OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
NFR Wizards Archive: Re: Say it ain't so

Re: Say it ain't so


Paul D. Robertson (probertsclark.net)
Fri, 19 Sep 1997 10:18:36 -0400 (EDT)


On Thu, 18 Sep 1997, Rick Murphy wrote:

> Possibly. If you're using somebody else's IP addresses on your network, you
> need a firewall that supports NAT to avoid readdressing. Otherwise, there's

You don't _need_ NAT, a proxy based firewall will work without
re-addressing. You'll not be able to reach the legitimate owners of the
netblock you're using, without a NAT system that supports routing based on
the interface a packet arrived on combined with source and destination
address, and which bi-directionally NATs the packets in and out from that
network though. NAT itself doesn't necessarily provide that solution
without per-interface and independent source/destination address translation.

Paul
-----------------------------------------------------------------------------
Paul D. Robertson "My statements in this message are personal opinions
probertsclark.net which may have no basis whatsoever in fact."
                                                                     PSB#9280



This archive was generated by hypermail 2.0b3 on Sat Jul 17 1999 - 07:08:58 CDT