Hey there,

I got some security questions... I'll first try to make a drawing to clarify

| Internet |
-------------- ------------
| WAP |------| DMZ |
-------------- ------------
| LAN |

NOTE!: The WAP is a Draytek Vigor2200Wplus which also has an ISDN connection
to the business, this is not in the drawing. The DMZ is on IP range the LAN is on
The WAP automatically forwards all ports to the DMZ (with exception of the
port it uses for PPTP/VPN to setup the internet connection ofcourse).
Actually the DMZ is only one PC running FreeSCO.

The risk I need to know/understand is the possibility to get from the DMZ
into either the LAN or the ISDN connection the WAP makes towards the
business. In principle the DMZ does not know about the LAN (there is no
route to it in there).

I don't much about cracking these kind of things. What I do know is that you
could manually put a route in packets (I have never done that though...).
Would it be possible, from either the internet or DMZ, to get into the LAN
with what I believe is called source-routed packets (packets with a
predefined route by the users)? In theory this would come down to telling
the cracking client that the internet IP is the gateway for the LAN behind
it, but since this isn't possible (because you already have a gateway
towards the internet and/or on the internet to route packets on to the
internet and you can't put a route through a gateway that's already behind a
gateway) I believe you have to do that through source-routed packets.

The point is, we need to estimate the risk. The LAN isn't even the biggest
concern, the biggest one is the ISDN connection to the business. However,
once in the LAN you can send packets there since the WAP will automatically
dial out if you send packets to the IP segments the business is on. It
should thus also not be possible to go either straight from the internet
over the ISDN, nor from the DMZ. Once in the DMZ it could be possible to
crack the WAP, perhaps it can even be done from the internet (although the
only port that is open 1723).

Anyone familiar with these kind of setups and how secure they are and/or the
security of the Draytek Vigor2200Wplus itself ?

Any info you can give will be greatly appreciated. We are aware that we
should keep up with firmware updates, and it has the latest one at this

How secure can a DMZ be anyways? The DMZ things I know in all cases the LAN
goes out over the same connection as the DMZ, so there might always be a
hole right? Then again, I think you can never be totally secure, and the LAN
connected to the internet right away would be even worse.

