Re: [fw-wiz] VPN endpoints

From: Rodel Collado Urani (sparc_at_ucomputer.org)
Date: 08/30/04

  • Next message: Jeremiah Cornelius: "Re: [fw-wiz] About Port Forwarding, Apache and Firewall Rules"
    To: hermit921@yahoo.com
    Date: Sun, 29 Aug 2004 18:21:05 -0700
    
    

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    On Tue, 24 Aug 2004 10:36:43 -0700 hermit921 <hermit921@yahoo.com>

    hello,

    VPN is secure by default and it uses several encryption algorithm to
    satisfy the endpoint security every administrator and endusers is looking
    for. As long as it is within the VPN jurisdiction (i mean the client
    and server who are accessing the service) the communication cannot be
    easily be compromised (it may take long to get that) because the data
    are encrypted while traversing the unsecured public internet. Also consider
    what types of service or protocols are you going to employ there are
    like L2TP, PPTP from Microsoft, IPSec VPNs and the new one which is the
    SSL VPN where its elimates hassles on part of the Security Admin (whoever
    is in-charge in your organization) to configure the vpn client because
    lots of internet browsers has now have their own SSL embedded in it.
    The question must be like this, is the security still remains if the
    message or data transmitted is still secure when it goes out of the VPN
    server? Like when you transfer it to your PC or any machine that is already
    out of the VPN jurisdiction. Absolutely NOT! unless you have implemented
    an OpenSecurity Infrastructure (OSI) that will totally secure by encrypting
    all data transmitting in (your LAN) and out (that is the use of VPN)
    of your network.

    Actually, I coined OSI ;-) as an implementation of distinct security
    techniques and several processes particularly in protecting the inter-

    network. Meaning adept in the disposal of security components such us
    encryption, PKI, openPGP, software/hardware firewall, antivirus software
    that will make sure it will guarantee the protection of your data wherever
    it goes. ;-)

    Cheers,

    a.k.a Sparc

    RODEL COLLADO URANI
    -----BEGIN PGP SIGNATURE-----
    Note: This signature can be verified at https://www.hushtools.com/verify
    Version: Hush 2.4

    wkYEARECAAYFAkEzZT8ACgkQQ7QUZrvBIZ0/eQCeOG+2Zlh8TPLb47VdH19Chg78c3YA
    niVaSZrbTfztEBuJ6NuYpBEPKCEB
    =imhZ
    -----END PGP SIGNATURE-----

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Jeremiah Cornelius: "Re: [fw-wiz] About Port Forwarding, Apache and Firewall Rules"

    Relevant Pages

    • Re: Internet security on "hotspots"
      ... Network Security Engineer ... visiting HTTPS sites so, she doesn't need encryption'. ... then a VPN wasn't needed. ... personal firewall can be a dangerous venture. ...
      (Focus-Microsoft)
    • Re: Another RWW versus VPN question
      ... Sarbanes Oxley and all other regulations are silent as to technology. ... One could argue that after the CISCO/Michael Lynn Blackhat/Vegas issue that Cisco isn't that secure. ... With VPN access, the data could be pulled over the wire to my home users, they "could" introduce more risk to my network if they are not patched, updates and protected. ... I have a client that recently had a programmer from a large security based company come by and demo the Access database he is working on for them. ...
      (microsoft.public.windows.server.sbs)
    • Re: Another RWW versus VPN question
      ... And after Blackhat I wouldn't be trusting of Cisco PIX either. ... One could argue that after the CISCO/Michael Lynn Blackhat/Vegas issue that Cisco isn't that secure. ... With VPN access, the data could be pulled over the wire to my home users, they "could" introduce more risk to my network if they are not patched, updates and protected. ... I have a client that recently had a programmer from a large security based company come by and demo the Access database he is working on for them. ...
      (microsoft.public.windows.server.sbs)
    • Re: Another RWW versus VPN question
      ... A Pix does not ...by itself make you more secure. ... VPN "can" make you more insecure. ... I have a client that recently had a programmer from a large security based ...
      (microsoft.public.windows.server.sbs)
    • Re: [Full-disclosure] Remote Desktop Command Fixation Attacks
      ... This set of steps is redundant in many places, and it's also enormously expensive, since you're using no less than three different expensive bits of networking hardware (AP, PIX, VPN Concentrator), in addition to a bunch of x86 server hardware, windows server licenses, and at least one ISA license. ... Your computers necessarily don't have full access to your network infrastructure when they aren't logged on, so GPOs, software updates, etc can't be applied at the times you want them to be applied. ... Turning on, enabling, and implementing every possible security setting and device you think of is not defence in depth, and will probably only have two effects - your users won't use your wireless network, and you'll burn so much cash you won't have any left to spend on *useful* security measures. ...
      (Full-Disclosure)