Firewall Wizards mailing list archives

Re: Firewall blocking broadcasts in between NT Servers


From: roger nebel <roger () homecom com>
Date: Sun, 19 Jul 1998 12:32:23 -0400

Richard,

Thanks for the correction, I meant to write NetBIOS not NetBEUI...the
point is that most (all?) NAT'ing products can't handle MS
internetworking.  

cheers, roger

Richard Sharpe wrote:

At 09:18 PM 7/15/98 -0400, roger nebel <roger () homecom com> wrote:
Another possibility is that if the firewall you are using has Network
Address Translation (NAT) or even IP masquerading, and your MS boxes are
talking SMB over TCP/IP (NetBT), then the firewall can't translate the
NetBEUI addresses since most, if not all, firewalls don't know how to
open up the SMB headers to fix the NetBEUI addresses correctly according
to your NAT mappings.  Of course I'm assuming you have all the net
masks, gateways, and routes correctly set...

Ummm, this sounds a little confused. NetBEUI (NetBIOS Extended User Info)
is an ethernet only protocol, and as such is not routable and will not
carry IP addresses (except possibly in the final data area where they may
appear in SMB data as a result of IP addresses in files).

Since you also mention NetBT, what you may be referring to is WINS and
other Name lookup stuff that Microsoft Windows does, which definitely will
carry IP addresses that will need translation by the FW if NAT is in use
inside the network to be protected. NetBT is NetBIOS over TCP/IP, which
includes name lookup and SMB functions. An NetBT connection may result in a
redirect, which will contain an IP address that may need to be translated,
but all name lookup responses will need to be translated as well.


etc.



Current thread: