RE: [fw-wiz] vpn end-point

From: Frederick M Avolio (fred_at_avolio.com)
Date: 03/19/04

  • Next message: Kyle King: "Re: [fw-wiz] Cisco PiX 501 running 6.2 - Defying me for no reason"
    To: Dave Piscitello <dave@corecom.com>, paul <paul@compuwar.net>, "Claussen, Ken" <Ken@kccweb.com>
    Date: Fri, 19 Mar 2004 11:48:01 -0500
    
    

    At 08:40 AM 3/19/2004 -0500, Dave Piscitello wrote:
    >I am surprised no one mentioned that terminating VPN at the firewall lets
    >you distinguish VPN traffic from all other traffic routed through the
    >firewall (without topological or addressing finagling), and protects VPN
    >traffic to the security policy enforcement point, e.g., across the "DMZ"
    >you have between the router and firewall (unless the router-firewall link
    >is a crossover cable, it's a network, and I've seen people throw IDS/IPS,
    >performance analysis devices, and gee, how about a web server there - and
    >that's only the list of systems they learn about).

    Which begs the question: How many of you with firewall/VPN combinations can
    and do configure the VPN to functionally terminate before the firewall?

    Some firewall/VPN boxes assume no firewalling for VPN connections. IE, if
    you are authenticated, you are in.

    f

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Kyle King: "Re: [fw-wiz] Cisco PiX 501 running 6.2 - Defying me for no reason"

    Relevant Pages

    • RE: Sandboxing
      ... the 3Com Embedded Firewall would be extremely useful and enabling (in ... your case) when you look at it in a VPN context. ... This security policy will accomplish quite a few things: ... During the Policy Server installation, ...
      (Focus-IDS)
    • Re: VPN Firewall for new webserver
      ... > I'm setting up a webserver at a colocation and I need to put a VPN ... You're not going to get a quality firewall for that amount, ... and D-Link makes a DI-804HV unit ... users access to the SQL server, let them do it through a VPN session. ...
      (comp.security.firewalls)
    • Re: Firewall Info/Recommendations?
      ... I would seriously consider an air-gap solution. ... Let me outline a few features that no other firewall can touch. ... Provide secure access without a VPN from any web browser (this greatly ... > manageable without much higher-level support if you want things like ...
      (comp.security.firewalls)
    • Re: [fw-wiz] Integrated IDS/IPS/Firewall (Cisco ASA and Juniper ISG)
      ... complexity and architectural inelegance of having 3-5 gateway security ... VPN) convinced me to eventually champion a migration to Symantec's SGS ... Nice balance of "default deny" at the firewall, ...
      (Firewall-Wizards)
    • Re: two winxp home machines, varied results
      ... >The only firewall I have on my machine *aside* from the Cisco VPN ... Please don't change "restrictAnonymoussam", only ... >Here is the IPCONFIG and BROWSTAT listings for each machine. ...
      (microsoft.public.windowsxp.network_web)