PPTP versus L2TP and possible attacks

From: James D. Stallard (james_at_leafgrove.com)
Date: 02/11/04

  • Next message: Marc Fossi: "Article Announcement: Automating Windows Patch Management: Part I"
    To: <focus-ms@securityfocus.com>
    Date: Wed, 11 Feb 2004 19:19:19 -0000
    
    

    Hi

    I have recently deployed a VPN Server using Microsoft RRAS. RRS is the
    preferred technology because there are few anticipated users and the
    software is free :)

    The VPN Server sits behind the corporate firewall and operates fine,
    accepting incoming connections reliably.

    I am rather new to the VPN game (I usually design Active Directory
    infrastructures) and set up both L2TP and PPTP protocols for convenience
    sake while the client pilots the solution. My questions are therefore:

    1. Which is the better tunnelling protocol in terms of security and
    functionality, L2TP or PPTP, and why?

    2. Is the community aware of any exploits that could be levelled against the
    firewall with the following ports opened to support VPNs?

    L2TP requires: Protocol 50, UDP 4500, UDP 500
    PPTP requires: Protocol 47, TCP 1723

    3. Anything else I should know?

    All advice is appreciated

    Thanks in advance
    Regards

    James D. Stallard

    ---------------------------------------------------------------------------
    Free trial: Astaro Security Linux -- firewall with Spam/Virus Protection

    Protect your network with the comprehensive security solution that
    integrates six applications for ease of use and lower TCO.

    Firewall - Virus protection - Spam protection - URL blocking - VPN
    - Wireless security.

    Download 30-day evaluation at:
    http://www.astaro.com/php/contact/securityfocus.php
    ---------------------------------------------------------------------------


  • Next message: Marc Fossi: "Article Announcement: Automating Windows Patch Management: Part I"

    Relevant Pages

    • Re: VPN ports
      ... Pptp requites tcp 1723 and protocol 47/gre which sometimes is referred to as pptp ... client on the client computer into a W2003 rras vpn server. ...
      (microsoft.public.win2000.networking)
    • Re: MS VPN server
      ... What will you use for VPN? ... PPTP or L2TP? ... protocols open between the client and VPN server? ... GRE - IP protocol 47 ...
      (microsoft.public.windows.server.setup)
    • Re: Remote Desktop security
      ... You can increase security if you can go through a VPN ... connection - particularly L2TP which will only allow computers with a ... trusted certificate to access the VPN server. ... > I have Remote Desktop exposed to the internet on a 2003 standard server ...
      (microsoft.public.windows.server.security)
    • Deny VPN access to machines not in domain
      ... We are using MS W2K3 server as a VPN server. ... security. ... Is there an easy way to deny login through the VPN for valid ...
      (microsoft.public.windows.server.general)
    • VPN configuration for WLAN connection
      ... I am attempting to configure a W2K VPN server for routing ... all WLAN connections through for security. ... the W2K client to connect to the W2K VPN server. ...
      (microsoft.public.security)