[SLUG] Re: CD-Based Firewall -- PPPoE on the modem? (I recommend against it)

From: Bryan J. Smith (b.j.smith@ieee.org)
Date: Thu Nov 04 2004 - 05:38:52 EST


On Wed, 2004-11-03 at 08:44, Robert Snyder wrote:
> Now when it comes to Verizon and PPPOE it usually best for it the
> modem to handle it. Verizon will force you to use PPPOE login via the
> modem if you ever have a problem.

Unfortunately, that can quickly become a performance issue. It can also
be a usability issue if the modem does the 1-to-many NAT for you. I.e.,
you seriously limit yourself to the capabilities of that 1-to-many NAT
device.

Since most 1-to-many NAT devices utterly lack advanced firewall and,
more importantly, IDS capabilities, they are rather useless. It's never
a matter of not being hacked, but knowing when you have.

Otherwise you're just another Valve -- you won't know you've been hacked
for months until your source code is posted on the Internet. Had Valve
had IDS, they would have known.

-- 
Bryan J. Smith                                  b.j.smith@ieee.org 
------------------------------------------------------------------ 
"Communities don't have rights. Only individuals in the community
 have rights. ... That idea of community rights is firmly rooted
 in the 'Communist Manifesto.'" -- Michael Badnarik

----------------------------------------------------------------------- This list is provided as an unmoderated internet service by Networked Knowledge Systems (NKS). Views and opinions expressed in messages posted are those of the author and do not necessarily reflect the official policy or position of NKS or any of its employees.



This archive was generated by hypermail 2.1.3 : Fri Aug 01 2014 - 16:27:01 EDT