VPN's - Firewall's and Security

From: Christopher Joles (CJoles_at_proteabhs.com)
Date: 08/26/03

  • Next message: Logan Rogers-Follis - TNTNetworx.net: "Re: Is anyone else seeing SMURF ?"
    Date: Tue, 26 Aug 2003 11:08:53 -0400
    To: <security-basics@securityfocus.com>
    
    

    Good Day All!

    I'm looking for design advice.

    Currently, I have a network that is protected by a Cisco PIX 515 =
    firewall. We have it configured to protect our internal network along =
    with supplying access to our DMZ which holds our email and web servers.

    My concern arises from the spread of the blaster worm. Currently we =
    give a couple employees (the boss, the CFO and myself) VPN access from =
    home. In this scenario, the bosses home computer was compromised by the
    = blaster worm and luckily for me, he was on vacation in Germany at the
    = time. If he wasn't, he most assuridly would have made a VPN
    connection = and the lovely blaster worm would have gotten through our
    defenses. = Keep in mind, I had applied the MS patch to our servers and
    = workstations, however, it would have still gotten "inside". How can I
    = redesign my network to either firewall the VPN connections or at a =
    minimum filter them.

    Thanx for your opinions in advance!

    Christopher J. Joles
    Chief Information Officer

    PROTEA Behavioral Health Services
    187 Exchange St.
    Bangor, ME 04401
    Phone: (207)992-7010 Ext: 245 Fax:(207)992-7011

    ---------------------------------------------------------------------------
    Attend Black Hat Briefings & Training Federal, September 29-30 (Training),
    October 1-2 (Briefings) in Tysons Corner, VA; the world's premier
    technical IT security event. Modeled after the famous Black Hat event in
    Las Vegas! 6 tracks, 12 training sessions, top speakers and sponsors.
    Symantec is the Diamond sponsor. Early-bird registration ends September 6.Visit us: www.blackhat.com
    ----------------------------------------------------------------------------


  • Next message: Logan Rogers-Follis - TNTNetworx.net: "Re: Is anyone else seeing SMURF ?"

    Relevant Pages

    • Re: Travelling laptops over VPN
      ... >>> on the user's machine within the properties of the VPN Dialup Connectiod. ... >> network administrators would want to do that to prevent the users from enabling ... when the user connects to the VPN using the Cisco ... the firewall shuts off because it sees the domain. ...
      (microsoft.public.windowsxp.work_remotely)
    • Re: Travelling laptops over VPN
      ... >>> on the user's machine within the properties of the VPN Dialup Connectiod. ... >> network administrators would want to do that to prevent the users from enabling ... when the user connects to the VPN using the Cisco ... the firewall shuts off because it sees the domain. ...
      (microsoft.public.windowsxp.security_admin)
    • Re: Using a Linksys router, should I also use Zonealarm?
      ... public internet to access corporate network. ... In the "old days" when people used to use Dial-In instead of VPN you ware ... protected by corporate Firewall -- since there was no public Internet ...
      (microsoft.public.security)
    • Re: Firewalls
      ... To enable or disable Internet Connection Firewall ... Open Network Connections ... protect, and then, under Network Tasks, click Change settings of this ...
      (microsoft.public.windowsxp.security_admin)
    • Re: Cannot access network share
      ... the firewall locks those down by default. ... Robert Brown ... Networking, Internet, Routing, VPN Troubleshooting onhttp://www.ChicagoTech.net ... How to Setup Windows, Network, VPN & Remote Access ...
      (microsoft.public.windows.server.networking)