Is this totally un-secure?

From: Paul Kavanagh (pkavanagh_at_ntlworld.com)
Date: 01/31/04


Date: Sat, 31 Jan 2004 00:57:50 -0000

Today I setup my 1st VPN server using SBS2000 on a fixed IP ADSL connection
and it actually works! What I don't know is how secure it is. I've ran
audits using the securityspace.com standard audit service and it's found no
high or medium vulnerabilities.

A very loose overview of what I did is below:

Applied all service packs and critical updates. Installed & configured IIS
lockdown tool and URLScan. Setup RRAS to accept incoming VPN clients (5 x
l2tp ports), allowed vpnclients in ISA Server - disabled allow PPTP packet
filters. Installed Stand-alone CA with web enrollment enabled on SBS server
and set it so administrator has to approve all requests.

All of this has resulted in a working l2tp VPN! When connected if I look at
the connection status it says I am using L2TP/IPSEC with encryption.

I realise the above is very general but what I am looking for here is to see
if I've missed anything really really important.

All comments are very welcome (though go easy, I'm just amazed the bloody
thing worked!)

Cheers,

Paul.



Relevant Pages

  • RE: VPN issue on SBS2003
    ... I understand that you encountered VPN connection issue when you use VPN to ... Internet clients or VPN to external VPN Server from SBS Client computers? ... Configure E-mail and Internet Connection Wizard ... Total GRE packets sent = 1 ...
    (microsoft.public.windows.server.sbs)
  • RE: PPTP VPN connection problems
    ... The problem is that the VPN does not disconnect. ... However after some idle period I can not send packets across the connection. ... A ping to the server would result in "Request timed out". ... If I connect with the VPN client locally to the internet ...
    (microsoft.public.windows.server.sbs)
  • Re: VPN Ports to Open
    ... the VPN connection after you change the firewall before SBS. ... On the server, please stop the Routing and Remote Access service. ... Total GRE packets sent = 1 ...
    (microsoft.public.windows.server.sbs)
  • Re: Windows 2003 VPN Default Gateway Issues
    ... Ethernet adapter Local Area Connection: ... If the VPN server is configured to use a static IP address ... the default gateway on the client is not the problem. ...
    (microsoft.public.windows.server.networking)
  • RE: VPN Connectivity issues through LAN
    ... I understand that you cannot ping SBS after ... you can establish VPN connection from the remote LAN. ... You have to rerun the CEICW to make sure your SBS 2003 server have right ...
    (microsoft.public.windows.server.sbs)