Go Back   Velocity Reviews > Newsgroups > Computer Security
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply

Computer Security - How secure am I behind a NAT router?

 
Thread Tools Search this Thread
Old 01-06-2004, 11:16 PM   #1
Default How secure am I behind a NAT router?


Just bought a NAT router..

Now that my public IP address is contained in my little black box am I a
*lot* safer from external probes?

I practice safe browsing/email collection and use AVG and Sygate on each
workstation. I have been to grc.com and all ports including ICMP are
stealthed.

How much safer am I from hackers who want to poke a stick at my network now
that I am behind a NAT router?


Thanks

Paul




Paul H
  Reply With Quote
Old 01-06-2004, 11:44 PM   #2
David H. Lipman
 
Posts: n/a
Default Re: How secure am I behind a NAT router?
You'll be even safer if you block TCP/UDP ports 135 ~ 139 and 445 on your Router.

Dave



"Paul H" <> wrote in message
news:nkHKb.18778$...
| Just bought a NAT router..
|
| Now that my public IP address is contained in my little black box am I a
| *lot* safer from external probes?
|
| I practice safe browsing/email collection and use AVG and Sygate on each
| workstation. I have been to grc.com and all ports including ICMP are
| stealthed.
|
| How much safer am I from hackers who want to poke a stick at my network now
| that I am behind a NAT router?
|
|
| Thanks
|
| Paul
|
|




David H. Lipman
  Reply With Quote
Old 01-07-2004, 12:03 AM   #3
Rowdy Yates
 
Posts: n/a
Default Re: How secure am I behind a NAT router?
"Paul H" <> wrote in
news:nkHKb.18778$:

> Just bought a NAT router..
>
> Now that my public IP address is contained in my little black box am I
> a *lot* safer from external probes?
>
> I practice safe browsing/email collection and use AVG and Sygate on
> each workstation. I have been to grc.com and all ports including ICMP
> are stealthed.
>
> How much safer am I from hackers who want to poke a stick at my
> network now that I am behind a NAT router?
>
>
> Thanks
>
> Paul
>
>


you are safer and more private than if you did not have a NAT or AV or
software firewall in place.

i am no cisco guy, but your first comment about public address is a bit
confusing? the NAT hides your private addresses. you can assign what you
want for IP address to your boxes on the internal side of NAT (but you
should stick with private addressing scheme). the other end of NAT, that
is exposed to the outside world will contain your public address which you
can not hide - unless you spoof, that is. but why would you want to.

i guess my point is, people can still trace you back to what ISP you are
connecting from. a NAT won't change that.
--
Rowdy Yates
MCSE, Security+, Linux+
I am Against-TCPA
http://www.againsttcpa.com


Rowdy Yates
  Reply With Quote
Old 01-07-2004, 03:38 AM   #4
K2NNJ
 
Posts: n/a
Default Re: How secure am I behind a NAT router?
Any reason to install a software FW behind a router?

Bob
"Rowdy Yates" <> wrote in message
news:Xns9468C1E5CA9B8rowdyyatesnospamlyco@66.185.9 5.104...
> "Paul H" <> wrote in
> news:nkHKb.18778$:
>
> > Just bought a NAT router..
> >
> > Now that my public IP address is contained in my little black box am I
> > a *lot* safer from external probes?
> >
> > I practice safe browsing/email collection and use AVG and Sygate on
> > each workstation. I have been to grc.com and all ports including ICMP
> > are stealthed.
> >
> > How much safer am I from hackers who want to poke a stick at my
> > network now that I am behind a NAT router?
> >
> >
> > Thanks
> >
> > Paul
> >
> >

>
> you are safer and more private than if you did not have a NAT or AV or
> software firewall in place.
>
> i am no cisco guy, but your first comment about public address is a bit
> confusing? the NAT hides your private addresses. you can assign what you
> want for IP address to your boxes on the internal side of NAT (but you
> should stick with private addressing scheme). the other end of NAT, that
> is exposed to the outside world will contain your public address which you
> can not hide - unless you spoof, that is. but why would you want to.
>
> i guess my point is, people can still trace you back to what ISP you are
> connecting from. a NAT won't change that.
> --
> Rowdy Yates
> MCSE, Security+, Linux+
> I am Against-TCPA
> http://www.againsttcpa.com





K2NNJ
  Reply With Quote
Old 01-07-2004, 03:42 AM   #5
David H. Lipman
 
Posts: n/a
Default Re: How secure am I behind a NAT router?
Software that makes it into the enclave may make a "phone home" call. The software FireWall
will block it.

Dave



"K2NNJ" <> wrote in message
news:GaLKb.41478$ et...
| Any reason to install a software FW behind a router?
|
| Bob
| "Rowdy Yates" <> wrote in message
| news:Xns9468C1E5CA9B8rowdyyatesnospamlyco@66.185.9 5.104...
| > "Paul H" <> wrote in
| > news:nkHKb.18778$:
| >
| > > Just bought a NAT router..
| > >
| > > Now that my public IP address is contained in my little black box am I
| > > a *lot* safer from external probes?
| > >
| > > I practice safe browsing/email collection and use AVG and Sygate on
| > > each workstation. I have been to grc.com and all ports including ICMP
| > > are stealthed.
| > >
| > > How much safer am I from hackers who want to poke a stick at my
| > > network now that I am behind a NAT router?
| > >
| > >
| > > Thanks
| > >
| > > Paul
| > >
| > >
| >
| > you are safer and more private than if you did not have a NAT or AV or
| > software firewall in place.
| >
| > i am no cisco guy, but your first comment about public address is a bit
| > confusing? the NAT hides your private addresses. you can assign what you
| > want for IP address to your boxes on the internal side of NAT (but you
| > should stick with private addressing scheme). the other end of NAT, that
| > is exposed to the outside world will contain your public address which you
| > can not hide - unless you spoof, that is. but why would you want to.
| >
| > i guess my point is, people can still trace you back to what ISP you are
| > connecting from. a NAT won't change that.
| > --
| > Rowdy Yates
| > MCSE, Security+, Linux+
| > I am Against-TCPA
| > http://www.againsttcpa.com
|
|




David H. Lipman
  Reply With Quote
Old 01-07-2004, 06:05 AM   #6
Beachcomber
 
Posts: n/a
Default Re: How secure am I behind a NAT router?

>Software that makes it into the enclave may make a "phone home" call. The software FireWall
>will block it.
>
>Dave
>


Also, you may wish to familiarize yourself with the "netstat" command
which can actually show these connections in your machine "phoning
home" in real time.

From a command prompt, enter "netstat -ano" for a usage directory.
Don't type the quotes.

"netstat -a" gives details on what protocol, ports, and port status
are doing on your machine in real time.

To see connections on an ongoing basis, enter "netstat 3"
This sets a 3 second sample interval of what services your machine is
connecting to in real time. While observing this window, try opening
different browsers and your mail program. It can give you a better
sense of what is happening. Control C to cancel.

Beachcomber




Beachcomber
  Reply With Quote
Old 01-07-2004, 08:20 AM   #7
Jim Watt
 
Posts: n/a
Default Re: How secure am I behind a NAT router?
On Wed, 07 Jan 2004 06:05:00 GMT, (Beachcomber)
wrote:

>
>>Software that makes it into the enclave may make a "phone home" call. The software FireWall
>>will block it.
>>
>>Dave
>>

>
>Also, you may wish to familiarize yourself with the "netstat" command
>which can actually show these connections in your machine "phoning
>home" in real time.
>
>From a command prompt, enter "netstat -ano" for a usage directory.
>Don't type the quotes.
>
>"netstat -a" gives details on what protocol, ports, and port status
>are doing on your machine in real time.
>
>To see connections on an ongoing basis, enter "netstat 3"
>This sets a 3 second sample interval of what services your machine is
>connecting to in real time. While observing this window, try opening
>different browsers and your mail program. It can give you a better
>sense of what is happening. Control C to cancel.
>
>Beachcomber
>

Yeah but the advantage of a personal firewall is that it blocks it
automatically and you don't have to keep looking for problems.
--
Jim Watt http://www.gibnet.com


Jim Watt
  Reply With Quote
Old 01-07-2004, 11:02 AM   #8
David H. Lipman
 
Posts: n/a
Default Re: How secure am I behind a NAT router?
Actually you don't want to use netstat. It shows a static windows at that second.

You want TCPView.exe by http://www.sysinternals.com/

It is a dynamic viewer and on NT platforms it shows the program that opens the ports that
connects to the web site.

Dave



"Beachcomber" <> wrote in message
news:...
|
| >Software that makes it into the enclave may make a "phone home" call. The software
FireWall
| >will block it.
| >
| >Dave
| >
|
| Also, you may wish to familiarize yourself with the "netstat" command
| which can actually show these connections in your machine "phoning
| home" in real time.
|
| From a command prompt, enter "netstat -ano" for a usage directory.
| Don't type the quotes.
|
| "netstat -a" gives details on what protocol, ports, and port status
| are doing on your machine in real time.
|
| To see connections on an ongoing basis, enter "netstat 3"
| This sets a 3 second sample interval of what services your machine is
| connecting to in real time. While observing this window, try opening
| different browsers and your mail program. It can give you a better
| sense of what is happening. Control C to cancel.
|
| Beachcomber
|
|




David H. Lipman
  Reply With Quote
Old 01-08-2004, 12:36 AM   #9
Pete
 
Posts: n/a
Default Re: How secure am I behind a NAT router?

"David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
news:SGRKb.834$...
> Actually you don't want to use netstat. It shows a static windows at that

second.
>
> You want TCPView.exe by http://www.sysinternals.com/
>
> It is a dynamic viewer and on NT platforms it shows the program that opens

the ports that
> connects to the web site.
>
> Dave


TCPView is very good. Kerio Personal Firewall has almost exactly the same
kind of display by clicking on 'Firewall Status'.

http://www.kerio.com/dwn/kpf/kerio-pf-2.1.5-en-win.exe

Regards,

Pete.




Pete
  Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
router to router edwardsmichael Hardware 5 10-31-2009 10:51 PM
Problem Connecting Through Router Nobody404 General Help Related Topics 0 07-10-2007 11:28 PM
Adsl Router > Dual Wan Load Balancing Router > 24 port Switch Hub nazeth Hardware 0 03-28-2007 09:36 AM
Connecting dsl modem, switch and WiFi router RameshMeda Hardware 0 11-03-2006 01:58 PM
Server 2003 can't connect through wireless router Foghorn Leghorn Hardware 4 07-27-2006 04:55 AM




SEO by vBSEO 3.3.2 ©2009, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46