Re: NAT with IP Filters



I just noticed that the "NAT Session Mappings" table shows nothing
about the made connections - is it supposed to? (these are outwards
connections which I mean, from a private interface).

Thanks!

Jerome Baum wrote:

inline

Phillip Windell wrote:

If the connection is NATed, then you have a firewall already. NAT does not
allow anything inbound, ever,...unless you go out of your way to configure
Static NAT (inbound) connection on purpose. You don't have to actively
"block" what isn't going to happen in the first place. It does not mean
you have disabled the firewall if you aren't filtering specific ports. But
on the outbound direction NAT lets it all flow unless you "overcome" that
with outbound filtering.

I was not clear with what I meant. The NAT server itself runs services
such as IIS and those. I need ports such as 3389 for RDP open since I
have no local KVM. The point is, I would like to block all connections
but those established by clients on the virtual interfaces (there are
more than just that one) and those to specific ports (e.g. 3389, 80,
443).

Of course, I could ensure that no programs are listening on the public
interface, but this is far more tedious than simply telling the routing
service to only allow certain ports to be connected to.

The point is, the "firewall" (inbound filters) of the routing service
are fine except that they don't allow outgoing connections via e.g. TCP
from the internal interfaces.

Thanks again!


As far as OpenVPN,...never heard of it,..have no idea if it is a hardware
device or software or how you deployed it, or even if you deployed it
properly. So I can't really comment on that at this point.

OpenVPN: I have worked with it for quite a while and am sure that it is
configured correctly. I only mentioned it in case.


--
Phillip Windell [MCP, MVP, CCNA]
www.wandtv.com

The views expressed are my own (as annoying as they are), and not those of
my employer or anyone else associated with me.
-----------------------------------------------------



"Jerome Baum" <gratemyl@xxxxxxxxx> wrote in message
news:1167399034.934120.186350@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Hi!

I have a dedicated server on which I cannot install a custom firewall
(dedicated server, no KVM) and the windows firewall is disabled when
Routing and Remote Access is enabled.

So I use inbound filters instead of a firewall. But I have an interface
(OpenVPN) which is NAT'd. Those connected to this interface need access
to the Internet.

I have found that creating a rule to allow "Any" traffic (practically
disabling the firewall) will grant access to this interface.

I have a rule to allow all "TCP [established]" traffic, so I don't see
why I have to disable the entire firewall for that interface to gain
outward TCP access. I have no Outbound filters on the external
interface and no filters at all on the mentioned internal interface.

I would be thankful for any help!

-jerome


.



Relevant Pages

  • Re: New to IPFW and would like critique...
    ... The firewall ... You log a *lot* of types of connections that aren't particularly ... > # Outside interface network and netmask and ip ... packet coming from a port 53 and going to, say, port 137. ...
    (comp.unix.bsd.freebsd.misc)
  • Re: NAT with IP Filters
    ... Static NAT (inbound) connection on purpose. ... you have disabled the firewall if you aren't filtering specific ports. ... interface, but this is far more tedious than simply telling the routing ... are fine except that they don't allow outgoing connections via e.g. TCP ...
    (microsoft.public.windows.server.networking)
  • Re: PPTP Routing Cisco 1841
    ... ip inspect name firewall tcp ... interface FastEthernet0/0 ... ip nat inside ... encapsulation aal5mux ppp dialer ...
    (comp.dcom.sys.cisco)
  • Re: IP Addressing
    ... firewall and router). ... On the firewall create a static NAT entry as I wrote ... !we 're doing NAT to publish my Exchange server on the Internet ... external or any physical / logical interface. ...
    (comp.dcom.sys.cisco)
  • Re: SP1 breakes VPN RRAS Server
    ... And it's like I wrote in the previous message: The VPN server doesn't accept any connection to the firewalled interface over any protocol, including a telnet session to this interface over PPTP port 2723 ... firewall" category, the server doesn't accept inbound connections anymore, ...
    (microsoft.public.windows.server.networking)