Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos

Firewall Wizards: Re: static nat and tcp limits

Re: static nat and tcp limits

From: Robby Cauwerts <robby_at_cauwerts.be>
Date: Sat, 1 Mar 2008 17:19:08 +0100

On Fri, Feb 29, 2008 at 11:27 AM, Vladislav Antolik <
vladislav.antolik_at_gmail.com> wrote:

> What is the best solution; disable nat-control and then
> disable static record?
>

Yes.
Creating nat rules for traffic that doesn't need to be natted is (in most
cases) ... useless.
(although some people see this as an additional layer of security)
By default in PIX/ASA v7.0 and later the "no nat-control" is the default
value.

Bye.
Robby

_______________________________________________
firewall-wizards mailing list
firewall-wizards_at_listserv.icsalabs.com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
Received on Mar 01 2008

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]