Virtual Private Networks
Home > Ask the Windows Security Experts > Ask the Experts Archives, Inactive Questions & Answers > Tackling VPN security without firewalls
Ask The Windows Security Expert: Questions & Answers
EMAIL THIS

Tackling VPN security without firewalls

Roberta Bragg EXPERT RESPONSE FROM: Roberta Bragg

Pose a Question
Other Windows Security Categories
Meet all Windows Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 29 October 2003
With this latest round of worms it became apparent that our biggest exposure was NOT our front door (the firewall), but rather the back door (laptops brought in from vendors/home, VPN users without firewalls). How are most organizations tackling the issue of protecting those devices? We've tried to mandate antivirus software and firewalls, but how can we technically force compliance?

>
EXPERT RESPONSE
Ah, here's the six million dollar question. Do you remember when most viruses were spread by floppy disks from home or other offices? We tried implementing stations at which everyone had to go and scan their disks before they could be used. Sometimes the station became infected and gave clean floppies viruses. It was an impossible task, and finally, we just eliminated the floppy drives on desktop computers.

Some companies I know are requiring that laptop computers be scanned before use (another impossible task). Others are attempting to use personal firewalls on laptops to prevent worms from leaving infected computers.

I don't know of a 100% sure technical control. (How can you prevent the laptop user from finding a network port and plugging in his laptop?) We've spent decades getting wired access everywhere, but how much of it do we really control? But one idea floating around is to require any new connection to the network to be authenticated and screened for adherence to security policy, just like we require external access to be screened. The security policy may include personal firewall, antiviral, etc.


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Ask the Experts Archives, Inactive
Recovering files from a Windows 2003 server
Converting user IDs to SIDs
Problems opening Group Policy snap-in
Problems accessing database files
Security configurations preventing programs from running
Adding domain groups using GPOs
Accessing the VPN after lock down
Resetting the default password policy
Conflicts among multiple GPOs
Methods for changing password policy settings

Virtual Private Networks
What's new and improved in IPsec in Windows Server 2008
Is a GPO blocking my VPN security scan?
How can I use Group Policy to manage proxy servers?
VPN security: Testing, troubleshooting and deploying
Penetration testing: Five tips in five minutes
VPN quick tips
Pen testing your VPN
The hacker handbook: Eleven tips in eleven minutes
Cisco patches flaws in multiple products
Extranet security

Network Firewalls
Network security assessment for network infrastructure
Hacking for Dummies, 2nd edition: Chapter 9
How can I disable file transfer in MSN Messenger?
Hacking for Dummies: Test your firewall rules
Setting up IPsec bypass
Automatic exceptions: IPsec bypass
The hacker handbook: Eleven tips in eleven minutes
Wireless network security testing
Cisco patches flaws in multiple products
Rootkits: Managing the threat with prevention measures

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice

HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersIT DownloadsBlogs
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2004 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts