4 ms·
While technically true I think with Nat enabled it disables access from the Internet by default even if a firewall is misconfigured.
by Gee101 2y ago
While technically true I think with Nat enabled it disables access from the Internet by default even if a firewall is misconfigured.
- Arnavion 2y agoIf your firewall is disabled, an incoming v4 packet on the WAN interface with destination IP = a NAT'ed LAN device's address like 192.168.1.2 could cross over to the LAN interface and reach said LAN device. It is the firewall's job to filter such bogons.
- magicalhippo 2y agoHow would the package get routed my way unless the attacker hooked up right outside my network?
- Arnavion 2y agoYou've answered your own question.
- chgs 2y agoSuch a rare occurrence. Nat alone doesn’t protect you from 100% of threats. Neither does a firewall btw. But it does add an extra layer of safety.
- deleted 2y ago[deleted]
- mrshadowgoose 2y agoIn what realistic scenario would a regular individual need to worry about such a threat scenario?
- ffsm8 2y agoJust by sending the packet. That's essentially how NAT hole punching works. It doesn't work on all routers, but most do just route the packet. You just need to know the exact configuration of the network and send the correct packet through a valid port and it goes through https://en.m.wikipedia.org/wiki/Hole_punching_(networking) https://en.m.wikipedia.org/wiki/Hole_punching_(networking)
- dfawcus 2y agoHaving implemented a commercial hole punching mechanism, and having tested it on home and commercial deployments (various UK and USA ISPs), I have to agree. For most deployments (home and commercial) the NAT function (its session table) employs Endpoint Independent Mapping, and Endpoint Independent Filtering (see BEHAVE RFCs). As such once something behind the NAT (say at IP:Port) has connected to an external node, any external node can connect back to that internal IP:Port location by targeting packets at the public IP':Port' mapping. This applies even if the node behind the NAT was not expecting, nor desiring it. For home deployments, there is generally no additional firewall. For commercial deployments, there is usually a firewall working in an Endpoint Dependent Filtering manner (usually full 5-tuple, Port and Address Dependent Filtering). This additional firewall blocks off the unexpected connection allowed by the home scenario above, but still allows for hole punching if the behind NAT node(s) can coordinate punching via a third party to exchange their public mappings. Notably in the home deployment case, if the attacker is working with known public ports and addresses (i.e. itself being none NATted), then it can easily bypass the filtering logic of the home NAT once it learns of the existence of the 5-tuple public flow from the home NAT.
- indigo945 2y agoBut even if the attacker knows the 5-tuple (which is a big if), how would they send a package with the correct headers? Pretty much every ISP firewall will just drop your packages if you send them with a source IP that's not yours. Note that if you can fake source IP addresses, then a proper firewall won't protect anymore either, because all rules of the form "allow inbound connections from 1.2.3.4 only" are now broken.
- hanikesn 2y agoBut no package would ever make it back as none would be sent to the gateway and even then the gateway would send it to the local network.