Re: sFTP compared with FTP via VPN

From: Chris Calabrese (chris_calabrese_at_yahoo.com)
Date: 04/28/04


Date: 28 Apr 2004 06:32:04 -0700

FTP via VPN:
  o Good protection for the portion of the network actually
    covered by the VPN
  o No protection for portion not covered by the VPN (for example, if
    using site-to-site VPN, traffic will not be protected in each
    organization's internal networks)
  o Need to setup VPN

SFTP
  o Good protection for all traffic
  o Need to have SFTP software (but available for free - www.openssh.org,
    http://www.chiark.greenend.org.uk/~sgtatham/putty/download.html)

FTP with PGP-encrypted files
  o Protection not only for data in transit, but also at rest
  o Non-repudiation based on digital signautres, which offer higher
    legal protection than server logs
  o Need to install/configure/program PGP software on both ends



Relevant Pages

  • Re: [fw-wiz] risk level associated with VPNs?
    ... the VPN terminates. ... But when the remote system has less protection, ... don't care if the VPN client software makes sure the current connection is ...
    (Firewall-Wizards)
  • RE: [fw-wiz] risk level associated with VPNs?
    ... Our VPN connections pass via the same checking systems when they connect ... Now we assume, repeat assume, the VPN machines are adequately protected ... The protection services inside the network are doing their job. ...
    (Firewall-Wizards)
  • Re: Protecting an open VPN connection from a local home LAN
    ... lower case, 1 upper case, one special character and one number. ... I took a screen capture and then locked out the VPN. ... > I have taken an old PC (Win98) and turned it into a VPN gateway to my LAN. ... > Do you think this is unwarranted protection, not enough protection, or ...
    (alt.computer.security)
  • Re: Protecting an open VPN connection from a local home LAN
    ... >> my VPN listening service. ... I have set up the Win98 box ... >> Do you think this is unwarranted protection, not enough protection, ... even with a respectable software firewall. ...
    (alt.computer.security)
  • Re: Connecting to Multiple networks
    ... I would not rely on NAT as a layer of protection between the public domain ... >> NAT and Firewall How to Setup Network, Internet Sharing, Remote Access ... and VPN Step by Step Guide ... ...
    (microsoft.public.win2000.networking)