Security Basics mailing list archives

RE: How safe is a VPN connexion from within an internal network?


From: "Patton Roub" <proub () dci wyo gov>
Date: Tue, 21 Nov 2006 09:28:58 -0700

Your biggest problem will be that with a tunnel originating behind your
firewall, all the tunnel traffic through your firewall is encrypted and
unavailable for inspection.  A site to site tunnel would be much better
as then you can apply rules of access, etc.

Regards

Patton J Roub


-----Original Message-----
From: listbounce () securityfocus com [mailto:listbounce () securityfocus com]
On Behalf Of PIERRE.DUFRESNE () MESS GOUV QC CA
Sent: Monday, November 20, 2006 9:47 AM
To: security-basics () lists securityfocus com
Subject: How safe is a VPN connexion from within an internal network?

Hi all!

I have been asked to install a vpn client on a workstation inside our
network that would access another network through our firewall.
Besides the technical details of allowing IPSec traffic through a NATed
device,  I was wondering how safe is this practice? Is it done often?
Once the connexion is established, can a host on the external network
access the workstation inside my network, ie initiate a connexion?
Should I rather go with a "site to site" vpn connexion?

Thanks for your time

Pierre 


------------------------------------------------------------------------
---
This list is sponsored by: Norwich University

EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The NSA has designated Norwich University a center of Academic
Excellence 
in Information Security. Our program offers unparalleled Infosec
management 
education and the case study affords you unmatched consulting
experience. 
Using interactive e-Learning technology, you can earn this esteemed
degree, 
without disrupting your career or home life.

http://www.msia.norwich.edu/secfocus
------------------------------------------------------------------------
---


---------------------------------------------------------------------------
This list is sponsored by: Norwich University

EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The NSA has designated Norwich University a center of Academic Excellence
in Information Security. Our program offers unparalleled Infosec management
education and the case study affords you unmatched consulting experience.
Using interactive e-Learning technology, you can earn this esteemed degree,
without disrupting your career or home life.

http://www.msia.norwich.edu/secfocus
---------------------------------------------------------------------------


Current thread: