Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

do i need firewall software if using NAT?

Thread Tools
 
Search this Thread
 
Old Sep 3, 2002 | 04:35 PM
  #1  
suba's Avatar
suba
Thread Starter
Scooby Regular
 
Joined: Mar 2000
Posts: 2,462
Likes: 0
Question

if the shared PCs are using NAT for IP from a broadband router, in theory can i get away without installing any firewall software like zonealarm, etc???
Reply
Old Sep 3, 2002 | 05:48 PM
  #2  
mega_stream's Avatar
mega_stream
Scooby Regular
 
Joined: May 2001
Posts: 4,580
Likes: 0
From: Scotland
Talking

No
Reply
Old Sep 3, 2002 | 06:42 PM
  #3  
suba's Avatar
suba
Thread Starter
Scooby Regular
 
Joined: Mar 2000
Posts: 2,462
Likes: 0
Post

so i still need software firewall? i thought NAT IP is not hackable? (coz it's fake???)
Reply
Old Sep 3, 2002 | 07:40 PM
  #4  
vmax's Avatar
vmax
Scooby Regular
 
Joined: Dec 2001
Posts: 291
Likes: 0
Post

NAT will be fine for a small home office. Especially if you are using private non public routed ip address's.

10.0.0.0 - 10.255.255.255 (10/8 prefix)
172.16.0.0 - 172.31.255.255 (172.16/12 prefix)
192.168.0.0 - 192.168.255.255 (192.168/16 prefix)

http://www.ietf.org/rfc/rfc1918.txt?number=1918

However if you can afford a decent firewall [ Zone Alarm is good for dialup modem usage] I would get one. With a firewall you can kill icmp or ping replies and stop script kiddies sapping your bandwidth by port scanning your ip address.

You can even use the firewall to detect if your machine has spyware or a virus.

NAT is a good start, but get a firewall if you can.
Reply
Old Sep 3, 2002 | 09:56 PM
  #5  
RVeiga's Avatar
RVeiga
Scooby Regular
 
Joined: Mar 2000
Posts: 225
Likes: 0
Wink


NAT (Network Address Translation) is exactly that. It translates addresses from non routable to routable ones. That is not security in any shape or form.

I run DSL at home and get scanned everyday.

I suggest a statefull Firewall.

SonicWall/NetScreen/Cisco/Sofaware/etc...main players in the soho
market.
Reply
Old Sep 3, 2002 | 10:46 PM
  #6  
suba's Avatar
suba
Thread Starter
Scooby Regular
 
Joined: Mar 2000
Posts: 2,462
Likes: 0
Post

thanx for all your reply. i just wanna double check on the security issue of NAT.
Reply
Old Sep 4, 2002 | 11:46 AM
  #7  
Jeff Wiltshire's Avatar
Jeff Wiltshire
Scooby Regular
 
Joined: Nov 2000
Posts: 2,021
Likes: 1
From: 412 Wheel HP Audi RS4
Post

Suba

NAT is designed to help with the lack of IP addresses in IPV4 and not as a security protocol. Routers on the Internet are mean't not to forward the RFC 1918 networks but some do....

It would be trival to spoof a RFC1918 address...

Get a stateful firewall if you can afford it, if you can't get a Software 'Personal Firewall' (I use the term loosely).



Jeff
Reply

Trending Topics

Old Sep 4, 2002 | 03:20 PM
  #8  
Retsyn [i-Dub]'s Avatar
Retsyn [i-Dub]
Scooby Newbie
 
Joined: Sep 2002
Posts: 3
Likes: 0
Post

Make sure that whatever router you settle on it has the capability to utilize "stealth mode" which is to say that it won't even respond to port requests. Essentially if a script kiddie scans your IP he has to wait for it to time out. Macsense makes a nice 4 port 100base switching router. I have the MIH-130 X-Router. On the topic of a firewall. Yes, you still need to run firewall software on the computer itself. It's really the only way to know if a trojan has been installed on your system. Zonealarm is my weapon of choice too...
Reply
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
hardcoreimpreza
Computer & Technology Related
21
Oct 11, 2015 03:40 PM
Brzoza
Engine Management and ECU Remapping
1
Oct 2, 2015 05:26 PM
BlkKnight
Non Scooby Related
104
Oct 1, 2015 09:40 PM
dantiel
General Technical
8
Sep 29, 2015 11:33 PM
Wurzel
Computer & Technology Related
10
Sep 28, 2015 12:28 PM




All times are GMT +1. The time now is 08:13 AM.