CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Is a router with a NAT firewall really doing much?

 
Post new topic   Reply to topic       All -> FavForums -> Firewalls [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
TopDog

Sergeant
Sergeant
Premium Member

Joined: Mar 23, 2003
Posts: 111
Location: USA
Premium

PostPosted: Wed Apr 30, 2003 3:36 am    Post subject: Is a router with a NAT firewall really doing much?
Reply with quote

I have to admit this firewall stuff overwhelms me. I run a NetGear RP114 with a NAT firewall and ZoneAlarmPro. Im running ZAP because Im told even a home computer that is on a shared high bandwidth cable connection should have layered security. So thats were Im at.

What I want to know is using a router with a NAT firewal worth the effort?

Now I used this tool http://reglos.de/myaddress/IPAddress.html from this post at computercops http://www.computercops.biz/t271-Reveal_Your_IP_not_so_smart_thinks_does_I.html

It told me what my public IP address was and the fact that I was on a router with a NAT firewall, then what the IP was to my desktop on the router. I assume through some java applet, like one that could be loaded from any visited web site.

I understand the most complete way to surf securely is to use an anonymous proxy server like Anonymizer.com. Even that had draw backs as the proxy server still has your IP.

Having said all that the question remains, what good is a router with a NAT firewall really?

Back to top
View users profile Send private message Visit posters website
Paul

CastleCops Founder


Joined: Feb 22, 2002
Posts: 27351

Administrators Firetrust Forums Admin MIRT Moderators MVP Phishing Squad Premium Team CC Committee

PostPosted: Wed Apr 30, 2003 6:06 pm    Post subject:
Reply with quote

Both are good because you are following a layering concept. The NAT router stops traffic from coming into your network. ZA stops traffic from leaving your PC without authorization.

Now you have to protect your browser with something like Proxomitron.


_________________
Paul Laudanski - http://www.laudanski.com
http://www.linkedin.com/pub/1/49a/17b
Back to top
View users profile Send private message Send email Visit posters website
IP: 65.29.*.*

Guest






PostPosted: Wed Apr 30, 2003 7:56 pm    Post subject:
Reply with quote

Paul isnt the router allowing traffic into my computer? As in the case of test I ran above it knew the IP of my desktop. Can anyone just put a java script on thier web site that will allow them access to your desktop?

Back to top
TopDog

Sergeant
Sergeant
Premium Member

Joined: Mar 23, 2003
Posts: 111
Location: USA
Premium

PostPosted: Wed Apr 30, 2003 7:58 pm    Post subject:
Reply with quote

Sorry I was not logged in, Im that guest above.

Back to top
View users profile Send private message Visit posters website
Paul

CastleCops Founder


Joined: Feb 22, 2002
Posts: 27351

Administrators Firetrust Forums Admin MIRT Moderators MVP Phishing Squad Premium Team CC Committee

PostPosted: Wed Apr 30, 2003 11:36 pm    Post subject:
Reply with quote

A router won't block javascript that you allow to access your computer. A router only allows traffic back to you that you have requested to be sent in. Hence, visiting a web site is such a request, the router will send back that page to you. Now what gets rendered on your browser is not controlled by a firewall, it is controlled by your privacy settings in your browser, or by the use of a proxy like Proxomitron.


_________________
Paul Laudanski - http://www.laudanski.com
http://www.linkedin.com/pub/1/49a/17b
Back to top
View users profile Send private message Send email Visit posters website
TopDog

Sergeant
Sergeant
Premium Member

Joined: Mar 23, 2003
Posts: 111
Location: USA
Premium

PostPosted: Thu May 01, 2003 1:16 am    Post subject:
Reply with quote

Ok so if I want to surf and be safe I need to go through a proxy server either:

Local on my machine like Proxomitron or through

Anonymizer.com or using a program like GostSurf.

I will download Proxomitron and use it. Thanks for your help.

Back to top
View users profile Send private message Visit posters website
Paul

CastleCops Founder


Joined: Feb 22, 2002
Posts: 27351

Administrators Firetrust Forums Admin MIRT Moderators MVP Phishing Squad Premium Team CC Committee

PostPosted: Thu May 01, 2003 6:50 pm    Post subject:
Reply with quote

My pleasure... you're in luck, the author hosts its forum here on site.


_________________
Paul Laudanski - http://www.laudanski.com
http://www.linkedin.com/pub/1/49a/17b
Back to top
View users profile Send private message Send email Visit posters website
IP: 65.29.*.*

Guest






PostPosted: Thu May 01, 2003 10:25 pm    Post subject:
Reply with quote

Kool, I love this forum. Im glad I joined.

Back to top
TopDog

Sergeant
Sergeant
Premium Member

Joined: Mar 23, 2003
Posts: 111
Location: USA
Premium

PostPosted: Thu May 01, 2003 10:30 pm    Post subject:
Reply with quote

Man, messed up again. Im that guest above. I keep forgetting to log in before I post. Do you think there is a chance that the site could check to see if your logged in before posting and give you the option to log in if you not?
You know a kind of failsafe for knuckle heads like me.

Back to top
View users profile Send private message Visit posters website
Paul

CastleCops Founder


Joined: Feb 22, 2002
Posts: 27351

Administrators Firetrust Forums Admin MIRT Moderators MVP Phishing Squad Premium Team CC Committee

PostPosted: Fri May 02, 2003 1:36 pm    Post subject:
Reply with quote

Maybe in future code, but for now we're in "stable" mode. Thankfully too because my day job has been pressing lately. You can just stay logged in and not log out.


_________________
Paul Laudanski - http://www.laudanski.com
http://www.linkedin.com/pub/1/49a/17b
Back to top
View users profile Send private message Send email Visit posters website
TopDog

Sergeant
Sergeant
Premium Member

Joined: Mar 23, 2003
Posts: 111
Location: USA
Premium

PostPosted: Fri May 02, 2003 5:45 pm    Post subject:
Reply with quote

Kool, that dosent stress the server? Embarassed

Back to top
View users profile Send private message Visit posters website
Paul

CastleCops Founder


Joined: Feb 22, 2002
Posts: 27351

Administrators Firetrust Forums Admin MIRT Moderators MVP Phishing Squad Premium Team CC Committee

PostPosted: Mon May 05, 2003 4:54 pm    Post subject:
Reply with quote

Nope, not at all.


_________________
Paul Laudanski - http://www.laudanski.com
http://www.linkedin.com/pub/1/49a/17b
Back to top
View users profile Send private message Send email Visit posters website
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Firewalls All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer