|
|||||||||||
|
Re: To NAT or not to NAT
From: Aaron Cheek <aaron_cheek(at)yahoo.com>
Date: Fri Jan 10 2003 - 08:40:33 EST
NAT is not good nor it's bad. It depends on your needs and how you use it. It's true that NAT can be a pita in some situations (like creating VPNs), that's why you should carefully study your current and possible future needs. You must also think of your security requirements. Are all your machines equally important? Are some of them more critical than others? Are some machines more exposed and running more dangerous services than others? Are some hosts supposed to not need internet access at all? If so, use all your resources to create different "security zones", separated by firewalls/routers as necessary. Don't allow any traffic between them if it's not required. For that purpose you can subnet your external network or use NAT and introduce new subnets, whatever suits you best. NAT can provide some extra security against misconfigurations, and may hide that you are running a bigger network (maybe making it less attractive to attackers)... However, it's true, as some others pointed out, that it does not provide anything that a good firewall configuration wouldn't.
Aaron
This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 13:32:20 EDT |
||||||||||
|
|||||||||||