From: Wietse Venema (no email)
Date: Mon Jan 03 2005 - 10:35:13 EST
Mark Martinec:
> Wietse,
>
> > > The source port number (i.e. the whole TCP quadruple) is needed to be
> > > able to distinguish between boxes behind NAT, e.g. when they are
> > > firewalled.
> >
> > NAT is not a firewalling technique. Without a proper firewall on
> > top of NAT, is is possible to break into systems behind NAT boxes.
>
> I wasn't clear enough and you missed my point. I'll explain.
I was merely being obnoxious, but not stupid.
Wietse
|
|
|