Technology Questions

Go Back   Technology Questions > Software Questions > Operating System Questions > Windows XP

Windows XP Discuss the Microsoft Windows XP Operating System

Reply
 
LinkBack Thread Tools
  #1 (permalink)  
Old 05-07-2009, 11:20 AM
ToddAndMargo
Newsgroup Contributor
 
Posts: n/a
firewall test and NAT

Hi All,

I would like to test my firewall, but have a NAT box
between me and the various firewall tests I know
of. Anyone know of a firewall test that shoots
through NAT?

Many thanks,
-T
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

 
Old 05-07-2009, 11:20 AM
  #2 (permalink)  
Old 05-07-2009, 11:40 AM
John John - MVP
Newsgroup Contributor
 
Posts: n/a
Re: firewall test and NAT

ToddAndMargo wrote:
> Hi All,
>
> I would like to test my firewall, but have a NAT box
> between me and the various firewall tests I know
> of. Anyone know of a firewall test that shoots
> through NAT?


NAT would be pretty useless if anything could just "shoot" through it.
Open (forward) a port in the box or temporarily disable/bypass the NAT
box for your tests.

John
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

  #3 (permalink)  
Old 05-07-2009, 11:50 AM
ToddAndMargo
Newsgroup Contributor
 
Posts: n/a
Re: firewall test and NAT

John John - MVP wrote:
> ToddAndMargo wrote:
>> Hi All,
>>
>> I would like to test my firewall, but have a NAT box
>> between me and the various firewall tests I know
>> of. Anyone know of a firewall test that shoots
>> through NAT?

>
> NAT would be pretty useless if anything could just "shoot" through it.
> Open (forward) a port in the box or temporarily disable/bypass the NAT
> box for your tests.
>
> John


Hi John,

The bad guys know all about NAT. And it is indeed useless
as a firewall.

The bad guys start with 192.168.0.0/24 and work their way
up. Check your firewall logs, you will see SYN packet probes
on it all the time: about 1/100 if you did not use NAT, but
still enough to do damage. NAT is *not* a firewall -- it is
a common misconception.

I was hoping to way to test it without redoing anything
on my network.

-T
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

  #4 (permalink)  
Old 05-07-2009, 12:00 PM
John John - MVP
Newsgroup Contributor
 
Posts: n/a
Re: firewall test and NAT

ToddAndMargo wrote:
> John John - MVP wrote:
>> ToddAndMargo wrote:
>>> Hi All,
>>>
>>> I would like to test my firewall, but have a NAT box
>>> between me and the various firewall tests I know
>>> of. Anyone know of a firewall test that shoots
>>> through NAT?

>>
>> NAT would be pretty useless if anything could just "shoot" through it.
>> Open (forward) a port in the box or temporarily disable/bypass the NAT
>> box for your tests.
>>
>> John

>
> Hi John,
>
> The bad guys know all about NAT. And it is indeed useless
> as a firewall.
>
> The bad guys start with 192.168.0.0/24 and work their way
> up. Check your firewall logs, you will see SYN packet probes
> on it all the time: about 1/100 if you did not use NAT, but
> still enough to do damage. NAT is *not* a firewall -- it is
> a common misconception.
>
> I was hoping to way to test it without redoing anything
> on my network.


I'm by no means any kind of expert on this but my understanding about
NAT is that it will only allow traffic in if the request for the packets
originated from within. You say that you have a "NAT box" I assume that
to be a router of sorts, check the documentation for your router.

John
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

  #5 (permalink)  
Old 05-07-2009, 12:40 PM
ToddAndMargo
Newsgroup Contributor
 
Posts: n/a
Re: firewall test and NAT

John John - MVP wrote:
> ToddAndMargo wrote:
>> John John - MVP wrote:
>>> ToddAndMargo wrote:
>>>> Hi All,
>>>>
>>>> I would like to test my firewall, but have a NAT box
>>>> between me and the various firewall tests I know
>>>> of. Anyone know of a firewall test that shoots
>>>> through NAT?
>>>
>>> NAT would be pretty useless if anything could just "shoot" through
>>> it. Open (forward) a port in the box or temporarily disable/bypass
>>> the NAT box for your tests.
>>>
>>> John

>>
>> Hi John,
>>
>> The bad guys know all about NAT. And it is indeed useless
>> as a firewall.
>>
>> The bad guys start with 192.168.0.0/24 and work their way
>> up. Check your firewall logs, you will see SYN packet probes
>> on it all the time: about 1/100 if you did not use NAT, but
>> still enough to do damage. NAT is *not* a firewall -- it is
>> a common misconception.
>>
>> I was hoping to way to test it without redoing anything
>> on my network.

>
> I'm by no means any kind of expert on this but my understanding about
> NAT is that it will only allow traffic in if the request for the packets
> originated from within. You say that you have a "NAT box" I assume that
> to be a router of sorts, check the documentation for your router.
>
> John


Hi John,

It is a router.

The trouble with NAT is that the bad guys just slap their
guess as to what your internal off Internet address on
to their probe. They find you very quickly if your internal
off Internet address is 192.168.0.xxx. (Recommendation:
pick an internal address other than 192.168.0.0/24 or
192.168.1.0/24.)

NAT does not stop incoming requests called SYN (TCP) or
state "New" (TCP or UDP). It only stops traffic not
properly addressed to your internal network. Enough
guessing and the bad guys will find you.

NAT is *NOT* a firewall. You take you rear end in your hands
if you rely on NAT to protect you from port probes.

-T

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

  #6 (permalink)  
Old 05-07-2009, 01:00 PM
John John - MVP
Newsgroup Contributor
 
Posts: n/a
Re: firewall test and NAT

ToddAndMargo wrote:
> John John - MVP wrote:
>> ToddAndMargo wrote:
>>> John John - MVP wrote:
>>>> ToddAndMargo wrote:
>>>>> Hi All,
>>>>>
>>>>> I would like to test my firewall, but have a NAT box
>>>>> between me and the various firewall tests I know
>>>>> of. Anyone know of a firewall test that shoots
>>>>> through NAT?
>>>>
>>>> NAT would be pretty useless if anything could just "shoot" through
>>>> it. Open (forward) a port in the box or temporarily disable/bypass
>>>> the NAT box for your tests.
>>>>
>>>> John
>>>
>>> Hi John,
>>>
>>> The bad guys know all about NAT. And it is indeed useless
>>> as a firewall.
>>>
>>> The bad guys start with 192.168.0.0/24 and work their way
>>> up. Check your firewall logs, you will see SYN packet probes
>>> on it all the time: about 1/100 if you did not use NAT, but
>>> still enough to do damage. NAT is *not* a firewall -- it is
>>> a common misconception.
>>>
>>> I was hoping to way to test it without redoing anything
>>> on my network.

>>
>> I'm by no means any kind of expert on this but my understanding about
>> NAT is that it will only allow traffic in if the request for the
>> packets originated from within. You say that you have a "NAT box" I
>> assume that to be a router of sorts, check the documentation for your
>> router.
>>
>> John

>
> Hi John,
>
> It is a router.
>
> The trouble with NAT is that the bad guys just slap their
> guess as to what your internal off Internet address on
> to their probe. They find you very quickly if your internal
> off Internet address is 192.168.0.xxx. (Recommendation:
> pick an internal address other than 192.168.0.0/24 or
> 192.168.1.0/24.)
>
> NAT does not stop incoming requests called SYN (TCP) or
> state "New" (TCP or UDP). It only stops traffic not
> properly addressed to your internal network. Enough
> guessing and the bad guys will find you.


I don't think that is how it works. My router stops SYN floods and
operates in stealth mode, you could be "knocking" all you want but you
ain't gonna come in!

John
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

  #7 (permalink)  
Old 05-07-2009, 01:10 PM
ToddAndMargo
Newsgroup Contributor
 
Posts: n/a
Re: firewall test and NAT

John John - MVP wrote:

> I don't think that is how it works. My router stops SYN floods and
> operates in stealth mode, you could be "knocking" all you want but you
> ain't gonna come in!
>
> John


Hi John,

The is a good feature to have. But, is not NAT. It is an
additional feature. I was specifically referring only to NAT.

What scares me is people with $15.00 routers with NAT thinking
it is a real firewall.

-T
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

  #8 (permalink)  
Old 05-07-2009, 02:10 PM
John John - MVP
Newsgroup Contributor
 
Posts: n/a
Re: firewall test and NAT

ToddAndMargo wrote:
> John John - MVP wrote:
>
>> I don't think that is how it works. My router stops SYN floods and
>> operates in stealth mode, you could be "knocking" all you want but you
>> ain't gonna come in!
>>
>> John

>
> Hi John,
>
> The is a good feature to have. But, is not NAT. It is an
> additional feature. I was specifically referring only to NAT.
>
> What scares me is people with $15.00 routers with NAT thinking
> it is a real firewall.


I think that your assessment of how easily NAT can be broken is
overblown, consider this, if your firewall tests can't make it through
your NAT box it isn't as flimsy as you make it out to be! If anyone is
that worried they can put their private IP address in the Class A range
and give the hackers a "few" more doors to knock on. But I do have to
agree with you that you get what you pay for and that a $15 router may
not be the best thing to have between your network and the internet!

John
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

  #9 (permalink)  
Old 05-07-2009, 02:20 PM
ToddAndMargo
Newsgroup Contributor
 
Posts: n/a
Re: firewall test and NAT

John John - MVP wrote:
> I think that your assessment of how easily NAT can be broken is
> overblown, consider this, if your firewall tests can't make it through
> your NAT box it isn't as flimsy as you make it out to be!


You are missing the point. The firewall test sites that don't shoot
through NAT do not tag the secondary off internet address on to
their attack packets. In those tests, everything comes back perfect
because they are being rejected by the router.

Now if the test site took your secondary off Internet address from
your initial SYN packet to log into their site and probed you, the
router would pass their probes right through.


> If anyone is
> that worried they can put their private IP address in the Class A range
> and give the hackers a "few" more doors to knock on. But I do have to
> agree with you that you get what you pay for and that a $15 router may
> not be the best thing to have between your network and the internet!
>
> John


Best Buy is ready and waiting for the $15.00 crowd: their Geek Squid
will happily wipe your hard drive clean and reinstall windows for you!
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

  #10 (permalink)  
Old 05-07-2009, 02:20 PM
ToddAndMargo
Newsgroup Contributor
 
Posts: n/a
Re: firewall test and NAT

ToddAndMargo wrote:
> John John - MVP wrote:
>> I think that your assessment of how easily NAT can be broken is
>> overblown, consider this, if your firewall tests can't make it through
>> your NAT box it isn't as flimsy as you make it out to be!

>
> You are missing the point. The firewall test sites that don't shoot
> through NAT do not tag the secondary off internet address on to
> their attack packets. In those tests, everything comes back perfect
> because they are being rejected by the router.
>
> Now if the test site took your secondary off Internet address from
> your initial SYN packet to log into their site and probed you, the
> router would pass their probes right through.
>
>
>> If anyone is that worried they can put their private IP address in the
>> Class A range and give the hackers a "few" more doors to knock on.
>> But I do have to agree with you that you get what you pay for and that
>> a $15 router may not be the best thing to have between your network
>> and the internet!
>>
>> John

>
> Best Buy is ready and waiting for the $15.00 crowd: their Geek Squid
> will happily wipe your hard drive clean and reinstall windows for you!


Squid was a typo. :-)

He who pays the least, pays the most
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

  #11 (permalink)  
Old 05-07-2009, 03:20 PM
Leythos
Newsgroup Contributor
 
Posts: n/a
Re: firewall test and NAT

In article <#2gS5#zzJHA.4116@TK2MSFTNGP04.phx.gbl>,
ToddAndMargo@invalid.com says...
>
> Hi All,
>
> I would like to test my firewall, but have a NAT box
> between me and the various firewall tests I know
> of. Anyone know of a firewall test that shoots
> through NAT?


LOL, NAT doesn't have things "Shoot Through" it, that would break NAT.

If you want to test, most of those cheap, crappy, NAT routers have a
fake DMZ IP address, just map the DMZ to the same IP as your computer.
The DMZ IP gets all traffic that you have not created rules for, in most
NAT routers.

--
- Igitur qui desiderat pacem, praeparet bellum.
- Calling an illegal alien an "undocumented worker" is like calling a
drug dealer an "unlicensed pharmacist"
spam999free@rrohio.com (remove 999 for proper email address)
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

  #12 (permalink)  
Old 05-07-2009, 03:30 PM
Leythos
Newsgroup Contributor
 
Posts: n/a
Re: firewall test and NAT

Forget my last post I was wrong, you need to format your hd and reinstall
windows.


--
- Igitur qui desiderat pacem, praeparet bellum.
- Calling an illegal alien an "undocumented worker" is like calling a
drug dealer an "unlicensed pharmacist"
spam9999fre@rohio.com (remove 999 for proper email address)


"Leythos" <spam999free@rrohio.com> wrote in message
news:004bdcc4$0$14705$c3e8da3@news.astraweb.com...
> In article <#2gS5#zzJHA.4116@TK2MSFTNGP04.phx.gbl>,
> ToddAndMargo@invalid.com says...
>>
>> Hi All,
>>
>> I would like to test my firewall, but have a NAT box
>> between me and the various firewall tests I know
>> of. Anyone know of a firewall test that shoots
>> through NAT?

>
> LOL, NAT doesn't have things "Shoot Through" it, that would break NAT.
>
> If you want to test, most of those cheap, crappy, NAT routers have a
> fake DMZ IP address, just map the DMZ to the same IP as your computer.
> The DMZ IP gets all traffic that you have not created rules for, in most
> NAT routers.
>
> --
> - Igitur qui desiderat pacem, praeparet bellum.
> - Calling an illegal alien an "undocumented worker" is like calling a
> drug dealer an "unlicensed pharmacist"
> spam999free@rrohio.com (remove 999 for proper email address)


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

  #13 (permalink)  
Old 05-07-2009, 04:00 PM
Leythos
Newsgroup Contributor
 
Posts: n/a
Re: firewall test and NAT- Another Impersonation by Butts

In article <7gJMl.25461$BZ3.21524@newsfe12.iad>, spam9999free@rrohio.com
says...
>
> Forget my last post I was wrong, you need to format your hd and reinstall
> windows.


The above post was not by Leythos, it was a faked post and shows the
lack of ethics and lack of Honesty of Butts and his sock TrollBuster.

--
- Igitur qui desiderat pacem, praeparet bellum.
- Calling an illegal alien an "undocumented worker" is like calling a
drug dealer an "unlicensed pharmacist"
spam999free@rrohio.com (remove 999 for proper email address)
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

  #14 (permalink)  
Old 05-07-2009, 04:40 PM
Leythos
Newsgroup Contributor
 
Posts: n/a
Re: firewall test and NAT- Another Impersonation by Butts

In article <7gJMl.25461$BZ3.21524@newsfe12.iad>, spam9999free@rrohio.com
says...
>
> Forget my last post I was wrong, you need to format your hd and reinstall
> windows.



The above post was not by Leythos, it was a faked post and shows the
lack of ethics and lack of Honesty of Butts and his sock TrollBuster.


--
- Igitur qui desiderat pacem, praeparet bellum.
- Calling an illegal alien an "undocumented worker" is like calling a
drug dealer an "unlicensed pharmacist"
spam9999fre@rohio.com (remove 999 for proper email address)


"

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

  #15 (permalink)  
Old 05-07-2009, 04:40 PM
Leythos
Newsgroup Contributor
 
Posts: n/a
Re: firewall test and NAT- Another Impersonation by Butts

In article <7gJMl.25461$BZ3.21524@newsfe12.iad>, spam9999free@rrohio.com
says...
>
> Forget my last post I was wrong, you need to format your hd and reinstall
> windows.


The above post was not by Leythos, it was a faked post and shows the
lack of ethics and lack of Honesty of Butts and his sock TrollBuster.


--
- Igitur qui desiderat pacem, praeparet bellum.
- Calling an illegal alien an "undocumented worker" is like calling a
drug dealer an "unlicensed pharmacist"
spam9999fre@rohio.com (remove 999 for proper email address)


Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Windows Security Alerts says that my XP Firewall is off, but Firewall Control Panel says it is on?????? Juan I. Cahis Windows XP 6 11-27-2007 08:10 PM
firewall popup warning, but firewall is ENABLED! Ogg Windows XP 5 10-08-2007 09:20 AM
After installing Windows6.0-KB938194-x64, and Windows6.0-KB938979-x64 Kaspersky, jetico firewall, and kerio firewall crash system. Pablo Rampone Windows Vista 0 08-09-2007 01:40 PM
8 Tools You Can Use To Test Your Personal Firewall. Jose Manuel Tella Llop Windows XP 0 06-05-2007 06:40 AM
Firewall: use hard- and / or software firewall? Karl Self Windows XP 3 05-28-2007 01:30 PM


New To Technology Questions? Do You Need Help with Your Computer or Device? Do You Need Help with this site?

All times are GMT -8. The time now is 02:46 PM.


2003 - 2009 All Rights Reserved. Technology Questions

Search Engine Friendly URLs by vBSEO 3.3.0