FW NAT and Keep State

From: Geoff Lane (bunsen_at_talk21.com)
Date: 12/05/03


Date: Fri, 05 Dec 2003 10:59:51 +0000

Re WiFi set up with three computer access (MAC access enabled).

I know a little about Firewalls in relation to Packet Filtering, I
know enough to confuse myself rather than, like many, live in blissful
ignorance.

I recently installed broadband, as I enjoy a 'fiddle' I bought a
slightly more user definable router than the norm, I got a Vigor 2600.

It uses NAT by default, this shows Stealth on Steve Gibson's site and
I have been told that with NAT there is no real need to have any
inbound protection as NAT takes care of it.

When I used my Linux machine as a server I had 'mangle' enabled (I
think this is NAT) and then there was a rule for any inbound packets
to be associated or related otherwise they would be dropped.

My router has an option on the 'rules' set up to tick 'keep state' and
I am wondering if this is an option only to be used for other
functions such as DMZ or open ports (I am guessing here).

Geoff Lane



Relevant Pages

  • Re: Double NAT?
    ... >>Is it possible to install a firewall that perform one time more the NAT? ... Because Zyxel perform only packet filtering, ... Transparent proxy for FTP, WEB. ...
    (comp.security.firewalls)
  • Re: iptables 1.2.7a "iptables-save" bug?
    ... As I understand it all of the actual packet filtering for masquerading is ... done on the FORWARD chain of the FILTER table. ... Is there a need to modify the default policies on the NAT and MANGLE ...
    (comp.os.linux.security)
  • Re: suggestions on router w/firewall
    ... of using NAT, even with SPI, as a firewall method. ... describe standard NAT as a firewall service. ... That sentence refers to four concepts: NAT, router, simple packet filtering, ... created port table to packet header info, and NAT does change the packet. ...
    (comp.security.firewalls)
  • Re: Windows 2003 Server NAT not allowing IPSEC to go through.
    ... If I'm using NAT without any packet filtering or firewalling, these ports should just be open and the packets should just pass through, should they not? ... connect to their server using IPSec. ...
    (microsoft.public.win2000.ras_routing)