Security benefits of hardware firewalls
Hi there.
I have been taught that the average consumer-grade IP NAT-capable wired router is (for residential end users, SOHO users, or really anyone who does NOT need to explicitly open ports in their Internet gateway device or run a DMZ) an execellent protection against both network worms and malicious crackers or script kiddies. Specifically, I have been told that by the nature of the form of IP NAT used by consumer/home user routers, all unsolicited inbound network traffic is simply discarded, thereby protecting all users on the network from UNSOLICITED attacks. Obviously, that would still leave you vulnerable to any malicious traffic that you personally allow to enter your PC, such as foolishly downloading malware-infected programs.
So my questions are as follows: is it true that all unsolicited network traffic that attempts to pass through a consumer/home user grade wired NAT router (assuming the necessary configurations are properly made, of course) is dropped? If so, is it possible for some manner of attack to fool the NAT router (without the user's knowledge or intervention) into thinking that some malicious unsolicited traffic was solicited? And if so, are there any known exploits that exist in the wild? Don't forget that I'm asking about wired-only routers here, no WIFI.
Thanks in advance for your time and help.
read more and respond »Posted 5 years ago by Sol in Networking Firewalls