Skip to content

Your Firewall Takes Instructions From Strangers. Turn Off the Protocol Helpers.

A protocol helper β€” SIP ALG, FTP helper, H.323 ALG, conntrack helper, call it what your vendor calls it β€” reads the payload of a connection, finds an address and a port written in the text, and opens an inbound pinhole for them. It cannot tell whether that text came from a real FTP client or from a hidden form on a web page, because there is nothing in it to tell. Samy Kamkar proved the browser case in 2010. NAT Slipstreaming proved it again in 2020, and Armis extended it in 2021 to reach any device on your network, not just the machine that clicked. The IETF asked for these off by default in 2007, Linux turned them off in 2016, and the browser vendors ended up shipping a blocked-port list that reads like a directory of conntrack modules. This post walks the mechanism diagram by diagram β€” the expectation table, the segment-alignment trick, H.323 call forwarding, the IRC helper that fires on somebody else’s message β€” takes in the IPsec pass-through helper, which cannot read ESP at all and steers inbound packets on an SPI it watched go past in the clear, sets the lot against the Cyber Essentials firewall control it plainly fails, and gives the commands to turn it all off on Linux, Cisco, Juniper, FortiGate and MikroTik.

14th September 2026 Β· 54 min Β· 12564 words Β· Damien Dye