Re: Deploying SSL-based VPNs



For things like Remote Desktop or IPSEC clients via SSL-VPN, then you're
correct as you'll need to install an active-x or java client of some
sorts.

VPN based SSL is merely a Reverse proxy with the capability to tunnel
mutiple protocol / ports. Apache + mod_proxy will allow you to
implement a simple SSL VPN, which will make intranet content available
on to the internet in a secure fashion. And you are correct, in its
simplest form this should NOT require any client installation on the
desktop.

However most enterprises want the ability to tunnel any kinds of
traffic / port and a kitchen sink, through the SSL VPN. Thus the need
for a Active X control / Java applet or some plugin.

--
Saqib Ali, CISSP, ISSAP
Support http://www.capital-punishment.net
-----------
"I fear, if I rebel against my Lord, the retribution of an Awful Day
(The Day of Resurrection)" Al-Quran 6:15
-----------

---------------------------------------------------------------------------
EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The Norwich University program offers unparalleled Infosec management
education and the case study affords you unmatched consulting experience.
Tailor your education to your own professional goals with degree
customizations including Emergency Management, Business Continuity Planning,
Computer Emergency Response Teams, and Digital Investigations.

http://www.msia.norwich.edu/secfocus
---------------------------------------------------------------------------



Relevant Pages

  • Re: MDA3 Synchronisation mit Exchange
    ... SSL einrichten zu müssen. ... Exchange mit ActiveSync funktionieren.Die Einwahl per VPN geht ja auch, man sieht mich auf der Firewall, aber der Sync geht nicht. ... Also kannst Du auch andere Daten übertragen, z.B. das mobile Gerät anpingen durch den Tunnel? ...
    (microsoft.public.de.exchange)
  • Re: VPN versus Terminal Server for remote workers
    ... If one wants to cross the river and gets into a secure tunnel, ... this does not really help me understand why the hardware will allow ... By default and intention 'split tunneling' of VPN connections is not ... as far as using Term Server, the question really is: ...
    (microsoft.public.windows.server.sbs)
  • Re: RV042 - Does anyone understand it? Documentation?
    ... if one is using an RV042 for VPN, then what affect does the routing table have on the VPN packets? ... When the packet is received at the other end of the tunnel, it will still be destined for a "foreign" private subnet. ... In other words the range of IP's you are trying to reach and the range of IP's the traffic is coming from MUST be included in the subnets for the encrypted tunnel. ...
    (comp.dcom.vpn)
  • Re: [fw-wiz] Secure access to LAN resources (WAS: terminal services)
    ... > encrypted tunnel. ... VPN devices are designed to do strong authentication. ... It's always a trade-off between risk and protection. ...
    (Firewall-Wizards)
  • Re: Turn-Key Installation Question: SBS 2003 Standard + Hardware VPN
    ... The clients I have found so far that like the SBS setup have been graphic ... Setting up a VPN tunnel is easy under ... A firewall appliance sounds like the ...
    (microsoft.public.windows.server.sbs)