Re: Security: VPN or RWW



In article <3641F358-2B88-428C-9272-1764A6B94867@xxxxxxxxxxxxx>,
gwdibble@xxxxxxxxxxxxxxxxxxxxxx says...
Generally speaking, RWW is more secure. VPN exposes the business network to
malware, etc. from the remote PC, where RWW does not.

Actually, VPN only exposes what you map through it, but most people map
ANY<>ANY in a VPN solution when they don't understand security.

We use VPN solutions and only permit TCP3389 to pass through them,
forcing the users to authenticate with the firewall with one
user/password that they have no control over and then their network
user/password for the terminal server or other.

We can also map a users access from the VPN to different network
services using the firewall user account.

So, many inexperienced people map all ports in a VPN, but there is
nothing that requires it, when using a real firewall/vpn solution.

--
- Igitur qui desiderat pacem, praeparet bellum.
- Calling an illegal alien an "undocumented worker" is like calling a
drug dealer an "unlicensed pharmacist"
spam999free@xxxxxxxxxx (remove 999 for proper email address)
.



Relevant Pages

  • Re: What am I missing? (Net View issues)
    ... assuming you can't map ip or hostname, do you have a firewall blocking the ... Networking, Internet, Routing, VPN, Anti-Virus, Tips & Troubleshooting on ... > The primary w2003 network is on the 16.0/255 subnet. ... I have been able to map to this particular ...
    (microsoft.public.windows.server.networking)
  • Need to have the VPN "host" behind NAT
    ... I have a client who has a corporate firewall located out of state. ... have been given permission to setup a VPN solution into the local ... problem that just occured to me is that a "router/firewall" with VPN ... I have a local subnet of 10.0.0.x and I want to setup a VPN into ...
    (comp.dcom.vpn)
  • Re: Windows CE browse network via VPN
    ... The guys at symbol tell me that it is becuase Windows mobile cannot map ... I have a VPN set up between our offices in VA and FL. ... BUT I am unable to map to a shared drive accross the VPN. ... connection but cannot access any network resources. ...
    (microsoft.public.windowsce.app.development)
  • RE: Secure Windows Domain auth for Cisco 2691 to Win2k or NT 4 Sever via Radius
    ... the dynamic VPN tunnels) into the static map you have set up for your static ... VPN tunnels. ... Anyway i setup a dynamic vpn pool ...
    (Security-Basics)
  • pix nat questions
    ... crypto map * 10 set peer * ... crypto map * 10 set transform-set 3des ... #using an acl that just tests tunnel from a host on net A, ... and i'm not clear on whether i should be using a nat statement to policy map the vpn traffic or a static. ...
    (comp.dcom.sys.cisco)