Re: Need VPN Firewall security advice

From: Anthony Ewell (aewell_at_gbis.com)
Date: 08/21/04

  • Next message: Baklin Drumheller: "Giving up"
    Date: Sat, 21 Aug 2004 14:05:18 -0700
    
    

    P Gentry wrote:

    >> I am about to put a port forward in my IPTABLES
    >>firewall to allow a remote Windows laptop to
    >>run a VNC on a desktop inside my firewall.
    >>
    >> The port forward checks to remote end's IP address,
    >>protocol type, and port before doing the forward.
    >>the VPN required a password in addition to the key.
    >>The user is very good about keeping the password
    >>separate from the laptop, in case it gets stolen.
    >>(The password is really, really nasty!) To break
    >>in, a thief would need both the password and the IP
    >>address of the distant end.
    >>
    >> Question: at this point in my description, do
    >>you all feel comfortable with what I am planning?
    >
    >
    > Probably not -- the VNC connect password is encrypted (barely) but all
    > subsequent traffic passes unencrypted. Will compression be enough to
    > discourage the bad guys? Your call. At least check into using SSH or
    > SSL (stunnel) to provide end-to-end encryption of all traffic. SSL
    > with certificates provides reasonable authentication security as well
    > ;-)

    Hi P.,

         I should have made it more clear that TightVNC has to
    transverse OpenVPN to make connection with the other end.
    I am presuming that OpenVPN will provide enough (encrypted)
    security. Does this change your evaluation?

         As far as the floating IP's, I have complete control
    over the firewall. I am a private contractor, not an
    employee. My customer give me the final say on everything
    to do with the network. They are dear people -- the ones
    you want to take very, very good care of. Consequently, I
    am very, very protective of them. I even have them off
    of IE and OE (Firebird and Thunderbird are awesome).
    They have only caught one virus in the seven years I have
    worked for them! :-)

         As I stated before, floating IP's through the firewall
    give me the hives. Since they give all of you the hives as well,
    they are out. If the other users want VPN access, I will arrange
    with their ISP's for a fixed address. (My other remote
    users will love any excuse to upgrade to DSL at
    their homes. So, it is a win-win situation for me!)

         I appreciate all of your wisdom and assistance in
    this matter. :-)

    --Tony


  • Next message: Baklin Drumheller: "Giving up"

    Relevant Pages

    • Re: Alternative to GoToMyPC?
      ... > Remote Desktop would be your ... > Is there any way to tell what port GoToMyPC was using? ... Shenan Stanley wrote: ... > address and to create a path through the firewall to the pc... ...
      (microsoft.public.windowsxp.work_remotely)
    • Re: SP2 firewall/remote management
      ... Right, and when that setting is applied, running>netsh firewall show port ... > I would think you need to apply this policy setting on the remote ... > Windows Firewall: Allow remote administration exception ...
      (microsoft.public.windowsxp.setup_deployment)
    • Re: Need VPN Firewall security advice
      ... > I am about to put a port forward in my IPTABLES ... > firewall to allow a remote Windows laptop to ... > run a VNC on a desktop inside my firewall. ... > The port forward checks to remote end's IP address, ...
      (comp.os.linux.security)
    • Re: Still behind a firewall (home edition sp2)
      ... You might look at either UltraVNC (you need TCP Port 5900 open on the ... firewall) with its encryption plug-in and XP driver for the host PC... ... Al Jarvi (MS-MVP Windows Networking) ... I am trying to install a remote desktop server (home ...
      (microsoft.public.windowsxp.network_web)
    • Re: 1 NIC v. 2 NICS & remote access questions from beginner
      ... you could use Remote Web Workplace for direct, remote control access of desktops, or you could use a VPN for general network connectivity followed by mapped drives to the file shares. ... You can use the free Microsoft VPN by configuring RRAS on the server and opening TCP port 1723 on the firewall, or you could use a firewall-provisioned client. ...
      (microsoft.public.windows.server.sbs)