7 ms·
You simply can. NAT doesn't give any security whatsoever. Here's an unsolicited connection to an internal host over a router that's doing NAT: (192.168.0.101
by Dagger2 3y ago
You simply can. NAT doesn't give any security whatsoever. Here's an unsolicited connection to an internal host over a router that's doing NAT:
(192.168.0.101)$ echo "Hello from inside" | nc -vlp5000
Connection from [203.0.113.1] port 5000 [tcp/*] accepted (family 2, sport 36596)
(203.0.113.1)$ nc 192.168.0.101 5000
Hello from inside
And here's the 3-way handshake captured on the router:
wan0 In IP 203.0.113.1.36854 > 192.168.0.101.5000: Flags [S]
lan0 Out IP 203.0.113.1.36854 > 192.168.0.101.5000: Flags [S]
lan0 In IP 192.168.0.101.5000 > 203.0.113.1.36854: Flags [S.]
wan0 Out IP 192.168.0.101.5000 > 203.0.113.1.36854: Flags [S.]
wan0 In IP 203.0.113.1.36854 > 192.168.0.101.5000: Flags [.]
lan0 Out IP 203.0.113.1.36854 > 192.168.0.101.5000: Flags [.]
See? It works just fine. Here's the other direction, just in case you think I wasn't NATing:
lan0 In IP 192.168.0.101.44682 > 203.0.113.1.5000: Flags [S]
wan0 Out IP 203.0.113.58.44682 > 203.0.113.1.5000: Flags [S]
(If you want to see any aspect of the config, just ask. Give me commands to run if you want.)
- cyberax 3y agoI can also deliberately misconfigure the router, connect directly to it's WAN port, and then pretend that it somehow validated my nonsense statement. This works ONLY if you control the ISP infrastructure, and the router is allowing inbound traffic to LAN. Mikrotik by default doesn't.
- justsomehnguy 3y agoLol, Mikrotik by default has an empty firewall ruleset with policy ACCEPT.
- Dagger2 3y agoThe fact that it works at all disproves your "you can't do it" claim. I didn't misconfigure the router here. Please ask for whatever config info would convince you of that. It's true that most router devices you buy (presumably including Mikrotik) do block inbound connections by default, but they do it with a firewall, not with NAT. The reason they need the firewall is because NAT doesn't do it.
- cyberax 3y agoYes, it is correct. You can't do it in practice, because it requires you to control the ISP. This automatically makes it a non-issue for pretty much all home and small office networks. Meanwhile, the DEFAULT state for IPv6 is being open to the world. > I didn't misconfigure the router here. Please ask for whatever config info would convince you of that. OK. How can I ping your address? It should be easy, right? I'll even give you my IP: 208.52.76.162 , what do I need to set up to be able to ping all your internal hosts? Let's make that experiment.
- greyface- 3y agoHi, Condointernet/WaveG/Astound user. I've used their network before, and from experience, they put you on the same L2 segment as your neighbors. There's ARP/DHCP/etc filtering in place on the switch to prevent most kinds of shenanigans, but your neighbors can still send packets with a RFC1918 dst IP to your Ethernet address. To ping your internal hosts, I'd need to gain access to your building or one sharing the same L2 segment ("dfsea"?), then configure a static route for 10/8 / 192.168/16 / etc pointing at you. I would not need any control over the ISP.
- cyberax 3y agoI'm on a business line, and the L2 Ethernet segment consists of 1 device, their router. And most of Wave users (or any broadband users in the US, for that matter) use DOCSIS, which does not have a shared L2.
- 3y ago