|
Why
would you want to use NAT on DMZ devices?
If you
are running NT and you stop the firewall services (or they crash for
instance),
then
it will route all packets to those DMZ servers regardless of rulebase
etc.
(obviously, the fw-1 service is not controlling packets and the OS is
acting as a
dumb
router.)
If you
NAT the DMZ legs, then in the case of your firewall services failing
they
will
not be vulnerable.
I
haven't really seen any performance problems at all.
FW-1
seems amazingly efficient for what it does.
|
- [FW1] Opinon Requested - to NAT or not to NAT DMZ Address... Brian Burns
- Re: [FW1] Opinon Requested - to NAT or not to NAT DM... CryptoTech
- Re: [FW1] Opinon Requested - to NAT or not to NA... Carl E. Mankinen
- Re: [FW1] Opinon Requested - to NAT or not t... Brian Burns
- Re: [FW1] Opinon Requested - to NAT or n... Jason Witty
- RE: [FW1] Opinon Requested - to NAT or not to NAT DM... Frank Darden
- RE: [FW1] Opinon Requested - to NAT or not to NAT DM... Ian Campbell
- RE: [FW1] Opinon Requested - to NAT or not to NAT DM... Jason Kent
- RE: [FW1] Opinon Requested - to NAT or not to NAT DM... Frank Darden
