Another RWW versus VPN question



Setup

SBS2003 SP1 Standard
Dual NIC
SonicWall TZ150 with IPS, Antispyware and Antivirus services running

Ports 25,443,444,1723 and 4125 open


I have a client that recently had a programmer from a large security based
company come by and demo the Access database he is working on for them.

During the meeting (which I was not at) he tells the employee that hired him
and the owner of the company that the current system is not very secure and
that he would never trust Microsoft to be responsible for the security of
remote access. His solution is a PIX firewall and VPN access.

My client has asked me to put in writing the differences between his
solution and our current solution.

I have been researching on the web and newsgroups but haven't found anything
that gives me any concrete info on RWW versus VPN besides RWW not allowing
full access to the network like VPN. i.e viruses infecting the network from
the remote client


Is a VPN tunnel more secure that SSL? 128 bit versus 256?

Is having the SBS box perform the authentication for access inherently less
secure than having a hardware device authenticate?

Does anyone know if my setup is compliant?



They deal in financial information and the Sarbans Oxley Act keeps getting
brought up

Sorry for all the questions but this is technically beyond my experience.


Thanks


John


.



Relevant Pages

  • Re: Another RWW versus VPN question
    ... A Pix does not ...by itself make you more secure. ... VPN "can" make you more insecure. ... I have a client that recently had a programmer from a large security based ...
    (microsoft.public.windows.server.sbs)
  • Re: Another RWW versus VPN question
    ... I have a client that recently had a programmer from a large security based company come by and demo the Access database he is working on for them. ... During the meeting he tells the employee that hired him and the owner of the company that the current system is not very secure and that he would never trust Microsoft to be responsible for the security of remote access. ... I have been researching on the web and newsgroups but haven't found anything that gives me any concrete info on RWW versus VPN besides RWW not allowing full access to the network like VPN. ...
    (microsoft.public.windows.server.sbs)
  • RE: Opinions required - GoToMyPc.com
    ... How does the VPN Concentrator provide access in the likes of PC-Anywhere to ... They already have a IPSec Client VPN solution on the FW-1, ... but much more secure would be the Cisco VPN ...
    (Security-Basics)
  • Re: Best practices for internal/external servers
    ... > We'll probably have to agree to disagree since I see the VPN (and I'm ... > IPSEC based VPN here) as being the more secure option. ... I don't disagree that a VPN pipe can more securely carry traffic. ... A client machine compromised with a virus, ...
    (comp.mail.imap)
  • [NEWS] Cisco VPN 5000 Client Multiple Vulnerabilities
    ... Multiple vulnerabilities exist in the Cisco Virtual Private Network (VPN) ... 5000 Client software. ... These vulnerabilities are documented as Cisco bug ID ... CSCdx17109 - MAC OS VPN 5000 Client password vulnerability ...
    (Securiteam)