Firewall Wizards mailing list archives

RE: VPN concentrators


From: "Schouten, Diederik (Diederik)" <dschout () lucent com>
Date: Mon, 26 Aug 2002 17:02:04 +0200



Depending on your VPN setup it can.  Many vpn switches allow 
you to push security configurations upon clients.

Exactly, depending on the ocncentrator.

Therefor, unless you can control what traffic goes into the tunnel at
the
remote end, you should still firewall the traffic that comes out of the
tunnel at your end.

Nope.  I agree that the other end should have minimum standards of
security set up--i.e. antivirus software/signature that is X days old,
firewall, yadda yadda.  However, the more important thing is not what
goes into the tunnel, but what comes out.  If you are the concentrator,
then you control what comes out without need of an extra firewall.  VPN
switches ARE firewalls.

Then we still agree... if your VPN-Concentrator can enforce your security
Policy, you're not just terminating VPN's, the VPN firewalling is already
done in the concentrator.

Depending on the internals of the firewall, I'd say it is just as safe
to
terminate the VPN in a DMZ as it is to terminate it in the Firewall.

Agreed.  Less useful, but just as safe....

:)

Terminating the VPN parrallel to the firewall, completely bypassing your
Security Policy is a definite NO.

It doesn't bypass the security policy, it enforces it.

So in lamens terms, it's a Firewall just for VPN-ed traffic.

Therefore the real strength of this setup is more the VPN throughput, and
the fact that the VPN does not cause stress on your normal firewall.

Sure, keep them separated, if them together are just as easy to manage a
single box Firewall/VPN Gateway solution.

Greetings,

        Diederik
_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


Current thread: