Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #247886

Re: Networking book recommendation

From Jeremy Ardley <jeremy@ardley.org>
Newsgroups linux.debian.user
Subject Re: Networking book recommendation
Date 2022-05-04 08:00 +0200
Message-ID <Ejgdj-d5U6-5@gated-at.bofh.it> (permalink)
References <Ej6GZ-cZwJ-3@gated-at.bofh.it> <Ej7a1-d01z-1@gated-at.bofh.it> <Ej7jH-d04N-5@gated-at.bofh.it> <Ejfhf-d5eH-1@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


[Multipart message — attachments visible in raw view] - view raw

On 4/5/22 12:57 pm, tomas@tuxteam.de wrote:
> On Wed, May 04, 2022 at 04:27:52AM +0800, Jeremy Ardley wrote:
>
> [...]
>
>> [...] NAT in itself
>> provides quite good security because internal hosts can't be scanned by
>> attackers.
> Uh, oh. I think general opinion these days disagree with this
> statement strongly (see e.g. [1], but this has been rough
> consensus since at least the 2000s).

Your consensus is 20 years old. Times move

Natural evolution has developed standard features in routers that out of 
the box are 'good enough' for SOHO implementations.

That is when you plug it in and connect to your home LAN you can 
reasonably expect your LAN won't be compromised in 5 minutes or even 5 
years of persistent attacks.

The only problem is when the enthusiastic owner starts opening ports to 
allow internal mail or web, or even just to run some games. This problem 
will also occur when you have the latest fancy dandy firewall. It is 
users who are insecure, not NAT or routers as such.

More interesting is IPv6 which many ISPs now offer. Modern routers know 
about Prefix delegation and all your windows hosts will automatically 
pick up IPv6 Addresses. These are 'raw' on the internet, no NAT 
involved. It will depend on your router firewall on how well protected 
you are.

In the IPv6 case, modern Windows machines all have inbuilt firewalls 
that work reasonably well. Linux systems are variable in firewall 
configuration and may not be as well protected.

I run my own Armbian dual homed router that does the IPv6 stuff and I 
have a reasonable set of ip6tables rules to allow specific hosts to 
provide IPv6 services on well known addresses (ie in DNS) but at the 
same time protect most other hosts from any unsolicited IPv6 Traffic.

If I was still in the 90s I'd set up a DMZ blah blah. Now I just expose 
services on the router using HA proxy for IPv4 Stuff and specific rules 
for IPv6. I also run a postfix instance on the router for IPv4 connectivity.


Jeremy

Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

Networking book recommendation Tom Browder <tom.browder@gmail.com> - 2022-05-03 21:50 +0200
  Re: Networking book recommendation john doe <johndoe65534@mail.com> - 2022-05-03 22:20 +0200
    Re: Networking book recommendation Jeremy Ardley <jeremy@ardley.org> - 2022-05-03 22:30 +0200
      Re: Networking book recommendation <tomas@tuxteam.de> - 2022-05-04 07:00 +0200
        Re: Networking book recommendation Jeremy Ardley <jeremy@ardley.org> - 2022-05-04 08:00 +0200
    Re: Networking book recommendation Tom Browder <tom.browder@gmail.com> - 2022-05-03 22:40 +0200
      Re: Networking book recommendation Dan Ritter <dsr@randomstring.org> - 2022-05-03 23:10 +0200
      Re: Networking book recommendation john doe <johndoe65534@mail.com> - 2022-05-04 18:10 +0200
        Re: Networking book recommendation Tom Browder <tom.browder@gmail.com> - 2022-05-05 16:40 +0200
          Re: Networking book recommendation john doe <johndoe65534@mail.com> - 2022-05-05 21:40 +0200
            Re: Networking book recommendation David Christensen <dpchrist@holgerdanske.com> - 2022-05-05 23:10 +0200
              Re: Networking book recommendation Tom Browder <tom.browder@gmail.com> - 2022-05-06 00:40 +0200
                Re: Networking book recommendation Celejar <celejar@gmail.com> - 2022-05-06 03:50 +0200
                Re: Networking book recommendation Dan Ritter <dsr@randomstring.org> - 2022-05-06 04:00 +0200
                Re: Networking book recommendation john doe <johndoe65534@mail.com> - 2022-05-06 09:00 +0200
          Re: Networking book recommendation David Christensen <dpchrist@holgerdanske.com> - 2022-05-05 22:50 +0200
  Re: Networking book recommendation Charles Curley <charlescurley@charlescurley.com> - 2022-05-03 22:40 +0200
    Re: Networking book recommendation Tixy <tixy@yxit.co.uk> - 2022-05-03 23:00 +0200
  Re: Networking book recommendation Dan Ritter <dsr@randomstring.org> - 2022-05-03 23:00 +0200
  Re: Networking book recommendation Tom Browder <tom.browder@gmail.com> - 2022-05-03 23:20 +0200
    Re: Networking book recommendation Greg Wooledge <greg@wooledge.org> - 2022-05-03 23:30 +0200
      Re: Networking book recommendation Tom Browder <tom.browder@gmail.com> - 2022-05-03 23:40 +0200
    Re: Networking book recommendation Bob Weber <bobrweber@gmail.com> - 2022-05-04 00:30 +0200
      Re: Networking book recommendation Tom Browder <tom.browder@gmail.com> - 2022-05-04 01:40 +0200
  Re: Networking book recommendation David Christensen <dpchrist@holgerdanske.com> - 2022-05-04 01:50 +0200
  Re: Networking book recommendation "Rick Thomas" <rick.thomas@pobox.com> - 2022-05-07 10:00 +0200

csiph-web