NAT firewall

Opinion
Jul 25, 20053 mins

Ron Nutter helps a reader who asks: “For the average home user, how safe is having a simple NAT box between your Internet connection and your PC or network?”

For the average home user, how safe is having a simple network address translation (NAT) box between your Internet connection and your PC or network? I’ve heard claims that breaking through NAT is a trivial matter, although I’ve never seen or heard of it being done.

– George Kaplan

Having a “simple” NAT appliance between your Internet connection and a single PC or group of PCs is better than being directly attached without any protection. Having just a NAT box unfortunately isn’t offered by some vendors, you also have the ability to block additional services and/or ports so even if a given PC is having a valid conversation with a host on the Internet, someone cant inject traffic coming from another port into the same conversation if the rules you have set up don’t allow it. This is known as a Man in the Middle Attack. Fortunately the “appliance firewalls” offered by the various vendors that I have had a chance to look at keep getting better and offer better protection than some of us are used to with the firewalls used by larger companies.

It can’t be stressed enough that with any firewall, your protection is only as good enough as the latest version of firmware your vendor has released to be installed on the appliance. Something the average home user would probably not do but should is enable some type of logging or alert so when unwelcome traffic starts arriving you know someone is trying to knock at the door. Just like anti-virus signature updates, keeping things current will do nothing but help to keep the barbarians at the gate.

Although it is theoretically possible to break through a NAT-only firewall, I haven’t heard of it happening to anyone I know. Fortunately, most of the basic NAT-type appliances have some type of stateful operation in the firewall. With this feature, the appliance won’t allow incoming traffic to a PC on the protected side of the firewall where the traffic coming from the host wasn’t in response to traffic generated from your side of the connection. Again, it may be possible but I haven’t heard first hand of any such cases. Having said that, on my personal connection at home, I go through two firewalls from different vendors just to be on the safe side. I know that if someone really wants to get in and spends enough time at trying to break in, they probably will – I just don’t have to make it very easy to do so.