Re: Double NAT Question

From: Matt Gibson (mattg_at_blueedgetech.ca)
Date: 03/16/05


Date: Wed, 16 Mar 2005 09:05:01 -0800

Your setup is perfectly fine, I've got similar setups running at most of my
clients.

Yes, it provides an extra layer of security, in that you have to open up a
port in both firewalls to let something in, and you're less likely to make a
mistake in both. It's less secure in that you have two firewalls to keep
track of, and maintain.

There's no way this slows down network traffic for a network of SBS size.

Matt Gibson - GSEC

"Techieluvr" <nkim@ccef.org> wrote in message
news:1110992461.157265.294110@z14g2000cwz.googlegroups.com...
> All-
>
> Running SBS2K, two nics, and Netopia 4522 router over T1.
>
> My router is doing NAT and so is ISA. Until today, I thought a double
> NAT setup was a bad thing but a quick perusal through some of the
> threads on this topic indicates otherwise. I'm understanding that
> double NAT provides an extra layer of security. Am I correct?
>
> I was going to stop the router from doing NAT and let ISA do it because
> I find network slow (i.e., web browsing). My thinking is that double
> NAT slows network. However, I'm not so sure that I'm willing to trade
> the extra layer of security that double NAT provides for faster
> browsing.
>
> I'd welcome any response on the above remarks and whether I'm right or
> wrong in my understanding.
>
> Thanks.
>
> Techieluvr
>



Relevant Pages

  • Re: Probes on Port 135 and 445 continue
    ... >>all you have to do is request it, the default will be NAT. ... >>on public IP's, in fact, they had a firewall, but it was setup to pass ... It's not hard to justify costs most of the ... and monitor the IP/MAC relationship for security purposes. ...
    (comp.security.unix)
  • Re: Probes on Port 135 and 445 continue
    ... >>all you have to do is request it, the default will be NAT. ... >>on public IP's, in fact, they had a firewall, but it was setup to pass ... It's not hard to justify costs most of the ... and monitor the IP/MAC relationship for security purposes. ...
    (comp.security.misc)
  • Re: Systems behind NAT - port scanning etc.
    ... >security considerations section of the STUN document goes ... probably be filter-blocked on any firewall relying on NAT for security. ... >understand network architecture or network security). ...
    (comp.security.firewalls)
  • Re: Performance improvement for NAT in IPFIREWALL
    ... NAT is not a security feature. ... provides no better security than the packet-filtering firewall would alone. ... any network topology, which connects to the Internet, IMHO. ...
    (freebsd-net)
  • Re: Must I be forced to Upgrade from SBS 4.5?
    ... Just sometimes with security you need to be political, a NAT only customer ... "wrong" if no "industrial strength" firewall is not installed, ... The good thing about ISA is that it can be updated ...
    (microsoft.public.backoffice.smallbiz)

Loading