Re: NAT with IP Filters

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance




Phillip Windell wrote:

"Jerome Baum" <gratemyl@xxxxxxxxx> wrote in message
news:1167410837.115945.186740@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
I just noticed that the "NAT Session Mappings" table shows nothing
about the made connections - is it supposed to? (these are outwards
connections which I mean, from a private interface).

I think that is only for inbound connections (Static NAT aka, Reverse NAT).
Nothing

I don't know what to tell you about the RDP. I think without a real
firewall product beng in use it is going to be "all or nothing". I think
your only option is to control *who* can connect based on their user account
and not be concerned with where they came from.

That policy is already in place. My plan is that everybody who is
connected via the VPN (i.e. any of the internal interfaces) can connect
via NAT to the outside world, but the outside world can only access
certain ports on the router. The problem is that I cannot set the
inbound filters to allow only certain ports without blocking the
internal interfaces off for outbound connections.

Thx again


--
Phillip Windell [MCP, MVP, CCNA]
www.wandtv.com

The views expressed are my own (as annoying as they are), and not those of
my employer or anyone else associated with me.
-----------------------------------------------------

.



Relevant Pages

  • Re: Routing question
    ... using netgraph to balance between network interfaces. ... NAT C & D to their respective "public" interfaces. ... > C & D are connections for 2 differnet client networks. ...
    (freebsd-questions)
  • Re: Max open connections
    ... So large number of connections are ... If you are running MLdonkey be sure to connect to the management interface: ... the simplest one is telnet (telnet ... more elaborate Graphical Interfaces (see the GUIs available on your ...
    (Fedora)
  • Re: The RCA connector is living proof
    ... While unbalanced interfaces don't necessarily cause problems, ... not as resistant to causing problems as balanced connections. ... unbalanced is sub-sub-sub standard. ...
    (rec.audio.opinion)
  • Re: redundancy on multi-homed hosts for outgoing mail
    ... automatically retries out the other with the other source address? ... I don't think this is a routing issue. ... The two interfaces have ... single address space with two Internet connections. ...
    (comp.mail.sendmail)
  • Re: iscsi multipath fails when cluster service is started
    ... Sorry if I missed this previously, are your iSCSI network connections on the ... If the iSCSI connections are not on the same subnet as your other cluster ... i think the problem is that the interfaces are in the same subnet. ...
    (microsoft.public.windows.server.clustering)