Re: [fw-wiz] VPN concentrators

From: m p (sumirati@yahoo.de)
Date: 08/26/02


From: m p <sumirati@yahoo.de>
To: Patrick Darden <darden@armc.org>, scouser@paradise.net.nz
Date: Mon Aug 26 10:34:49 2002


 --- Patrick Darden <darden@armc.org> schrieb: >
> I don't agree. Putting authenticated and authorized traffic through a
> firewall is redundant. IPSEC traffic is trusted traffic. A VPN is an
> extension of your network--it is as trusted as any traffic internal to
> your network--perhaps more, as it can be completely accounted
> for--remember that every packet has a confirmed sip, dip, and payload.
>

I beg to differ.

He talked about VPN - not authorized and authenticated traffic from a source he
can trust 100%.

Traffic via a VPN can be from different sources with different levels of trust.
It can be a company or an employee or a branch office. That are 3 classes of
different trustworthy. Perhaps there are more.

There were some DoS-attacks against the Windows IPSEC implementation last year.
There too was a DoS attack against some open source IPSEC implementation. If
you can limit the addresses that connect to the termination point of your VPN
it may be worth the additional layer of security.

To make sure each person that logins / operate via the VPN is only allowed to
see what he/she/it should see there should be a firewall behind the termination
point of the VPN.

Yes, traffic via VPN should be the same as normal "in-house" traffic. But the
connection begin can be a problem - and if traffic via VPN is not "in-house"
traffic. If you firewall the RAS users in your company you should too firewall
the VPN users.

Just my 2 euro cent

Marc

__________________________________________________________________

Gesendet von Yahoo! Mail - http://mail.yahoo.de
Möchten Sie mit einem Gruß antworten? http://grusskarten.yahoo.de



Relevant Pages

  • Re: DFL-300 IPSEC VPNs only works if your remote client is open wide open on the internet! Sucks!
    ... > Are you trying to make a VPN connection somewhere? ... My PC is sitting on a 10/8 network behind a Checkpoint MG firewall I ... I allow IPSEC passthrough and I allow UDP virtual connectivity. ...
    (comp.security.firewalls)
  • Re: Calling all Experts!!
    ... I would strongly recommend building a IPSec VPN tunnel from one ... end to the other and forget the Nortel solution. ... > 1 Should VPN switch sit beside firewall or sit outside firewall? ...
    (comp.security.firewalls)
  • Re: cisco / microsoft -- what is the VPN IPsec alternative????
    ... I like Gnatbox firewall. ... about 2 years ago and they had just released the IPSec VPN verison. ...
    (comp.security.misc)
  • Re: Security of a Windows 2003 VPN Question
    ... I was thinking of using IPSec to block access to the box. ... Do you really need IPSec between VPN server and DC? ... Ok, what about the integrity of the box, since there's no firewall on it? ...
    (microsoft.public.windows.server.security)
  • RE: Sandboxing
    ... the 3Com Embedded Firewall would be extremely useful and enabling (in ... your case) when you look at it in a VPN context. ... This security policy will accomplish quite a few things: ... During the Policy Server installation, ...
    (Focus-IDS)