Firewall Wizards mailing list archives
RE: VPN concentrators
From: "R. DuFresne" <dufresne () sysinfo com>
Date: Tue, 27 Aug 2002 21:38:32 -0400 (EDT)
On Wed, 28 Aug 2002, Crispin Harris wrote: [SNIP]
My personal preference is to have a policy enforcement system between the VPN Terminator and the internal networks. This is mostly because I don't trust that the traffic INSIDE the VPN is as clean as it cold be. Much of this is because I am a paranoid SOB, who is aware that the easiest (and often cheapest) ways to break a network are _NOT_ through the firewall: - Steal the CEO/CFO/CTO's laptop. - Break-in to the CEO/MIS' house and use the "Fully Authenticated, Encrypted" VPN. - Bribe the secretary. - Break in to a partner organisation who has a useless firewall/VPN security setup.
These days, there's perhaps one more area even less secure and a better route for attacking; The wireless network. It's often fully exposed and unencrypted, even in those environments that know better from the wired end. And, one can gain in places totally free and annonymous wireless access into the internet from which to probe and attack others from, but, this is an additional side issue to the wirelss side attack on a company... Thanks, Ron DuFresne -- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ admin & senior security consultant: sysinfo.com http://sysinfo.com "Cutting the space budget really restores my faith in humanity. It eliminates dreams, goals, and ideals and lets us get straight to the business of hate, debauchery, and self-annihilation." -- Johnny Hart testing, only testing, and damn good at it too! _______________________________________________ firewall-wizards mailing list firewall-wizards () honor icsalabs com http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
Current thread:
- Re: VPN concentrators, (continued)
- Re: VPN concentrators Patrick Darden (Aug 28)
- RE: VPN concentrators Ben Nagy (Aug 29)
- RE: VPN concentrators Schouten, Diederik (Diederik) (Aug 26)
- RE: VPN concentrators Patrick Darden (Aug 26)
- RE: VPN concentrators Schouten, Diederik (Diederik) (Aug 26)
- RE: VPN concentrators Crispin Harris (Aug 26)
- RE: VPN concentrators Patrick Darden (Aug 27)
- RE: VPN concentrators Brian Ford (Aug 27)
- RE: VPN concentrators Schouten, Diederik (Diederik) (Aug 27)
- RE: VPN concentrators Crispin Harris (Aug 27)
- RE: VPN concentrators R. DuFresne (Aug 27)
- RE: VPN concentrators Crispin Harris (Aug 27)
- RE: VPN concentrators Crispin Harris (Aug 29)
- RE: VPN concentrators Patrick Darden (Aug 29)
- RE: VPN concentrators Nilesh Chaudhari (Aug 29)
- RE: VPN concentrators R. DuFresne (Aug 29)
- RE: VPN concentrators Nilesh Chaudhari (Aug 30)
- RE: VPN concentrators Patrick Darden (Aug 29)