Re: Site-to-site VPN to client, good idea?
- From: Newell White <NewellWhite@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Date: Fri, 7 Nov 2008 00:35:01 -0800
"ac130" wrote:
Phillippe,If you terminate the VPN connection in your Pix firewall then access is not
Thank you for taking the time to answer my questions. Your post validated my
concerns about creating the site to site vpn to our client. We've actually
discussed a scenario similar to your second suggestion and we're probably
going to implement something similar.
Again thanks for your input and by the way, your English is perfectly fine :)
"Philippe Gillet [CISSP-CISA-CISM]" wrote:
Hi,
Indeed it is the main problem with Site to Site VPN. This is often done in
the context of a company with many offices in many countries.
In that case, the security policy is the same for the company and they can
control what is done with multiple access control software, logs ,etc...
In your case, you give a complete access to your LAN to the other company.
Yes, you open the door, clearly !
You have 3 solutions:
--> you make an agreement where you state that they will be monitored, they
will have to respect your security policy, etc... You can monitor their
potential fraudulent activities with an IDS for example.. to be sure to
detect viruses, hacking, etc...
The main problem with that is the reaction time: You will act after the
problem happens.... not before.
--> You restrict their VPN and redirect them to a VLAN or isolated private
LAN, and enforce an ACL that will only permit them to make file transfer and
RDP for example.
--> You don't make a Site-to Site VPN. You allow them to use FTP + RDP +
others if necessary ( it's better to use sftp or scp...) to get the files.
but you have to create a server with a ftp server or equivalent and make the
Port address translation on your PIX.
The choice is yours. (don't choose the first if possible...)
+++
Excuse my bad english writing ;-(
necessarily wide open.
You can configure the Pix to restrict the range of IP addresses in your LAN
that the VPN connection can access.
I forget the exact details but I learnt this and implemented it when setting
up 'split-tunnelling' in this context some years ago.
A search on this term + 'Cisco Pix' should get you some info.
--
HTH,
Newell White
.
- Follow-Ups:
- Re: Site-to-site VPN to client, good idea?
- From: Anteaus
- Re: Site-to-site VPN to client, good idea?
- References:
- Site-to-site VPN to client, good idea?
- From: ac130
- Re: Site-to-site VPN to client, good idea?
- From: Philippe Gillet [CISSP-CISA-CISM]
- Re: Site-to-site VPN to client, good idea?
- From: ac130
- Site-to-site VPN to client, good idea?
- Prev by Date: Re: Site-to-site VPN to client, good idea?
- Next by Date: Kaspersky notes, Firefox crashing
- Previous by thread: Re: Site-to-site VPN to client, good idea?
- Next by thread: Re: Site-to-site VPN to client, good idea?
- Index(es):
Relevant Pages
|