Re: [Security-Discuss] NAT/SSH Tunneling Alternatives
Steve <[email protected]>
| Newsgroups | gmane.linux.mandrake.security.general |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
On Thursday 10 June 2004 06:10 pm, Danny wrote:
> Hey All,
> I'm doing a science project on securing an insecure windows network,
> without doing any changes to the windows machines themselves, aside from
> altering DNS search order, proxy config, etc. But the problem I have run
> into, is:
> NAT is too insecure, any good hacker seems to be able to get past it
> quite quickly, so I need an alternative to it.
No, a Poor firewall is easily penetrated. Has nothing to do with NAT.
They way it's done is by spoofing the IP to be one of the internal ones.
You install OpenBSD and it will not get hacked*. In over seven years they have
only had one root hole on a default install. Each line in the O/S is audited.
True you could mess it up, but the point is it CAN be a really good firewall
it not messed up. It's as good as any commercial firewall, often much better.
So a firewall should have ZERO services running on it. Why? Because any hole
in any service (program) can let someone in and then...
OpenBSD is installed in 15 minutes. By default it will not let anything IN.
You spend 15min - 2hrs configuring the rules depending on you. Good examples
are on the web site. The computer needs to be at least a 486 and have 48MB
RAM and of course two NICs. That can handle your cable connection.
DHCP is a bad idea. Especially for a few computers. The only good place for it
is with an ISP with random people connecting up. It's just another thing that
must be configured and maintained. Why not just give each machine it's own
IP? Now if you see a packet on the network you know who it belongs to without
having to track down which machine is now using it.
Also with static IP's you can configure the firewall easily for what services
you want to allow for each one. As far as maintaining it I can easily support
200 computers this way without much headache. You usually only configure a
computer once anyway.
If you really don't want the two windows boxes to talk to each other use one
NIC for each. I don't see why but that's not my problem. You Can have a
print, DNS and samba server on OpenBSD, but as I said it really should not be
there.
*Taking in mind that the only secure computer is one that has no connections
and is not turned on, while not having any data on it in the first place. Any
other condition can and has been used to penetrate a box.
> SSH Tunneling requires _way_ to much client side configuration, and
> can't forward UDP traffic (as far as I know...).
> So, what can one use for this? The linux box is acting as a gateway for
> the windows network, it runs a DNS server, DHCP server, samba server,
> and a few other utilities. It has 2 NICs and a third cannot be added.
> I would prefer that the windows machines not be able to talk to each
> other, as all file/print sharing will be done by the linux box.
> Thanks!
> Danny
- --
Steve
"They that would give up essential liberty for temporary safety deserve
neither liberty nor safety."
Benjamin Franklin
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)
iD8DBQFAyTkaljK16xgETzkRAmk0AKCaktgEe6WKY+4dH2kaBmjiWEY+gQCgxXHZ
5ApaD+g1ihhKJE/BqXG+PuM=
=zLM/
-----END PGP SIGNATURE-----
message.footer
(text/plain, 239 B)
____________________________________________________ Want to buy your Pack or Services from MandrakeSoft? Go to http://www.mandrakestore.com Join the Club : http://www.mandrakeclub.com ____________________________________________________