there are ways to mitigate the security issues associated with the vpn in
exchnage for the business functionality it provides. Some ideas: limit the
access ports coming through the vpn (pca in this case), provide
authentication on the corp firewalls, require host-based firewalls along
with appliance/network firewalls on the vpn endpoints.
Byron
----- Original Message -----
From: "Alvin Oga" <[EMAIL PROTECTED]>
To: "Rick Lim" <[EMAIL PROTECTED]>
Cc: "firewalls@Lists. GNAC. NET" <[EMAIL PROTECTED]>
Sent: Tuesday, September 25, 2001 3:58 PM
Subject: Re: Firewall and pc anywhere
>
>
> home pc #1 ------| fw | ** internet ** | f | ------>office pc#1
> | i |
> | r |
> home pc #2 ------| fw | ** internet ** | e | ------>office pc#2
> | w |
> | a |
> home pc #3 ------| fw | ** internet ** | l | ------>office pc#3
>
> now everything is hunky-dore....
> - run VPN on each firewall ( office and home ) and
> home pc#1 can seethe office pc#1 as is he was sitting inthe office
> - assuming the firewall rules is sconfigured for it
>
> -- but i'd disallow home PCs from access corp lans....geez...disaster
> waiting to happen...as the sys admin at work ...has tomaintain
> everybody's home PC network which probably has gazillion trojans
> and viruses and hacked machines...waiting for this connection
> to get into the corp lan
>
> have fun
> alvin
> http://www.Linux-Sec.net/VPN
>
> On Tue, 25 Sep 2001, Rick Lim wrote:
>
> > Is this possible,
> > we have 3 pc's that we would like office staff to be able to
> > access via pc anywhere from their home, is it possible that
> > all 3 staff members be able to access 3 different pc's behind
> > the firewall at the same time? If so how do I go about it?
> >
> > home pc #1 ------------>| f |------------------>office pc#1
> > | i |
> > | r |
> > home pc #2 ------------>| e |-----------------> office pc#2
> > | w |
> > | a |
> > | l |
> > home pc #3 ------------>| l |------------------> office pc#3
> > _______________________________________________
> > Firewalls mailing list
> > [EMAIL PROTECTED]
> > http://lists.gnac.net/mailman/listinfo/firewalls
> >
>
> _______________________________________________
> Firewalls mailing list
> [EMAIL PROTECTED]
> http://lists.gnac.net/mailman/listinfo/firewalls
_________________________________________________________
Do You Yahoo!?
Get your free @yahoo.com address at http://mail.yahoo.com
_______________________________________________
Firewalls mailing list
[EMAIL PROTECTED]
http://lists.gnac.net/mailman/listinfo/firewalls