Great Circle Associates Firewalls
(January 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Re[2]: NT NAT
From: Carl Karlsson <ckn @ findata . se>
Date: Sat, 4 Jan 1997 09:40:46 +0100 (MET)
To: "'Firewalls Mailing List'" <firewalls @ GreatCircle . COM>
In-reply-to: <199701031957 . LAA20883 @ miles . greatcircle . com>

On Fri, 3 Jan 1997 dharris @
 kcp .
 com wrote:

> Added security?  Only that extra security provided by not having your network's 
> addresses known to the 'net.  The NAT provides no extra protection from someone 
> "outside" who knows or deduces (from unparsed E-mail headers, perhaps) your 
> actual addresses.  It also provides no activity logging for later audit, at 
> least not as part of the NAT function.

Please correct me if I'm wrong here but I was under the impression that
the 192.168.x.x-addresses was 'non-routable' or whatever the term is.
Under what circumstances can an external intruder gain access to my
internal 192.168.x.x-machines? 

I'm not arguing that NAT is a great firewall, I'm just trying to
understand what the risks are with masquerading 'illegal' addresses behind
a machine that is 'secure enough'. And, sorry, just saying it's useless
without any argument just isn't enough. :)


  Calle



Follow-Ups:
References:
Indexed By Date Previous: Re: Re[2]: NT NAT
From: lists @ lina . inka . de (Bernd Eckenfels)
Next: Re: Re[2]: NT NAT
From: peter @ baileynm . com (Peter da Silva)
Indexed By Thread Previous: Re: Re[2]: NT NAT
From: lists @ lina . inka . de (Bernd Eckenfels)
Next: Re: Re[2]: NT NAT
From: peter @ baileynm . com (Peter da Silva)

Google
 
Search Internet Search www.greatcircle.com