NAT as Firewall

theCheetah

Member
Dec 13, 2000
128
0
0
I installed a router having NAT as a firewall, connecting to internet through cable modem. I am planning to open up port 21 of the router and run a personal ftp server. How safe am I? Do I need to run any special firewall software on my PCs?
 

Carceri

Member
Aug 7, 2001
119
0
0
You are mixing things up. NAT has nothing to do with firewalling. NAT is a technology used to have a local IP address on your private network and the router has one or more global IP adresses assigned to it. It then translates between those two. Also with a small modification you can use several computer behind just one global IP address.

A packet filtering firewall blocks data to certain ports.

What I'm guessing your setup is (at least the way I would set it up if I had to) would be to run NAT on your router and assign a private IP address to your PC (that is probably already the case). The router should not forward any packets to your PC unless they are a response from a server your PC contacted (the router will keep track of this).

Now, to use FTP you need the router to forward port 21 to your machine, that's all.

How safe are you: That depends on the FTP server. If you use a well tested server and keep track of security problems and apply patches you should be pretty safe, since the FTP server will be the only access point into your PC. I would still recommend installing some kind of application level firewall on your PC (such as Tiny Personal Firewall) to keep track of outgoing connections, since the router will just allow all traffic to go out. You should only allow the programs that you use to access the network.
 

pm

Elite Member Mobile Devices
Jan 25, 2000
7,419
22
81


<< You are mixing things up. NAT has nothing to do with firewalling. >>

Inexpensive router manufactures (Linksys, Dlink, etc.) have been advertising that NAT acts like a firewall which has led to confusion about what firewalls are. OTOH, NAT can be considered a form of firewall. To me a firewall is something that secures one network from access by another and NAT does this.
 

Carceri

Member
Aug 7, 2001
119
0
0


<< To me a firewall is something that secures one network from access by another and NAT does this. >>


Well, NAT can't do this alone, it needs to run on some device. That device could be (and normally is) a firewall and NAT is one of the tools the firewall can use to do it's job (just as it can filter packets, establish VPN connections, etc.)

But what people choose to call a firewall depends probably on what they are used to. I would not call my ADSL router a firewall, but merely a router with very limited packet filtering capabilities, but the SonicWALL we use at work is a real firewall IMHO
 

CTho9305

Elite Member
Jul 26, 2000
9,214
1
81
I use a p200mmx, win98se + ics. there is a 3rd party tool you can use to forward ports so you can run servers on the backend... search for "ics configuration" on google.
 

QTPie

Golden Member
Dec 30, 2001
1,813
1
81
Yes, you can implement NAT as firewall when you setup your private network behind the router. It's pretty safe.

Let's say your public IP is 64.36.153.48. Using your router with NAT enable, you can assign your PCs with IP 192.168.100.2 and 192.168.100.xxx (subnet mask= 255.255.255.0 and gateway= 64.36.153.48) Then all your PCs are not visible from the outside. Therefore, ppl cannot access to your PCs.
But if you want to setup your FTP server, you can only access to it from the outside of your network when you assign it your public IP address (from ISP, 64.36.153.48 in this case). I use Serv-U FTP server. It's free for 45 days. and you can set all access rights to your files (you might want to set it as read-only)
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |