imabrowneye said:
Hi
I might be wrong (have been in the past), but I understood it that
NAT, isn't a true firewall. Doing tests with my adsl modem (Billion
5100 which has NAT), if i download GRC.com's leak test and run it I
fail every time, because NAT opens an incoming connection if
requested by an outgoing connection. If i want a port to be opened I
need to set the modem up to allow it (ie, port forwarding). When I do
the Shield's up test I pass, but my ports only show up as closed not
stealth (which doesn't worry me) To be truly secure with NAT, you
should still run a firewall which monitors outgoing connections (Ie:
Kerio, Zonealarm etc) so only the programs you allow, can access the
net
Please correct me if I'm wrong
JB
Your observations are right.
The biggest disadvantage is indeed that it wouldn't prevent TCP/IP
connections from the inside.
The advantage is the reduced need to adjust the firewall with each new
program that wants an internet connection.
But having a boxed ('hardware') nat firewall has additional advantages:
- Most Boxed NAT firewalls use a stripped, but very secure linux version on
flashrom. more difficult to bring sown as a software based firewall on your
PC
- I havn't seen a boxed firewall that wasn't network capable, meaning you
can _at least_ plug up to 253 additional network devices on your internet
connection, software on your PC will either only support 1 pc or will have
to youse that specific PC as an router, slowing down network traffice (and
your games er... work of course!)
- Most boxed firewall offer additional stuff. My old edimax can also be
used:
as a DHCP router (and I believe most boxed NAT firewalls can);
as a dns Pastrough service (the firewall will be handeling all DNS request
to the outside)
- Most boxed firewalls have aditional software for filters, making them
closer to the cisco and checkpoint firewall we'd all like to have
I've both an edimax router/firewall and an SMC route firewall. Though the
later has wireless support, I'd like the old edimax more. I've only had to
reset that firewall once (except some screwups in the settings I made myself
) while the SMC has to be resetted about once a month (mostly after an
attack of some form. But since I have the need of wireless, I'll stick to
the SMC for now.
MightyKitten
--
http://www.it-hulp.nl/
http://fotoalbum.it-hulp.nl/
gmx.net is the mailserver of mightykitten
start subject with *ping* or the antispam monster will eat it.