6 ms·
It is a substitute to an actual firewall because I don't need a firewall since NAT makes all of my listening ports unavailable to my WAN.
by lzaaz 4y ago
It is a substitute to an actual firewall because I don't need a firewall since NAT makes all of my listening ports unavailable to my WAN.
- noipv6 4y agothose of us who want to have the same port on different computers available to the internet might see that as a bad thing
- staringback 4y agoOh you don't need a firewall then? I guess accessing a routers web interface from the WAN is a-okay
- jraph 4y agoMy shitty cable modem which is also a router does not expose its web interface to the world by default. I don't understand why you'd need a firewall if - you trust devices on your network (yes, big if, but even then: the only reachable ports of a machine from the outside are those explicitly open to the outside, most stuff listens to 127.0.0.1 anyway) - you only configure your NAT to forward ports you would open on your firewall
- staringback 4y ago
- jraph 4y agoWhat's with the attacks?? I make sure what I build supports IPv6 (and I'll use tunnels if it's what it takes) but I can't make the only cable ISP available at my place support IPv6. I wish it did. I wish I didn't have to use its garbage hardware.
- sph 4y agoMy shitty router also firewalls incoming IPv6 connections by default, unless I manually allow them per-device, so I don't get your point.
- jraph 4y agoMy point is lzaaz's one https://news.ycombinator.com/item?id=33897568 https://news.ycombinator.com/item?id=33897568 I didn't think of my cable modem as a firewall. Maybe technically it has one to provide the feature of blocking access to its web interface from the world, or maybe it just listens to the right network. I don't know, but for all intent and purposes, setting up a firewall myself does not seem necessary. To be fair, I was also a bit annoyed by staringback's phrasing.
- lzaaz 4y agoMy router's httpd listens on the LAN not the WAN unless I tell it to. This is unrelated to what I said.
- vel0city 4y agoDepending on the NAT implementation this can be incredibly naive. Many home routers will send ANY traffic incoming on a port to the NAT'd IP address, even if the sources don't line up. So say Alice is behind a crappy NAT and wants to talk to Bob. Alice's router opens a port on its edge, lets say 1234, and sends traffic to Bob on port 80. Let's say Charles knows Alice's IP address. Charles starts spamming Alice's router, eventually hitting port 1234 with bad data. Alice's router is dumb. It sees traffic on port 1234, checks its NAT table, and sees that data is supposed to go to Alice. It happily rewrites that packet and passes it along to Alice. Now Alice is getting traffic from Bob *and* Charles. Uh oh! Many game consoles are explicitly designed around this bad, broken behavior. You'll open a port to the matchmaking server and then the matchmaking server will tell people to connect to that IP address and port combination. Crappy home routers will happily route that data through its NAT configuration to the console despite the console never explicitly opening up traffic to those other parties. This is why some game consoles will complain about closed NAT versus open NAT.
- lzaaz 4y agoThat's like saying that a bad firewall implementation leaks like a sieve. This is not what I was talking about.
- lazide 4y agoAny router running a poor NAT implementation (aka most of them) essentially has a built in firewall bypass for the right attacker. A naive NAT implementation can allow an attacker to bypass the firewall.
- jraph 4y agoCurious, could you expand on this?
- vel0city 4y agoI gave an example just a few comments above this. Alice never wanted Charles' traffic, the firewall should not have let it through. But because the NAT is dumb, and the firewall rules are often tied to the NAT on these crappy home routers, it's allowed. So now because Alice wanted to talk to Bob, she opened a port to the world that she never wanted opened as wide.
- Dagger2 4y agoThis is straight up untrue. The only thing NAT does is change the apparent source address of outbound connections. Inbound connections aren't outbound connections, so it does nothing to them. NAT is not a substitute for a firewall.