Re: VPN Question

From: Bernie M (while_up_late@night)
Date: 10/16/02


From: "Bernie M" <while_up_late@night>
Date: Wed, 16 Oct 2002 18:40:53 +1000


"Mesomorf" <newsgroup@only.please> wrote in message
news:SU7r9.1824$hV3.79896@newsb.telia.net...
> > If the remote user had their own router/firewall then, yes, security is
> > increased but how responsible is the remote user going to be? Do they
> > really know how to configure and then check that the router/firewall is
> > secure?
>
> Well, let me quote Jeff Grossman (author of this thread):
> "I am going to use the Linksys VPN router at the remote sites"
>
> ..so they WILL be behind router/firewall..and I guess he will configure
all
> remote sites (offices i guess) so the security will be there.
>
> And I know alot companys (small companys) that use Linksys product on the
> office to connect to Internet ..so that is why I am talking about "same
> security" on VPN and local office.
>
> > Lockdown the PC while the VPN is active ... better safe than sorry.
>
> .but I canīt say that I dissagre with you Bernie.. better safe than sorry
:)
>
> --
> Johan Tuneld
>
> Your Guide To Filetransfer Fix for ICQ 2001/2002
> And a complete guide of Gateway / Firewall configuration for all ICQ
clients
> http://www.tuneld.com
>
>

This week I've been attending a course on VPN deployment (run by Verisign)
and while I'm thinking along the right lines there are *best practice*
methods to help safeguard the company LAN. Others may have more experience
and exposure to this but what we spoke about today was exactly this
scenario.

Allowing people to browse while also having a VPN directly into a company
LAN does present risks but these can be reduced by ensuring the firewall
strictly controls what the VPN clients can access inside the company LAN
(remembering the VPN should be terminated on the outside of the firewall).
It has been seen where the VPN termination point was internal to the LAN
itself and the firewall had absolutely no idea what the client was
accessing. This should be avoided at all costs.

If browsing is to be allowed, it's *strongly* recommended to control what
sites they can go to while the VPN in up. There are malicious sites out
there that you really don't want people to connect to.

A packet filter router/firewall will go a long way to protect the PC against
hostile traffic incoming on blocked ports but isn't aware of what's being
sent through an established TCP session with a web site.

I don't mean to sound alarmist or paranoid but I hope my concerns have at
least raised awareness of the dangers involved. It's so common to hear
people say that "there's nothing to worry about ... we're using a VPN".

BernieM



Relevant Pages

  • Re: VPN Question
    ... > If the remote user had their own router/firewall then, yes, security is ... "I am going to use the Linksys VPN router at the remote sites" ... remote sites so the security will be there. ...
    (comp.security.firewalls)
  • Re: VPN Question
    ... >> If the remote user had their own router/firewall then, yes, security is ... > remote sites so the security will be there. ... > security" on VPN and local office. ...
    (comp.security.firewalls)
  • Re: [Full-disclosure] Remote Desktop Command Fixation Attacks
    ... This set of steps is redundant in many places, and it's also enormously expensive, since you're using no less than three different expensive bits of networking hardware (AP, PIX, VPN Concentrator), in addition to a bunch of x86 server hardware, windows server licenses, and at least one ISA license. ... Your computers necessarily don't have full access to your network infrastructure when they aren't logged on, so GPOs, software updates, etc can't be applied at the times you want them to be applied. ... Turning on, enabling, and implementing every possible security setting and device you think of is not defence in depth, and will probably only have two effects - your users won't use your wireless network, and you'll burn so much cash you won't have any left to spend on *useful* security measures. ...
    (Full-Disclosure)
  • Re: Firewall advice required please
    ... 2./ How do you provide "SECURE" access without a VPN? ... suggesting you are achieving as-good-as security using a standard SSL, ... > and air-gap is the only product we carry. ... > no other firewall can touch. ...
    (comp.security.firewalls)
  • RE: Re: Secure Intranet?
    ... need to have a minimum level of security that is in line with your policies. ... Sygate has a product that does security policy enforcement for VPN called ... Sygate Secure Enterprise. ... Sygate Secure Enterprise Data Sheet ...
    (Security-Basics)

Quantcast