Re: ISA firewall problem?
- From: Jim Magee <yanxandnix@xxxxxxxxxxxxxxxxx>
- Date: Sat, 23 Apr 2005 16:00:24 -0400
Steve Foster [SBS MVP] wrote:
My understanding is that if the remote machine is compromised to the point where it is acting as a router or proxy, this doesn't go away when a single tunnel VPN is invoked. The compromised machine would still be accessible from the internet.Jim Magee wrote:
Steve Foster [SBS MVP] wrote:
> Jim Magee wrote:
>
>> - Double-click on Network Connections
>> - Right-click on your VPN Connection
>> - Click on Properties
>> - Click on Networking
>> - Highlight Internet Protocol (TCP/IP)
>> - Click on Properties
>> - Click on Advanced
>> - Uncheck use default gateway on remote network
>
>
> Not a good idea, since this allows the remote machine to be a back-door
> into your network. This should only be used if you're absolutely
certain
> of the security of the remote machine.
>
I'm not disagreeing with you, but I would like you to explain further
how this is any more of a security threat. My understanding is that it only affects the outbound traffic of the remote machine. If the security of the remote machine is compromised, access to the internal network via the VPN is at risk regardless of the gateway setting, no? Again, I'm not disagreeing with you. I'm just looking for clarification. I usually use this setting when connecting to some of my clients that have a slower link than my cable internet connection.
In split-tunnel mode, it's possible for the remote machine to act as if it were a router. Information can flow to/from the internet, and can then in turn flow to/from your LAN, and vice versa.
Without the split tunnel, there can be no flow to/from the internet (other than through SBS and controlled by ISA).
It probably won't be long before someone writes a trojan that attacks VPN connections, and possibly makes the required changes to permit split-tunnelling anyway. With RWW, there's less need for VPN, and that's probably the way to go where possible.
Agreed.
.
- Follow-Ups:
- Re: ISA firewall problem?
- From: Steve Foster [SBS MVP]
- Re: ISA firewall problem?
- References:
- ISA firewall problem?
- From: Torrey Lauer
- Re: ISA firewall problem?
- From: Jim Magee
- Re: ISA firewall problem?
- From: Steve Foster [SBS MVP]
- Re: ISA firewall problem?
- From: Jim Magee
- Re: ISA firewall problem?
- From: Steve Foster [SBS MVP]
- ISA firewall problem?
- Prev by Date: Re: Clients Stuck in " Applying Computer Settings"
- Next by Date: Re: assigning a user to a client computer
- Previous by thread: Re: ISA firewall problem?
- Next by thread: Re: ISA firewall problem?
- Index(es):
Relevant Pages
|