cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
348
Views
0
Helpful
4
Replies

Security of NAT global ip to internal LAN ip?

huytuan
Level 1
Level 1

How safe/good is NAT global static ip to an internal LAN ip? How does this hide/protect from hackers and port probers finding the true ip address of the network. Any documents on NAT security for networks would be grateful.

4 Replies 4

lwierenga
Level 1
Level 1

Will this server be accessible from the outside/public network? If so, not advisible. If this answers your question please rate and close. Thanks.

Hi,

Iwierenga is right. NAT is as insecure as having the actual IP. The only thing that makes it secure is blocking access to unwanted ports/IPs/traffic

Thanks

Nadeem

How can things be made more secure??? Without costing too much??

lwierenga
Level 1
Level 1

Security is a business of diligence, and the first thing to understand is that the best security practices are to keep all systems and networking devices patched, and only allow that traffic that is absolutly neccessary into your DMZ. Also, learn to read a lot of logs, and learn to understand the difference between reconnaissance, compromise attempts, and false positives.

With regards to costs to your business? Think of it this way, what if your network was compromised...how much would it cost your business? I get an average of 6000 hits a day of offending traffic, thats slight compared to financial institutions.

Anyway, there are many products that are free that will help your business in staying secure. With regards to NAT, NAT is just one component to secure your network, NAT works to hide your DMZ (or sometimes internal network...bad idea) private IP addressing from the outside. The normal security model is to have Internet/perimeter router that connects to a firewall's outside interface, and the firewall's inside interface then connects to security switch that you would VLAN to seperate your DMZ/'s. This is the simple model, and get much more complex and costly. It would be my recommendation to have this model as a minumum.

With regards to securing routers and servers a good start is to go here:

National Security Agency

Security Recommendation Guides

http://nsa2.www.conxion.com/

A good freeby IDS is of course Snort for nix, go here:

http://www.snort.org/

Win32 version of Snort is here:

http://www.datanerds.net/~mike/snort.html

A good place to start understanding security is SANS:

http://www.sans.org/resources/

And finally a good place to start to unbderstand NAT:

http://www.ietf.org/rfc/rfc1631.txt?number=1631

Hopefully, this will help you. If this answer your questions please close and rate.