Welcome to the MacNN Forums.

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

You are here: MacNN Forums > Enthusiast Zone > Networking > Which is better: Airport w/ NAT or OS X's "stealth" firewall?

Which is better: Airport w/ NAT or OS X's "stealth" firewall?
Thread Tools
Addicted to MacNN
Join Date: Jan 2003
Location: ~/
Status: Offline
Reply With Quote
Jun 24, 2005, 12:46 AM
 
I know - not a good thread title, but everything else I wanted to add was too long.

Here's the deal... I've got 5 machines plus a TiVo here in the house, and they all access the 'net via my Airport Extreme basestation (either wireless or wired via its LAN port). I've noticed over the last several days (as that's when I've turned the logging on) that I'm being port-scanned. While its probably mainly zombie PCs and Windows worms looking for a host, I still don't like the idea of being scanned on a regular basis.

As far as securing each machine, they all have firewalls (MacOS X's or Windows'; all except the TiVo I suppose) turned on, and all non-essential services are turned off. Basically, only one machine has AFP file-sharing enabled. All machines are behind the Airport's NAT system. Herein lies the problem...

The thing is, the Airport will acknowledge any (outside/public) ping request made to it, and when port-scanned, will return an open or closed response, indicating of course that at least some kind of machine exists here. MacOS X 10.4's firewall, on the other-hand, will ignore any request made to it (unless a specific port is open) via its "Stealth" mode.

So, am I better off letting hackers/worms/zombie PCs port-scan me all day (while I sit behind the NAT and each machine's own firewall), or would connecting one of my machines directly to the cable modem's WAN port and turning on stealth mode in the firewall (so port-scanners don't see any machines alive at my IP address) be better (then feeding 'net access back to the Airport via OS X's internet sharing)? Or, third option, should I buy some kind of hardware/router to go between the Airport and the cable modem - one that has a stealth function build-in?

Any thoughts??

Not trying to be paranoid... just prudent. Plus, I do have a Windows box in here :brink: hence the need for good security. And doesn't being port-scanned 24/7 result in some kind of network/cable modem service degradation??
     
Senior User
Join Date: Jan 2003
Status: Offline
Reply With Quote
Jun 27, 2005, 12:23 AM
 
It's a fact of life, if you're on the internet you're gonna get scanned. No machine is 100% stealth, better to let your nat box do it's job and keep your hosts behind the wall. If your really paranoid, you could always put another NAT box (different manufacturer, model) in front of your current box. Think of it like an onion with multiple layers of defense.
15" Macbook Pro 1.83 2 GB RAM
Blackbook 13.3 Powerhouse 2 GB RAM
MacMini Dual Core 2 GB RAM (Sadly running Windows Most of the time)
Numerouse Workstations running windows and Linux. Sorry don't have the specs, I don't pay much attention to them anymore. :)
     
   
Thread Tools
Forum Links
Forum Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Top
Privacy Policy
All times are GMT -5. The time now is 09:57 PM.
All contents of these forums © 1995-2011 MacNN. All rights reserved.
Branding + Design: www.gesamtbild.com
vBulletin v.3.8.7 © 2000-2011, Jelsoft Enterprises Ltd., Content Relevant URLs by vBSEO 3.3.2