Re: Location of VPN Server



So what are you saying? Put the VPN on the firewall, or drop firewall all
toghether?

"S. Pidgorny <MVP>" <slavickp@xxxxxxxxx> wrote in message
news:OdvWzNaTGHA.424@xxxxxxxxxxxxxxxxxxxxxxx
It has to be connected to the Internet on one interface and to the
internal network on another. Any additional firewalls, NATs etc. prove to
be unnecessary complexities and overengineering.

--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-

"Andy" <nes@xxxxxxxxxxxx> wrote in message
news:ulaPWhZTGHA.1576@xxxxxxxxxxxxxxxxxxxxxxx
Hi

If you where to set up a VPN Server, where would you typical place it?
I plan to set up a W2K3 server as a VPN server for out little network.
Should we locate it in the DMZ or could we safely located within our
internal LAN and only open the necessary ports to allow inbound
connection to it? We plan to use L2TP/Ipsec with digital certifictes.

/A.





.



Relevant Pages

  • RE: VPNs - Firewalls and Security
    ... You had configured that vpn users access internal network, ... modify your PIX Config, you have configured "crypto map match ... = redesign my network to either firewall the VPN connections or at a = ...
    (Security-Basics)
  • Re: PPTP vpn appears firewalled?!
    ... just that there is no mechanism from turning the firewall off. ... >>VPN seems 'firewalled'. ... > to allow VPN clients access to the internal network automatically. ...
    (microsoft.public.windows.server.sbs)
  • Re: VPN problem
    ... Whenever i ping my vpn server by netbios name it returns thr external ... MVP -- ISA Firewalls ... IP range used from the Internal Network that is as follows: ...
    (microsoft.public.isa.configuration)
  • Re: [fw-wiz] VPN concentrators
    ... It is nice though to be able to filter/log/monitor undesirable inbound VPN ... > firewall is redundant. ... >> Current best thinking is to terminate VPN tunnels inside an external ... >> entering the internal network. ...
    (Firewall-Wizards)
  • Re: PPTP thru SUSEfirewall
    ... VPN connections just fine that way. ... the firewall prevents traffic from flowing to the VPN ... Can you connect to port 1723 from ... Port 1723 TCP is set to forward to the VPN server. ...
    (comp.os.linux.networking)