Firewall Wizards mailing list archives
RE: Radius access from provider to internal MS ISA Server
From: "Bill Royds" <broyds () rogers com>
Date: Sat, 6 Jul 2002 11:17:19 -0400
McAffee's E-Policy Orchestrator (EPO) is a push technology for updating anti-virus and other security products on desktops. It can be configured to work over VPN tunnels as well as LANS so it can ensure that home users are up-to-date when they connect to the office LAN. It is used on our network and it works quite well, although it does require monitoring. It also allows central monitoring of anti-virus scanning so management has an immediate report if any virus infected desktops are found. But it still depends on an agent on each receiving desktop and is not fully integrated with VPN products to ensure that updates are complete before the VPN connection is completed. It would really be nice of there were an integrated VPN/Personal Firewall/Anti-virus/Authentication scanner product available (preferably with hardware assist for NIC control and encryption). If it were a replacement for the TCP/IP stack, it would prevent subversion and would be much faster. -----Original Message----- From: firewall-wizards-admin () honor icsalabs com [mailto:firewall-wizards-admin () honor icsalabs com]On Behalf Of R. DuFresne Sent: Sat July 06 2002 02:56 To: Ben Nagy Cc: 'Christoph Steigmeier'; firewall-wizards () honor icsalabs com Subject: RE: [fw-wiz] Radius access from provider to internal MS ISA Server On Fri, 5 Jul 2002, Ben Nagy wrote: [SNIP]
So, this sounds like you're doing some sort of PPTP/L2TP/L2F type thing with the actual layer-2 dialup stuff. Normally that stuff comes in on a private link, I've seen it most when it's aggregated into a single frame-relay link the from ISP concerned. That has big advantages, in your situation, in that users cannot access the Internet directly and also concurrently access your internal network. (I don't need to go into why that's a good thing, I presume..) The only reason I type all this out is that the bit you mention later about the engineers claiming that the firewall offers enough protection raised a doubt in my mind as to whether the forwarded connections really were getting tunneled or whether it was just some strange authentication only forwarding scheme, which wouldn't appear to have much value. If the users can directly access the Internet from the ISP they're connected to, then IMO you're really wasting your time and you should just use the VPN gateway to do all your auth - it's stronger, better, faster and all that jazz.
My question on VPN tunnels in particular is; how many force all
communication out via the VPN, restricting access via other potential
internet'able pathways? The reason I ask is, it seems one of the issues
with especially home users accessing work servers would be pushing a
security policy through the VPN, preventing such things as viri and
trojans and other malicious activity from gaining a foothold and running
up the trusted tunnel into the workplace while the home user is connected
to work systems and servers.
How do others push their security policies to their home users in these
scenarios in a concurrent manner? Is it possible? Or is this just an
open trust scenario?
Thanks,
Ron DuFresne
--
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
admin & senior security consultant: sysinfo.com
http://sysinfo.com
"Cutting the space budget really restores my faith in humanity. It
eliminates dreams, goals, and ideals and lets us get straight to the
business of hate, debauchery, and self-annihilation."
-- Johnny Hart
testing, only testing, and damn good at it too!
_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
Current thread:
- RE: Radius access from provider to internal MS ISA Server, (continued)
- RE: Radius access from provider to internal MS ISA Server Paul Robertson (Jul 05)
- Re: Radius access from provider to internal MS ISA Server Kyle R. Hofmann (Jul 05)
- Re: Radius access from provider to internal MS ISA Server Paul Robertson (Jul 05)
- RE: Radius access from provider to internal MS ISA Server Ben Nagy (Jul 07)
- RE: Radius access from provider to internal MS ISA Server Paul Robertson (Jul 07)
- RE: strong passwords (was Radius/MS ISA stuff) Ben Nagy (Jul 08)
- RE: strong passwords (was Radius/MS ISA stuff) Paul Robertson (Jul 08)
- Re: strong passwords (was Radius/MS ISA stuff) Barney Wolff (Jul 08)
- RE: strong passwords (was Radius/MS ISA stuff) Bill Royds (Jul 08)
- RE: Radius access from provider to internal MS ISA Server R. DuFresne (Jul 06)
- RE: Radius access from provider to internal MS ISA Server Bill Royds (Jul 06)
- RE: Radius access from provider to internal MS ISA Server Ben Nagy (Jul 07)
