[47370] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: DDOS attacks and Large ISPs doing NAT?

daemon@ATHENA.MIT.EDU (Bradley Dunn)
Thu May 2 15:42:02 2002

Message-ID: <009101c1f211$4ad603b0$5801a8c0@LYSANDER>
From: "Bradley Dunn" <bradley@dunn.org>
To: "Mansey, Jon" <Jon_Mansey@verestar.com>
Cc: <nanog@merit.edu>
Date: Thu, 2 May 2002 15:40:57 -0400
MIME-Version: 1.0
Content-Type: text/plain;
	charset="Windows-1252"
Content-Transfer-Encoding: 7bit
Errors-To: owner-nanog-outgoing@merit.edu


> A NAT'd cell phone
> wont, cant ever, respond to an unsolicited connection request.

A NAT is not a firewall.

A firewall is not a NAT.

Some vendors bundle firewall functionality with NAT functionality, just as
some vendors bundle SNA with IP.

Please stop perpetuating the myth that a NAT is a security device.

Bradley


home help back first fref pref prev next nref lref last post