Re: Security of a Windows 2003 VPN Question



There is an option in VPN wizard to start static packet filters on VPN
enabled interface. They allow only selected VPN traffic to pass thru VPN
enabled interface.
If you don't find it good enough, you can always create IPSec policies.
Patching and hardening before connecting to the public network is a must.


--

************************
Best regards
Dejan
************************


"NOSPAMsmorzandoAT@xxxxxxxxxxx"
<NOSPAMsmorzandoAThotmailcom@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:88C2EF13-9733-4E6F-BE32-8E7BE9312E92@xxxxxxxxxxxxxxxx
How secure is Windows 2003 VPN? I understand the data transmission
encryption, but I'm curious about the security of the network. When one
installs the VPN on an standalone 03 server one has to shut off the
Windows
firewall service.

Due to minimal resources , I would like to not have to install a hardware
firewall and have the Win2k3 server, running only the VPN, hook directly
into my domain controller, which runs AD, etc. (Due to our network, the DC
has a firewall on it.)

Is this safe at all? Is the Win2k3 VPN box vulnerable? Could I run a
software firewall on Win2k3 VPN box to take the place of Windows
firewall,
which apparently can't run?

What would the ISA server do for me, if I could afford it.

Thanks!


.



Relevant Pages

  • RE: Sandboxing
    ... the 3Com Embedded Firewall would be extremely useful and enabling (in ... your case) when you look at it in a VPN context. ... This security policy will accomplish quite a few things: ... During the Policy Server installation, ...
    (Focus-IDS)
  • Re: VPN Firewall for new webserver
    ... > I'm setting up a webserver at a colocation and I need to put a VPN ... You're not going to get a quality firewall for that amount, ... and D-Link makes a DI-804HV unit ... users access to the SQL server, let them do it through a VPN session. ...
    (comp.security.firewalls)
  • Re: Firewall Info/Recommendations?
    ... I would seriously consider an air-gap solution. ... Let me outline a few features that no other firewall can touch. ... Provide secure access without a VPN from any web browser (this greatly ... > manageable without much higher-level support if you want things like ...
    (comp.security.firewalls)
  • Re: [fw-wiz] Integrated IDS/IPS/Firewall (Cisco ASA and Juniper ISG)
    ... complexity and architectural inelegance of having 3-5 gateway security ... VPN) convinced me to eventually champion a migration to Symantec's SGS ... Nice balance of "default deny" at the firewall, ...
    (Firewall-Wizards)
  • Re: two winxp home machines, varied results
    ... >The only firewall I have on my machine *aside* from the Cisco VPN ... Please don't change "restrictAnonymoussam", only ... >Here is the IPCONFIG and BROWSTAT listings for each machine. ...
    (microsoft.public.windowsxp.network_web)