Great Circle Associates Firewalls
(February 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Optimal Throughput for NAT
From: mch @ squirrel . com (Mark Henderson)
Date: Sun, 2 Feb 1997 14:17:57 -0800
To: chrisp @ sitescape . com
Cc: firewalls @ GreatCircle . COM
In-reply-to: <32F4E5E9 . 1504 @ tidalwave . net>; from Chris Pressley on Feb 2, 1997 14:07:21 -0500
References: <32F4E5E9 . 1504 @ tidalwave . net>

Chris Pressley writes:
> NAT is a small part of my overall security plan. I'm looking for the
> best way to implement NAT, primarily from a cost and performance
> standpoint. Currently, I know of three ways to do NAT:
>   1) Install and configure a firewall
>   2) Dedicate a host, using software such as IPRoute    
> (http://www.mischler.com/iproute/)
>   3) Configure a router (e.g. Cisco with IOS 11.2 and "IP Options")
> 
> I'm looking for feedback on the following:
>   1) What is my best dollar/cost solution?
>   2) Are there other ways to implement NAT that I'm not aware of?

I'm not going to attempt to answer the larger question, but you might 
also take a look at IP filter. It provides packet filtering, NAT 
functionality, and support for transparent proxies. It can also keep
some connection state information. 

http://coombs.anu.edu.au/~avalon/ip-filter.html

N.B. Although I like the feature set of this package, it is very much 
still a work in progress. If you aren't comfortable hacking a little 
C or generally playing around with your kernel, you should probably 
stay away from this. 

Attachment: pgpHxKJZDHwLo.pgp
Description: PGP signature


References:
Indexed By Date Previous: Re: [NTSEC] ActiveX, MSIE and Quicken
From: Bob Beck <beck @ obtuse . com>
Next: NTBugTraq now available
From: Russ <Russ . Cooper @ RC . on . ca>
Indexed By Thread Previous: Optimal Throughput for NAT
From: Chris Pressley <chrisp @ tidalwave . net>
Next: Optimal Throughput for NAT
From: Chris Pressley <chrisp @ tidalwave . net>

Google
 
Search Internet Search www.greatcircle.com