Todd is right, NAT is not really a security measure, just a clever way to overcome the shortage of IPv4. This paper shows a technique to count the hosts behind a NAT.
http://www.research.att.com/~smb/papers/fnat.pdf wow.. hadn't posted to the list in a while... Hello World! > On Thu, 4 Mar 2004, Robinson, Eric R. wrote: > >> Opinions, please: Is NAT useless for a DMZ where all hosts have static >> (i.e., one-to-one) translations? > > NAT and PAT are not inherently strong security measures, regardless of the > mappings. At best, it will function as a sort of security through > obscurity. The real purpose of {N,P}AT is to conserve IP address space > and/or translate for non-routable (e.g. RFC 1918) networks. > > -- > Todd's "Customer Disservice Hall of Shame" currently contains: > - Charter Communications: Mislead their customers about service > levels, block normal Internet connectivity, and exhibit excessive > downtime. > - AT&T: Honoring the "checks" they send out to entice you to switch > long-distance providers is apparently optional. > - eFax: Receive (not send) 20 pages of *unsolicited* faxes, and lose > your account. > _______________________________________________ > RLUG mailing list > [EMAIL PROTECTED] > http://www.rlug.org/mailman/listinfo/rlug > _______________________________________________ RLUG mailing list [EMAIL PROTECTED] http://www.rlug.org/mailman/listinfo/rlug
