nanog mailing list archives

Re: Important IPv6 Policy Issue -- Your Input Requested


From: James <haesu () towardex com>
Date: Tue, 9 Nov 2004 15:24:50 -0500


On Wed, Nov 10, 2004 at 03:14:51AM -0500, Jerry Eyers wrote:
"Get a firewall" is not a valid response when you have lusers
to drop the latest netgear whatever onto their PC and dial
to some provider somewhere.  Your firewall is useless to 
protect that segment.  In many cases NAT is the ONLY
protection you end up with in this scenario, a scenario that
is far to common in the corporate world.

Jerry 

Then get a stateful firewall. NAT == stateful fw + header map/mod
done/done.

-J

-- 
James Jun                                            TowardEX Technologies, Inc.
Technical Lead                       IPv4 and Native IPv6 Colocation, Bandwidth,
james () towardex com             and Web Hosting Services in the Metro Boston area
cell: 1(978)-394-2867           web: http://www.towardex.com , noc: www.twdx.net


Current thread: