Re: VPN without Firewall?!

From: Walter Roberson (roberson@ibd.nrc.ca)
Date: 06/03/02


From: roberson@ibd.nrc.ca (Walter Roberson)
Date: 3 Jun 2002 21:00:05 GMT

In article <3cfbd9f8_4@news1.prserv.net>,
MaryAnne <MaryAnne_2002@hotmail.com> wrote:
:The requirement:

:A remote office with 100 users needs to connect to the corporate network
:with minimal cost.

:The proposed solution:

:To reduce cost, it is proposed to install a VPN applicance without firewall

What is the cost to the company of having the connection exploited
even once? If it exceeds about $US1000 then economically you'd be
better off getting a firewall appliance that handles VPN.

IMHO, by the time you have 100 users at a connected site, that site needs
a firewall of its own -- unless perhaps the *only* connection to
the outside world (including modem connections!) is through the
main site AND the security needs of the remote site are -exactly- the
same as the security needs of the main site. Even then, the
onion containment principle would suggest that it would make sense to
protect the remote site separately, just to molify the damage should
someone break in to the main site.



Relevant Pages

  • Re: VPN without Firewall?!
    ... :A remote office with 100 users needs to connect to the corporate network ... :with minimal cost. ... :The proposed solution: ... What is the cost to the company of having the connection exploited ...
    (comp.security.misc)
  • Re: VPN without Firewall?!
    ... :A remote office with 100 users needs to connect to the corporate network ... :with minimal cost. ... :The proposed solution: ... What is the cost to the company of having the connection exploited ...
    (comp.security.firewalls)
  • Re: VPN without Firewall?!
    ... :A remote office with 100 users needs to connect to the corporate network ... :with minimal cost. ... :The proposed solution: ... What is the cost to the company of having the connection exploited ...
    (comp.security.misc)
  • Re: Connecting a remote workstation to a domain
    ... If you have more than a couple of remote workstations connecting to the SBS ... server via VPN, you really need to consider a Terminal Server in the main ... "Log in using a dial up connection" checkbox, ... roaming profile then synchronizes with the server over the VPN); ...
    (microsoft.public.windows.server.sbs)
  • Re: Connecting a remote workstation to a domain
    ... I can remotely join XP Pro computers at the remote ... connection" checkbox so that any user can logon remotely. ... "Log in using a dial up connection" checkbox, either way it loads her cached ... roaming profile then synchronizes with the server over the VPN); ...
    (microsoft.public.windows.server.sbs)

Quantcast