Re: PPTP or L2TP/IPSec?



Hi Al:

Very complicated subject with no simple answer. Security is always a cost benefit ratio, measured in either time, money, agro, or all of the above. I think your distrust of the SBS RWW is misplaced, and recommend it over VPN, but that is your call and your comfort level, as all of this discussion really.

MS ISA is a true software firewall, and one of the best. It gets a bum rap for living on the DC, as it does in SBS, and some will argue that it is less secure as a result. But if you do keep a strong pass phrase policy in place, and change them frequently, you are unlikely to be compromised. Manche$ter 3 Tottenh@m 2 Hurrah! is a strong pass phrase.

Beyond this, there are edge devices that will require incoming users to enter a (hopefully) second set of credentials before being offered a logon by your server, and there are token devices that require that you enter a second set of credentials at the RWW page before gaining access. Watchguard, Cisco, SonicWall and other offer the first, and http://www.scorpionsoft.com/ offers the second, specifically for the SBS space.

Regarding "attack of the password" given enough time and effort, any one device can be breached, or the financial insitutions, the defense departments, etc would not have such a difficult job. All you can hope for is to make it so difficult as to require the bad guys to look elsewhere. Frankly, I am not sure that the bad guys are specifically targeting "joe the plumber", or "larry the IT wiz" sites, so much as the drive by scanners who do it becuase they can hoping to find sites with "administrator" and pw = "admin" or, worse, no pw.

--
Larry
Please post the resolution to your
issue so that others may benefit.


"Al" <nospamplease@xxxxxxxxxxxxxxxxxx> wrote in message news:gln15a$qp$2@xxxxxxxxxxxxxxxxxxxx
SBS 2k3 R2 Premium site. Just need some pointers please as to the differences in real life between VPN protocols.
Small office with a couple of VPN sites into it. Currently PPTP but I would ideally like some form of token access (like RSA) but this is too expensive for the scale of site (unless there is an alternative version?); not too keen on web access (it just seems too open!) hence stuck with VPN.
We can filter the connections based on the IP of the site via the Router before it hits ISA so that creates an extra level ofsecurity (yes, I knowIP can be spoofed but attacker would have to know to try that), but as far as I can see thereafter the incoming client is authenticated based on their user name & password? Is my thinking correct at that point?
Does this not provide an opportunity for an attack of the password - I assume the answer there is to have strong passwords and to set eg 3 wrong password & locked out routines plus restrict which user accounts have VPN dial in allowed?
What I am wondering about beyond that, is whether L2TP gives anything beyond PPTP security wise? and in particular is it possible to have both the existing user name/password security backed up with eg a pre-shared password/passkey (in the absence of a RSA style revolving passkey)
Thanks


.



Relevant Pages

  • Re: Home office with WiFi: do I need Spotlock?
    ... Nobody will accidentally crack WEP. ... security. ... attack is that the "man in the middle" attack requires hearing both ... it appears that Spotlock is just a VPN ...
    (alt.internet.wireless)
  • Re: [Full-disclosure] Remote Desktop Command Fixation Attacks
    ... This set of steps is redundant in many places, and it's also enormously expensive, since you're using no less than three different expensive bits of networking hardware (AP, PIX, VPN Concentrator), in addition to a bunch of x86 server hardware, windows server licenses, and at least one ISA license. ... Your computers necessarily don't have full access to your network infrastructure when they aren't logged on, so GPOs, software updates, etc can't be applied at the times you want them to be applied. ... Turning on, enabling, and implementing every possible security setting and device you think of is not defence in depth, and will probably only have two effects - your users won't use your wireless network, and you'll burn so much cash you won't have any left to spend on *useful* security measures. ...
    (Full-Disclosure)
  • Re: Firewall advice required please
    ... 2./ How do you provide "SECURE" access without a VPN? ... suggesting you are achieving as-good-as security using a standard SSL, ... > and air-gap is the only product we carry. ... > no other firewall can touch. ...
    (comp.security.firewalls)
  • RE: Re: Secure Intranet?
    ... need to have a minimum level of security that is in line with your policies. ... Sygate has a product that does security policy enforcement for VPN called ... Sygate Secure Enterprise. ... Sygate Secure Enterprise Data Sheet ...
    (Security-Basics)
  • RE: VPNs - Firewalls and Security
    ... we turned off sysopt connection permit ipsec and then added the ... VPN connections. ... VPN's - Firewall's and Security ... You had configured that vpn users access internal network, ...
    (Security-Basics)