Firewall Stealth Mode?

Mar 11, 2006 54 Replies

In article , you say...

Lets just make this simple for the world:

1) I've claimed that I've seen MANY systems protected for a LONG TIME by NAT appliances and even Personal Firewall solutions. 2) I've stated that I trust a NAT Appliance over the PFW or Windows Firewall for most home user solutions. 3) I've stated that I've seen a non-technical, typical home user computer, were the user ran as a local admin, protected by ZAP for more than a year with no detectable malware on their machine.

A) You claim that NAT Appliances don't offer protection

B) You claim that PFW solutions don't offer protection

C) You have shown some examples where unknown NAT devices have been proven to be exploitable for specific cases

D) You claim to have tested NAT solutions and that they don't protect users/networks

E) You can't provide any data on vendor, part number, firmware, test, result for any of the devices that have failed since you say you don't track ones that have failed.

So, if I said I was using NAT Appliance XYZ, Firmware PDQ, you could not with any hope, tell me that the device has or doesn't have exploits.

There are masses of others, like me, that have found the protection that NAT Appliances offer, still have uncompromised networks and systems, and use them every day for business and home use....

I personally use a Firewall Appliance, not to be confused with a NAT Appliance, to protect my home and my business, along with very strict settings on stations, in order to protect my home and my office. Never had a compromised system at home or in my office, never had a client compromised....

Which I don't believe you, as such systems are rare.

And still didn't tell any serious reason.

Just as above, such cases are rare.

I claimed that any protection offered by NAT Appliances is pretty unreliable, partitially coincidencal and rarely needed at all.

As above, but just worse. PFWs do make a safe computer vulnerable in first place.

And claimed that this is usually the case, which I think is clear to almost any reasonably thinking, technically experienced person.

reliably, the way you claimed protection.

I named you some. But I can easily catch up by recording in future, catching documentation from peers, ...

Educational guess: It does have exploits.

I've become pretty resistant to such stupidity and ignorance. I really don't want to know what is actually going on there without your knowledge.

And I claim that you're not even able to estimate this correctly. And that, even if it was actually as good as it looks, it would be a total overkill, unreliable and and sometimes disturbing.

Not in any of the solutions I've sen, not one.

Because of what I've personally seen, including #1 above.

Such cases are very common, and as I travel all over the US, it seems to be common where I visit.

Except that I don't see any basis for your claims.

Again, I don't see that to be the case in any of the solutions I've had experience with.

How can it be "Usual" without any proof? How can you make an assumption without testing and results that are documented?

Except that I've listed solutions that work and you've listed nothing specific that doesn't work.

And nothing main-stream, that any typical user might experience, even in a business.

A guess is like an ASSumption.

It seems to be a common thing for you - you don't want to know anything with details, like what products failed vs what ones passed.

Strange, "overkill"? having a usable and fully protected network is overkill? What complete and utter BS. What's disturbing about a secure network?

Only the NAT implementations, Sebastion. Many filtering implementations on such boxes are OK, I bet.

Yours, VB.

IMHO You two obviously have some past life karma you need to resolve. Interesting that you should choose firewalls as the venue. Best wishes.

Hint: Stop trying to prove the other person wrong. Neither of you is wrong--or right. Look for a different approach. You'll find it if you are sincere.

Walterius, Old, and may have just incurred some karma of my own, in Fort Lauderdale

Then you're not getting around so much or just getting the better managed/more sane clients.

OMN! May I cite from RFC 2993:

| NAT (particularly NAPT) actually has the potential to lower overall | security because it creates the illusion of a security barrier, but | does so without the managed intent of a firewall. Appropriate | security mechanisms are implemented in the end host, without reliance | on assumptions about routing hacks, firewall filters, or missing NAT | translations, which may change over time to enable a service to a | neighboring host. In general, defined security barriers assume that | any threats are external, leading to practices that make internal | breaches much easier.

NAT is not supposed to be a security measure and the real world implementations do support this view even more.

Hello world? So far there is no Personal Firewall that does not have any known critical security vulnerabilities.

The contrary dominates the real world.

Neither is it fully protected nor does implementing useless security feature add any security.

That you're claiming such without any reasonable concept?

OK, but pretty unusable. One usually cannot even reference the TCP or NAT states, TCP flags, IP options, ICMP codes and alike. Not even a "me" keyword for the router's public IP address is available

And (usually) just 20 to 30 rules? I already need 40 for egress filtering (range, broadcast, IANA reserved).

It's usually written ASS U ME :-)

Don't think so. My ASUS box here is driving Linux with netfilter, for example.

Yours, VB.

But this Linux is not factory default, is it? How much did it cost?

It is.

ASUS W500g. Round about 80,- EUR IIRC.

Yours, VB.

There is nothing to prove wrong, he's made a claim without any facts to back it up.

Well we all know how assume breaks down now don't we. Perhaps you could have at least troubled yourself to point them to that RFC in your first post?

Jason

Well, at least he should know the RFCs at all. You know, there are certain five RFCs that every system has to follow if you want to connect it to the internet, anyway else the ICANN can expel you - he should have read them and checked his system.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required