Re: Solution

From: AD (ajd777_at_hotmail.com)
Date: 05/31/03


Date: Sat, 31 May 2003 06:38:32 +0100


Hi Chaps,

Thanks for both responses. I finally pursuaded the user to go for a
standalone pc on a dial-up link. This seemed the best course of action given
the requirements.

Thanks

Andy

"AD" <ajd777@hotmail.com> wrote in message
news:3ecd2f3e$0$7740$fa0fcedb@lovejoy.zen.co.uk...
> Hi All,
>
> We have a firewall on our internet gateway. One of our internal users
needs
> to connect to an external (customer) VPN server. I have been informed that
> UDP 500, IP 50 and IP 51 need to be allowed.
>
> I must stress that this is only so that an internal client can connect to
a
> customer VPN, we are not doing site to site VPN.
>
> What are the implications of setting this up? What do i need to be aware
of
> from a security perspective?
> What are the risks?
> What controls can we apply to protect our network from thiers?
>
> Many Thanks
>
> AD
>
>



Relevant Pages

  • Pix 506E IPsec site to site VPN Problem
    ... I am trying to set up two 506E Pix firewalls to use a Site to Site VPN. ... I can get that setup however afterwards my internet will stop working. ...
    (comp.dcom.sys.cisco)
  • Client to VPN tunnel
    ... We have a firewall on our internet gateway. ... to connect to an external (customer) VPN server. ... we are not doing site to site VPN. ...
    (comp.security.firewalls)
  • Client to VPN tunnel
    ... We have a firewall on our internet gateway. ... to connect to an external (customer) VPN server. ... we are not doing site to site VPN. ...
    (microsoft.public.win2000.security)
  • Re: Pix 506E IPsec site to site VPN Problem
    ... :I am trying to set up two 506E Pix firewalls to use a Site to Site VPN. ... :only route my VPN traffic over the VPN and all other over the internet? ...
    (comp.dcom.sys.cisco)
  • Re: Client to VPN tunnel
    ... You will be setting up a site-to-site VPN using your ... employee as the gateway into your network. ... > We have a firewall on our internet gateway. ... we are not doing site to site VPN. ...
    (microsoft.public.win2000.security)