Perhaps one solution to reduce VPN risk levels is simply not to use them
in the first place. A lot of organizations are now making the
applications their users need available over the directly over the
internet with web browsers (e.g. e-mail).
Isn't it preferable to give users access to e-mail, or other common
apps, by web-proxy and only give VPN accounts to a handful of
administrators? Taken to its extreme, maybe tunneling IP traffic over
VPNs can be done away with altogether.
Is this a goal administrators should strive for?
Cheers,
Michael Surkan
P.S. I don't really have a strong opinion about this, I am just posing a
solution that I hear some administrators talk about.
_______________________________________________
firewall-wizards mailing list
firewall-wizards_at_honor.icsalabs.com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
Received on Feb 12 2005