Re: NAT (Was: Is source address selection based on rules (netfilter) possible ?)
- From: Xavier Roche <xroche@xxxxxxxxxxxxxxxxxxxxxx>
- Date: Sun, 29 Aug 2010 15:08:01 +0200
Pascal Hambourg a écrit :
You cannot rely on it. Due to the lack of standardization, there are
many different implementations of NAT.
But at least NAT put you "behind" an opaque wall, for incoming traffic. Ie. portcan or direct attacks from the outside won't be possible, at least.
Of course, it means that legit servers will also have really big troubles (including crazy standard such as H323)
.
- Follow-Ups:
- Re: NAT
- From: Pascal Hambourg
- Re: NAT
- References:
- Is source address selection based on rules (netfilter) possible ?
- From: Xavier Roche
- Re: Is source address selection based on rules (netfilter) possible ?
- From: Pascal Hambourg
- Re: Is source address selection based on rules (netfilter) possible ?
- From: Xavier Roche
- Re: Is source address selection based on rules (netfilter) possible ?
- From: Roger Blake
- Re: Is source address selection based on rules (netfilter) possible ?
- From: David Schwartz
- Re: Is source address selection based on rules (netfilter) possible ?
- From: David Brown
- Re: Is source address selection based on rules (netfilter) possible ?
- From: Pascal Hambourg
- Is source address selection based on rules (netfilter) possible ?
- Prev by Date: Re: Is source address selection based on rules (netfilter) possible ?
- Next by Date: Re: Is source address selection based on rules (netfilter) possible ?
- Previous by thread: Re: Is source address selection based on rules (netfilter) possible ?
- Next by thread: Re: NAT
- Index(es):
Relevant Pages
|