OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Mike Shaw (mshawwwisp.com)
Date: Fri Jan 11 2002 - 14:06:39 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    If it's a true firewall (not a simple natbox), it should have a rule
    preventing traffic with inside origination IP from entering the outside
    interface. Either that or it should be built into the functionality.

    -Mike

    >He claimed that firewalls using NAT are inherently insecure, because someone
    >with enough technical know-how can "trick" it into passing packets back and
    >forth bi-directionally, thereby making it "transparent" and letting the
    >hacker through to any system behind it.