Re: ISA firewall problem?



Jim Magee wrote:

>
> In split-tunnel mode, it's possible for the remote machine to act as if
> it were a router. Information can flow to/from the internet, and can
> then in turn flow to/from your LAN, and vice versa.
>
> Without the split tunnel, there can be no flow to/from the internet
> (other than through SBS and controlled by ISA).
My understanding is that if the remote machine is compromised to the
point where it is acting as a router or proxy, this doesn't go away when a single tunnel VPN is invoked. The compromised machine would still be accessible from the internet.

The point is that in split-tunnel mode, it's automatically capable of transferring information between networks, without any compromise.

Without a split-tunnel, unless the TCP/IP stack itself has been compromised, the internet connection is effectively broken.


-- Steve Foster [SBS MVP] --------------------------------------- MVPs do not work for Microsoft. Please reply only to the newsgroups. .



Relevant Pages

  • Re: PPTP VPN Startup Connect
    ... >> be on your machine or on the remote machine. ... >> keep the Internet connection on your machine. ... he is in a different location we had to set up the VPN to share files. ...
    (comp.dcom.vpn)
  • Re: Sygate Personal Firewall
    ... >Sygate personal firewall is running on the host machine. ... >is that for the remote machine to see the Internet, I have to set Sygate to ... >machine is being used to access the internet. ...
    (comp.security.firewalls)
  • Re: Firewall Configuration Fails
    ... Did you enable Outlook over the Internet in CEICW? ... No the certificate is not installed on my remote machine. ...
    (microsoft.public.windows.server.sbs)
  • Re: PPTP VPN Startup Connect
    ... >Off course you open the vpn connection through the internet. ... You should *only* be able to access the remote machine (and ...
    (comp.dcom.vpn)
  • Re: 0.0.0.0 Probes
    ... > packets from saturating the whole Internet.) ... Thank you for the correction. ... flow seems, at first glance, to be in conflict with each other, and is likely ...
    (Security-Basics)