [fw-wiz] Internet accessible screened subnet - use public orprivate IPs?
    ... >The whole reason NAT was implemented was because of a very finite number of publicly routable IP addresses. ... The first firewalls I built offered NAT (inherent in the design and then later via ... "Proxy transparency" in Gauntlet) because a lot of the early firewall customers ... re-address their network or NAT ...
    (Firewall-Wizards)
  • Re: 56k dial up on laptop 802.11G ?
    ... Firewalls can also filter specific types of network traffic. ... Let's knock the NAT out of the box. ...
    (alt.internet.wireless)
  • Re: NAT is not a mechanism for securing a network.. but.. HELP!
    ... >> one of their firewalls). ... >> But there was one claim that sounded like a serious problem for NAT ... >> device opens a port by putting it in the NAT table, ... way into the network? ...
    (comp.security.firewalls)
  • Re: any suggestion for a good hardware firewall
    ... Besides being ICSA-certified firewalls, they ... > most certainly do much more than NAT. ... multiple subnets on each LAN or DMZ port - you would use something like ... this in between the Plant Floor network and the Business Office network, ...
    (comp.security.firewalls)
  • Re: Linksys hardware firewall enough...?
    ... >> network with one of those NAT systems and it gets compromised. ... I would never consider trying to break into a network that I was not ... them that the devices marketed as firewalls, that are only NAT Routers ...
    (comp.security.firewalls)