Raptor's good. Especially for NT. The internal non-legal address are fine
(that's one of the main purposes of NAT) and so are the external, since you will
have a router between the ISP and the firewall. The problem with using the NT
machine as a router is if the NT machine gets compromised (which is quite easy)
then your entire network could be compromised. If you still want to use it as a
router, I would set it up on its own domain or workgroup. That way if it does
get compromised, it would be harder for the attacker to compromise the internal
network. Also, make sure that the ruleset in your firewall is hardened because
some firewalls allow authenication and if the firewall is compromised then the
rest of your network is also.
"Dominique THIRY" <[EMAIL PROTECTED]> on 10/14/99 02:37:53 AM
To: Rob Walker/SV/AUS/HARCOURT@HARCOURT
cc:
Subject: Re: router with NT
I'm using Raptor V6 firewall.
It does NAT, but uses its external address wich is 192.168.1.1(non legal).
And the router will receive temporay legal address from my provider when it
connects.
-----Original Message-----
From: [EMAIL PROTECTED] <[EMAIL PROTECTED]>
To: Dominique THIRY <[EMAIL PROTECTED]>; [EMAIL PROTECTED]
<[EMAIL PROTECTED]>
Date: Thursday, October 14, 1999 12:28 AM
Subject: Re: router with NT
It is possible to use NT Workstation as a router. Just enable IP forwarding
and
set up your routing table.
What type of firewall are you using?
"Dominique THIRY" <[EMAIL PROTECTED]> on 10/13/99 09:36:27 AM
To: "FIREWALLS" <[EMAIL PROTECTED]>
cc: (bcc: Rob Walker/SV/AUS/HARCOURT)
Subject: router with NT
Maybe a simple question:
I have a NT box running NT4.0 workstation.
IP forwarding is enabled on it.
I have installed an NIC and an ISDN card (to connect to my Internet
provider).
Is it possible to use that NT box as a router between my firewall and the
Internet ?
May need additionnal software ?
Thanks,
Dominique THIRY
Systemat Luxembourg
|
I'm using Raptor V6 firewall.
It does NAT, but uses its external address wich
is 192.168.1.1(non legal).
And the router will receive
temporay legal address from my provider when it connects.
|
