Penetration Testing mailing list archives
RE: Security and VPN
From: "Petreski, Samuel" <samuel-petreski () uiowa edu>
Date: Tue, 19 Jun 2007 08:28:52 -0500
One product that offers some of the requirements for your deployment is FirePass by F5 (http://www.f5.com/products/FirePass/). There are also many other products which offer similar capabilities. General rule of thumb, never trust the end user to do what you tell them to do. --Samuel Samuel Petreski Sr. Security Analyst CIO Office University of Iowa -----Original Message----- From: listbounce () securityfocus com [mailto:listbounce () securityfocus com] On Behalf Of Sohail Sarwar Sent: Monday, June 18, 2007 8:08 AM To: James Patterson; pen-test () securityfocus com Cc: holstein.robert () bls gov Subject: Security and VPN Hi there, I just wanted to put this out there. How secure is VPN. Meaning, if my users take home the client and install it on their desktop at home, and connect to the corporate network and production network, wheat are we really looking at. Are they secure or not. Two factor authentication would only help the authentication purpose and to protect the user name and password ? How about restricting them to access, and how about worrying about their home computer that can be effected. Has anyone been through this. Any one give home users a list of requirements that they must have before vpn can be offered to them ? Should there be some type of desktop policy installed on their home computer, just to protect the company network ? Any help and guidance would be great Regards, Sohail ------------------------------------------------------------------------ This List Sponsored by: Cenzic Are you using SPI, Watchfire or WhiteHat? Consider getting clear vision with Cenzic See HOW Now with our 20/20 program! http://www.cenzic.com/c/2020 ------------------------------------------------------------------------
Attachment:
smime.p7s
Description:
Current thread:
- Re: Security and VPN, (continued)
- Re: Security and VPN Robin Wood (Jun 20)
- Re: Security and VPN Ben Nell (Jun 20)
- RE: Security and VPN Russell Butturini (Jun 21)
- Re: Security and VPN Kurt Buff (Jun 22)
- Re: Security and VPN Matthew Leeds (Jun 19)
- Re: Security and VPN Robert Hagen (Jun 19)
- Re: Security and VPN Thor (Hammer of God) (Jun 19)
- RE: Security and VPN Stong, Ian C CTR DISA GIG-CS (Jun 19)
- RE: Security and VPN Shenk, Jerry A (Jun 19)
- RE: Security and VPN Jessie Ling XX (MC/EPA) (Jun 19)
- RE: Security and VPN Petreski, Samuel (Jun 19)
- Re: Security and VPN Sat Jagat Singh (Jun 22)