Re: restrict implicit binding to interfaces



David Schwartz wrote:

On Oct 30, 5:08 am, Maxwell Lol <nos...@xxxxxxxxxxx> wrote:

Sounds like a real security risk to me. That says I can send
packets to a router/firewall with the destination being the
inside address, and it will respond.

Since you can send packets to that router/firewall with the
destination being the outside address much more easily, why
would you think this matters?

I think, he's fallen for the misconception, that NAT and private
address ranges are means of security. Tell the people about
IPv6, and they'll respond in the same way.

Wolfgang Draxinger
--
E-Mail address works, Jabber: hexarith@xxxxxxxxxx, ICQ: 134682867

.



Relevant Pages

  • Re: Problem with multiple IPs assigned to one server behind PIX 501...
    ... >> I am having a problem with my PIX 501. ... >>SERVERA, but I also need 209.14.222.102 to go to SERVERA, and the only ... > ping packets, the PIX would not have any way of knowing which IP ... > Think of it from the point of view of what the source and destination ...
    (comp.dcom.sys.cisco)
  • RE: Using Snort to find creditcard data?
    ... network transmission took place with between two IP sockets ... some number of bytes and packets were transmitted, ... the destination address is or is not within expectations ...
    (Focus-IDS)
  • Re: ARP requests on my net?
    ... MAC should be dumped. ... should dump packets not destined for its MAC. ... Or does IP need the MAC of the destination ... needs to send to the router via ethernet so it ARP's the ...
    (Fedora)
  • RE: Ping Scan
    ... sent) and the host is inexistent, a idlescan seemed a better guess. ... Also, from what you mentioned, unassigned IPs were seen in the destination ... The packets you are getting doesn't ... A presente mensagem pode conter informação considerada confidencial. ...
    (Incidents)
  • Re: martian destination 0.0.0.0 from ... in /var/log/messages
    ... 1122 Requirements for Internet Hosts - Communication Layers. ... Your original post showed this host as the source of martian destination ... ngrep to watch for and capture any packets for 'source 255.255.255.255' or ... some one would have to be using a special tool that bypasses the ...
    (comp.os.linux.misc)