VPN server using certificates... any attack against is?



Hi guys,

All of us are aware of Aggresive mode attacks in PSK
VPN devices, like this good document show:

http://www.giac.org/certified_professionals/practicals/gcih/0541.php

However I got a case where the VPN server (appear to
be a CheckPoint with all updates) is configured to
ONLY authenticate via certificates. Are there any
attacks against VPN using only certificates to
authenticate?

Thank you.

Daniel

__________________________________________________
Fale com seus amigos de graça com o novo Yahoo! Messenger
http://br.messenger.yahoo.com/

------------------------------------------------------------------------
This List Sponsored by: Cenzic

Need to secure your web apps?
Cenzic Hailstorm finds vulnerabilities fast.
Click the link to buy it, try it or download Hailstorm for FREE.

http://www.cenzic.com/products_services/download_hailstorm.php?camp=701600000008bOW
------------------------------------------------------------------------



Relevant Pages

  • Re: Secure VPN access
    ... with it's security option for the client. ... After getting the VPN connection I check the Ip settings and found the ... point to the head ISP's DNS server. ... > Computer certificates for L2TP/IPSec VPN connections ...
    (microsoft.public.windows.server.sbs)
  • Re: VPN Problem, PC not Authenticating with Server
    ... do you mean you have configured L2TP/IPSec VPN ... is the VPN server, SBS or router? ... 818043 L2TP/IPsec NAT-T update for Windows XP and Windows 2000 ... Computer certificates for L2TP/IPSec VPN connections ...
    (microsoft.public.windows.server.sbs)
  • Re: IAS / RRAS
    ... Install Certificate services ... Configure the VPN connectoid and set it for l2tp connections? ... So you may want to try to do without the IAS server until problems ... > are resolved to rule it out as a problem.As far as certificates, ...
    (microsoft.public.windows.server.networking)
  • RE: vpn woes
    ... Being relatively new to the world of VPN and knowing how scary it can be to ... are out there to have some sort of secondary method of authentication that ... isn't easily duplicated by a hacker... ... issue any certificates if I need to. ...
    (Focus-Microsoft)
  • vpn woes
    ... Being relatively new to the world of VPN and knowing how scary it can be to ... are out there to have some sort of secondary method of authentication that ... isn't easily duplicated by a hacker... ... issue any certificates if I need to. ...
    (Focus-Microsoft)