RE: DMZ and VPN

From: John Tolmachoff (sflist-secbasic@reliance.net)
Date: 02/18/03

  • Next message: blaxes: "RE: Web Log Analyzer"
    From: "John Tolmachoff" <sflist-secbasic@reliance.net>
    To: "'Security Manager'" <sec_man1234@yahoo.com>, <security-basics@securityfocus.com>
    Date: Tue, 18 Feb 2003 09:29:45 -0800
    
    

    > How do you solve that one?

    By using a firewall in addition to RRAS. RRAS only determines what packet
    goes where. You still need to filter and check those packets.

    This is one of my complaints of allowing RRAS to create an VPN endpoint. It
    can give someone a false sense of security. If the RRAS server becomes
    compromised, so is the VPN traffic as well as the network behind the VPN
    endpoint.

    IMO, using RRAS as a VPN endpoint should not be used in conjunction with a
    DMZ zone, only behind a firewall.

    John Tolmachoff MCSE, CSSA
    IT Manager, Network Engineer
    RelianceSoft, Inc.
    Fullerton, CA 92835
    www.reliancesoft.com



    Relevant Pages

    • Re: Need help setting up a VPN server
      ... "Phillip Windell" wrote in message ... outside is after business hours, I used the built in rules in the Linksys WRT45G to disable internet access before and after business hours. ... If I were to use RRAS for the vpn server, would I have to have another RRAS box at another location maintaining the site-to-site vpn or can I use a vpn endpoint router to connect to the RRAS box? ...
      (microsoft.public.windows.server.networking)
    • Re: ISA 2004 & SBS 2003
      ... I assume that ISA 2004 also has a Firewall Client. ... > NAT is configured through RRAS. ... > would know the wizards worked again if everything was configured correctly ...
      (microsoft.public.windows.server.sbs)
    • Re: RRAS - Works on internal network, not past DMZ
      ... > VPN Users would connect directly to the Public interface of the RRAS box. ... The Firewall would need some additional configuration if you ... On the network connections configuration of the RRAS box, ... but the 'multiple gateway' error message has me spooked. ...
      (microsoft.public.windows.server.networking)
    • Re: Unknown Network Attack
      ... disabled on a server using rras. ... Check your tcp/ip configuration to make ... IP to DHCP or changed the entries in tcp/ip such as IP address, dns server, ... >> firewall configurations for some firewalls. ...
      (microsoft.public.windows.server.networking)
    • Re: DSCP with GRE?
      ... I don't care if RRAS ... After all who wants to prioritize traffic by user?!? ... >> In order to prioritize the contents of a VPN tunnel you need to be able to propogate the ToS field with DSCP information from ... I ended up looking at the packet headers to be sure if this worked or not. ...
      (microsoft.public.isa.enterprise)

  • Quantcast