Re: [fw-wiz] HTTPS, proxies, and remote developers.

simonis_at_att.net
Date: 06/15/03

  • Next message: Paul Robertson: "Re: [fw-wiz] HTTPS, proxies, and remote developers."
    To: Firewall-Wizards <firewall-wizards@honor.icsalabs.com>
    Date: Sun, 15 Jun 2003 17:44:57 +0000
    
    

    >
    > What would be the easiest way to handle this situation? How would you
    > resolve a policy issue if one of your clients requires that you use
    > unencrypted traffic outbound from their network into yours.
    > (Their need to know for traffic on their network against your need for
    > security).
    >

    It seems to be that the client has an irrational desire. Why would
    anyone disagree with having a VPN between two networks whose
    interconnection crosses a public network? There are many ways they
    could maintain visibility on their network while still allowing
    encryption. For example, using a point to point VPN with a preshared
    secret. TCPDump can, with knowlege of the preshared key, decrypt
    that traffic for monitoring. There are numerous other, more complex,
    means for decrypting/inspecting/encrypting VPN traffic, if the need
    really exists, and I would use this angle to herd this customer into
    the proper corral.

    -Ds
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Paul Robertson: "Re: [fw-wiz] HTTPS, proxies, and remote developers."

    Relevant Pages

    • RE: SBS 2003 VPN issue through ISA
      ... The XP clients and the TS are in the same network and same domain. ... connections are established from the clients themselves using Cisco VPN ... appears ISA is somehow dropping the connection according to the logs. ...
      (microsoft.public.windows.server.sbs)
    • Re: Unable to access hosts by name across a PPTP VPN connection
      ... How many remote clients ... Home) will only accept one incoming VPN connection at a time using the ... network and as new machines are used as VPN clients. ...
      (microsoft.public.windowsxp.work_remotely)
    • Re: Cant locate resources by name... I have to use their IPs
      ... Make sure the ISA firewall assigns VPN clients a WINS server address. ... > When I VPN into our network from home, I can't find computers, servers, ...
      (microsoft.public.isa.vpn)
    • RE: Security and VPN
      ... VPN is that they are extending their network out to the VPN endpoint. ... Now that home desktop is on your network. ... also clients that will force a virus scan of the workstation and force ...
      (Pen-Test)
    • Re: VPN error with SBS2003 and ISA
      ... some of the cable/dsl router just don't work with VPN. ... When you switch your clients from the x.x.2.x network to x.x.3.x ...
      (microsoft.public.isaserver)