Wireless VPN cracking.

From: Clinton McDonald (cmcdonald@extremenetworks.com.au)
Date: 06/28/02


Date: Fri, 28 Jun 2002 09:49:11 +1000
From: "Clinton McDonald" <cmcdonald@extremenetworks.com.au>
To: <SECURITY-BASICS@securityfocus.com>

Hello all..

I've got a couple of (hopefully!) quick questions regarding a wireless
VPN.

I have set up a pix to terminate a VPN for our wireless users, to keep
all their network traffic secure. It looks vaguely like this:

<<----------VPN--------------->>
Laptop ---> Access Point ---> Pix ---> Switch ---> Server
172.16.0.1 10.1.1.11

The laptop is running the Cisco Secure VPN Client (3.5), and when the
VPN is connected, the Pix assigns the addresses 10.0.0.90-10.0.0.99 to
VPN users for the internal (wired) network. When the traffic gets to
the Pix, the VPN is terminated there, and there is no encryption on the
wired part of the network.

My theory is that if anyone is sitting out in the car park with a laptop
with a wireless card, they can associate to the access point all they
like, but if they are not authorised VPN users, the Pix will drop their
traffic, and thus, stop them from getting into the internal (wired)
network.

Questions are:
1. Can someone in the car park crack into a VPN users laptop
somehow, and then get into the network (ie, bypass the pix and connect
via the other laptop?

2. If I ping from the server, to 10.0.0.90 (the VPN user), I get a
response. Should this be so?

Thanks in advance..

Clinton McDonald CCNA



Relevant Pages

  • RE: [fw-wiz] PIX split tunneling
    ... Split tunneling is an excellent option for saving bandwidth and SA's on your ... To use a VPN the user would need access to the internet ( ... on a public network then if they change the config then they change it. ... If your users are inside the PIX then I don't understand the question. ...
    (Firewall-Wizards)
  • RE: RE: Wireless security and VPN
    ... IPSec alone is enough to secure all your network data. ... Subject: Wireless security and VPN ... authorized to receive the communication. ...
    (Security-Basics)
  • PIX 515E dropping existing TCP connections
    ... I recently took over administration of a PIX 515E. ... network, and VPN to the PIX to access a private network. ... When the VPN is connected, I can SSH to hosts on the private network. ... PIX drops the connection after transferring just a few kilobytes. ...
    (comp.dcom.sys.cisco)
  • RE: Wireless Security Strategy
    ... Use a VPN for all data traffic. ... From my perspective we are seriously considering creating wireless subnets ... would only be able to talk to a terminal/CITRIX server on the corporate ... wireless network and that would be in encrypted form due to the VPN. ...
    (Security-Basics)
  • RE: Wireless Security Strategy
    ... Make sure that all wireless network ... I'm new to this VPN lark.. ... >>would only be able to talk to a terminal/CITRIX server on the ...
    (Security-Basics)