Great Circle Associates Firewalls
(March 1998)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: NAT in NBT environment
From: Grich Ondřej <GrichO @ radiomobil . cz>
Date: Tue, 10 Mar 1998 12:38:36 +0100
To: "'Firewalls @ GreatCircle . COM'" <Firewalls @ GreatCircle . COM>


	Hello,

I'm facing up the  following problem:

We have 2 LAN's. They are connected through Firewall on which NAT is
enabled. We are using Windows NT server and WIndows 95 As main OS
platform. Some MS Windows based applications are using NBT (Netbios over
TCP/IP). When such a application generates packet which goes through
Firewall, NAT rules are applied on it. But the NAT is done only on IP
header of packet not on NBT part of packet. This situation generates
sonfusing state - IP header of packet says something else then NBT part
of packet. We have faced up such a situation with NetBios Name Service
(137/udp) and NetBios datagram service (138/udp). 
For example we have tried to make trusts between 2 NT Domains. The NT
domains are separated byt firewall with NAT. When trying to make a
trust, Domain Controlers are querying for name of the domain controler
in other domain. The query is done by nbname service (137/udp). Domain
controllers are confused between inconsistency between IP and NBT part
of header.

Does any one of YOU face up same problem? 
Is there some tool for NBT NAT?


Best regards

Ondra Girch

Indexed By Date Previous: [no subject]
From: Don_Tompkins @ esd . tracor . com
Next: RE: Connecting to Ibm AS/400 from outside a fw
From: manuel . ricca @ pararede . pt
Indexed By Thread Previous: [no subject]
From: Don_Tompkins @ esd . tracor . com
Next: [no subject]
From: "Esteban Vasquez" <esteban @ iamnet . com>

Google
 
Search Internet Search www.greatcircle.com