Firewall Wizards mailing list archives

Re: Opinions on VPN?


From: myles <myles () tenhand com>
Date: Wed, 28 Apr 1999 21:52:50 -0700

Robert Graham wrote:

Has anyone considered time-disjoint attacks via VPNs?

For example, most home VPN users today use the same machine for both Internet access and corporate
access via the VPN. Now VPN vendors try to lock out normal Internet traffic while connected via
the VPN, but the user can be hacked at other times.

Of course if your users are using laptops in the office & taking them home & on the road, you
already  have this problem.

IFF your users are allowed to connect to your internal network and are
blocked from internet access at the same time, you may be safe. This might actually be a rationale
for having users use the corporate firewall
for internet traffic  even though they're connected directly to the internet.  Slow, but  possibly
secure from netbus & co.



Current thread: