Firewall Wizards mailing list archives

RE: Stats on how common NAT is?


From: "Bill Royds" <broyds () rogers com>
Date: Sat, 14 Dec 2002 20:52:34 -0500

I would suggest is ubiquitous in corporate LANS. I work with a place that has its own class B and it still uses NAT 
between the Internet and internal network. We run the class B on the internal network because it was installed long 
before there was a need for firewalls other than ACLS. But the present firewall does a NAT on every connection between 
external Internet address and our class B address space. This does help in VPN but it wouldn't help using DCOM. DCOM 
should only be used on a LAN/private WAN anyway because of its insecurity, so it seldom causes much problems. port 135 
RFC calls are unlikely ever to be allowed past a firewall, so DCOM can't be used on the Internet anyway.
 
So even if the network can have its own Internet address space (not the private RFC1918 addresses), it is likely to NAT 
all addresses that go past the firewall.

-----Original Message-----
From: firewall-wizards-admin () honor icsalabs com
[mailto:firewall-wizards-admin () honor icsalabs com]On Behalf Of Michael
Still
Sent: Sat December 14 2002 18:36
To: fw-wiz
Subject: [fw-wiz] Stats on how common NAT is?



Hello.

I work as a software developer, and there has been some discussion at work
as to how common NAT is in corporate environments (this affects whether we
use DCOM or not).

Does anyone have any pointers on how common NAT in corporate environments
is? Why are these people using NAT, is it solely the expense of real IPs,
or is it also for the added security?

Thanks,
Mikal

-- 

Michael Still (mikal () stillhq com) | Stage 1: Steal underpants
http://www.stillhq.com            | Stage 2: ????
UTC + 11                          | Stage 3: Profit

_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards

_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


Current thread: