Security Basics mailing list archives

Re: How safe is a VPN connexion from within an internal network?


From: "Michal Merta" <michal.merta () gmail com>
Date: Tue, 21 Nov 2006 10:26:48 +0100

Hi Pierre,

it depends on client vpn policy. If you enable split tunneling it's
not safe, but if you disable it (it means that all the traffic is
going to the tunnel) its not security risk.
Regards, Michal

On 11/20/06, PIERRE.DUFRESNE () mess gouv qc ca
<PIERRE.DUFRESNE () mess gouv qc ca> wrote:
Hi all!

I have been asked to install a vpn client on a workstation inside our
network that would access another network through our firewall.
Besides the technical details of allowing IPSec traffic through a NATed
device,  I was wondering how safe is this practice? Is it done often?
Once the connexion is established, can a host on the external network
access the workstation inside my network, ie initiate a connexion?
Should I rather go with a "site to site" vpn connexion?

Thanks for your time

Pierre


---------------------------------------------------------------------------
This list is sponsored by: Norwich University

EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The NSA has designated Norwich University a center of Academic Excellence
in Information Security. Our program offers unparalleled Infosec management
education and the case study affords you unmatched consulting experience.
Using interactive e-Learning technology, you can earn this esteemed degree,
without disrupting your career or home life.

http://www.msia.norwich.edu/secfocus
---------------------------------------------------------------------------




--
Michal Merta
Network Security Engineer
http://www.misuta.cz

The information contained in this electronic message and any
attachments to this message are intended for the exclusive use of the
addressee(s) and may contain proprietary, confidential or privileged
information. If you are not the intended recipient, you should not
disseminate, distribute or copy this e-mail. Please notify the sender
immediately and destroy all copies of this message and any
attachments.

---------------------------------------------------------------------------
This list is sponsored by: Norwich University

EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The NSA has designated Norwich University a center of Academic Excellence in Information Security. Our program offers unparalleled Infosec management education and the case study affords you unmatched consulting experience. Using interactive e-Learning technology, you can earn this esteemed degree, without disrupting your career or home life.

http://www.msia.norwich.edu/secfocus
---------------------------------------------------------------------------


Current thread: