Re: Understanding NAT, Firewalls, TCP/IP



Nigel Wade wrote:

> Most home NAT routers don't even have a firewall. Those which do are
> generally shipped with the firewall disabled.

Both of the home NATers that I've had have included firewalls. The first (a
cheap thing) had only simple firewalling, but it was there and was turned on by
default. IIRC it blocked "random" outgoing connections by default (but that
was some time ago and I could be wrong). My current NATing router features a
decidedly more elaborate firewall, and that certainly shipped in a default
configuration disallowing outbound connections on arbitrary ports.

Oh, and it doesn't and won't -- as a matter of manufacturer's security
policy -- support UPnP.

I /could/ allow outgoing connections on any ports I liked, but I see no good
reason to do so for any except a very small number of protocols. I
/definitely/ wouldn't open up a port in order to take part in a BitTorrent-like
distribution scheme.

-- chris


.



Relevant Pages

  • Re: Understanding NAT, Firewalls, TCP/IP
    ... >> Most home NAT routers don't even have a firewall. ... > configuration disallowing outbound connections on arbitrary ports. ... I was basing the statement on my limited knowledge of home NAT routers. ... Nigel Wade, System Administrator, Space Plasma Physics Group, ...
    (comp.lang.java.programmer)
  • Re: Trouble accessing Outlook Web Access from behind firewall
    ... When starting the firewall I also set ... > rejected and dropped packets are logged, however I see nothing in my log ... > # Higher ports needed to accept incoming/outgoing calls ...
    (comp.security.firewalls)
  • Re: iptables configuration
    ... >> that if a 'virus/trojan' initiated a connection to the net, the firewall ... >> would not protect the LAN. ... The LAN is NATed with private IPs to one public IP. ... the ports that are used by services running on linux. ...
    (comp.os.linux.security)
  • Re: Norton Personal Firewall 2003
    ... |> First thing I would do is put the GRC test site into the Exclusions ... | ports they will not get the same result being in my blocklist, ... the firewall checks unsolicited inbound communications attempts. ...
    (comp.security.firewalls)
  • Re: How to stealth against ping/echo requests?
    ... I just started using the Online-Armor firewall. ... Some ports are even open. ... Are you behind a router? ... Every time it founds a new LAN, it asks if you want to trust it ...
    (comp.security.firewalls)