Bluehost.com Web Hosting $6.95

Re: Bridging vs Routing Firewalls

This is a discussion on Re: Bridging vs Routing Firewalls within the IPFilter forums, part of the System Security and Security Related category; Carson Gaspar wrote: > --On Thursday, July 31, 2003 10:47 PM -0400 Jefferson Ogata > <Jefferson.Ogata@noaa....


Go Back   Usenet Forums > System Security and Security Related > IPFilter

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 08-01-2003
Jefferson Ogata
 
Posts: n/a
Default Re: Bridging vs Routing Firewalls

Carson Gaspar wrote:
> --On Thursday, July 31, 2003 10:47 PM -0400 Jefferson Ogata
> <Jefferson.Ogata@noaa.gov> wrote:
>> One downside to bridges is that they can't do NAT, except perhaps in very
>> limited ways.

>
> Why? I've heard this before, and nobody who says it seems to have any
> facts to back them up. There is absolutely nothing magic about
> decrementing or not decrementing a hop count. Yes, your routing must be
> configured properly, but that's not news.


Why? I couldn't tell you -- I don't use IP Filter in a bridged configuration.
And don't misunderstand me to be saying that it's not possible for Brand X
bridge to support NAT (in fact, if you search the list archives you'll see
I've stated it's possible). But, as I've said, in the case of IP Filter,
others, including Darren, have stated that it just don't work right or
completely, e.g.:

http://marc.theaimsgroup.com/?l=ipfi...5283216321&w=2
http://marc.theaimsgroup.com/?l=ipfi...9717118236&w=2
http://marc.theaimsgroup.com/?l=ipfi...0667110724&w=2
http://marc.theaimsgroup.com/?l=ipfi...0387609631&w=2
http://marc.theaimsgroup.com/?l=ipfi...5408915756&w=2

If these statements are inaccurate, I'm sorry, but you know, Carson, the
statement you quoted isn't really the central thesis of what I was saying, is it?

--
Jefferson Ogata <Jefferson.Ogata@noaa.gov>
NOAA Computer Incident Response Team (N-CIRT) <ncirt@noaa.gov>

Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT +1. The time now is 06:10 PM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0