Firewall Wizards mailing list archives

Re: Newbie VPN setup/configuration question


From: Tony Howlett <thowlett () netsecuritysvcs com>
Date: Thu, 18 Jul 2002 14:00:37 -0500

The only things that really matter in the below configuration are the sonicwall and the SMC Firewall. The more devices inbetween, the more difficult it is to troubleshoot (wireless LANs being a particularly fluky element) but they shouldnt affect the VPN communication if they are working properly. I took a quick look at SMCs website but all they offered was a single page on the IPSec capabilties so im not sure exactly what it does. It does give quite a bit of information on PPTP and i believe that the sonicwall can be configured to support PPTP but his work would have to agree to support a nonstandard configuration and may not want to do this.

An additional note you may want to think about (sorry to be the pessimist but security folks tend to be this way :-) , do you have WEP (encryption) enabled on your wireless access point? If you dont, then you may be offering a wide open path via an encrypted tunnel onto your husbands company's LAN. Even with WEP, its not perfect because its crackable but atleast you can make it hard for them.

An additional point of correction. Sonicwall offers a number of free client licences on the PRO200 series and up but on the smaller models (PRO100, SOHO, TELE) you have to pay the $75 bucks per machine. Or you can use one of the other client side solutions recommended previously.



Do you know anything about SMC's Barricade Plus($109)?  It's cheaper
than SonicWALL TELE3($500).

Here's the hardware setup I invision - will this work?

work LAN
  |
SonicWALL
  |
 ISP
  .
internet
  .
  |
ISP
  |
DSL Modem
  |
SMC7004ABR Broadband router (VPN passthrough)
  |
Home  LAN
  |        |        |
  |        |       WinXP Computer (TCP/IP)
  |      Linux Computer (TCP/IP)
SMC7004FW Broadband router (VPN IPSEC & PPTP)
  |
Wireless AP
  |
Wireless NIC
  |
Linux computer (TCP/IP) running 'vncviewer'

Kathy Bieltz


_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


Current thread: