Re: SMB Shares Dangerous?



Since a VPN connection effectively makes the machine that is
using VPN into a machine on your network, all considerations
apply that one normally has. As you note, there are malwares
that attempt to spread via share accesses (unc or mapped).

The difference of course is that you might have the machines
on your network more tightly controlled than those allowed to
obtain the VPN connection. The route presently used most
widely to address this difference is a quarantine network, also
spoken of as network access protection, so that the initial VPN
connection is to a restricted vlan until the connecting machine
has been validated as meeting the specified health/config checks.

Roger

"Brad Baker" <brad@xxxxxxxxxxxxx> wrote in message
news:OIBeY3uhHHA.4288@xxxxxxxxxxxxxxxxxxxxxxx
A number of our employees access our windows servers using either mapped
drives or UNC paths with vpn. I am somewhat concerned that accessing our
servers this way may pose a security risk as a number of viruses
proliferate through network shares.

The shares are password protected so users do have to authenticate to
access them but as far as I know once they have authenticated, their
credentials are cached for a period of time. Also with mapped drives in
particular I believe login information is saved permanently.

I'm wondering what others thoughts are on this matter and if anyone can
point me to any articles that confirm or deny the risk (or lack there of)
for using mapped drives and/or UNC paths. Finally if there is a risk, are
there other alternatives?

Thanks
Brad



.



Relevant Pages

  • Re: Problem with route add and VPN
    ... here is what i am tying to access the destination network: ... the vpn connection is disconnected and reconnected. ... When I add the route it will only add sucessfully if I specify the ...
    (microsoft.public.win2000.ras_routing)
  • Re: Remote Desktop from LAN not working
    ... the ISA Server policies that are created by the SBS ... I think your outbound VPN connection is not established properly ... On the Add Network Entities page, expand Networks, select Internal, ...
    (microsoft.public.windows.server.sbs)
  • Re: How to share folder on internet securely?
    ... Thanks for your suggestions (VPN or RWW) but I'm thinking that a SharePoint ... much trouble for the outside client to create the VPN Connection on his PC ... > 2) On the left pane, under Network Tasks, click Create a new connection. ...
    (microsoft.public.windows.server.sbs)
  • Re: Skype & VPN Blocks Internet Connections
    ... How do you connect thru the VPN? ... VPN connection then you need to check in the ... the remote network of the VPN. ... To VPN.and we are using skype as VOIP Solution to Make Long Distance ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: 2 NICs + Site-to-Site VPN + Http proxy = problem
    ... The Proxy's LAT must contain the address range of the remote network LAN ... address range in it the same way as the proxy. ... I configured a Site-to-Site VPN connection between this ...
    (microsoft.public.windows.server.networking)