Title: RE: [FW1] PPTP thru SecuRemote ...?
Hi Jean Pierre.
 
Hm.. I understand, but for the other hand it increases the TCO and related management in a way the pay off is questionable,
 
Maybe a good combination of strong vpn/ fw (as vpn-1 is) and good authentication (as certificates / securid) could make better, considering the administration point of view...
 
Suggestions and thoughts welcome...
 
 
----- Original Message -----
Sent: Monday, May 21, 2001 8:09 PM
Subject: RE: [FW1] PPTP thru SecuRemote ...?

Aylton,
 
Like I said, the biggest advantage of using PPTP after establishing the SR connection is where you have dual level, multi vendor firewalls. Assuming the external FW is FW-1 then you can establish the Securemote connection to the border FW, then tunnel through the second FW to the internal n/w, or to the second firewall if supported. This also adds another level of authentication.
 
JP
-----Original Message-----
From: Aylton Souza, CISSP [mailto:[EMAIL PROTECTED]]
Subject: Re: [FW1] PPTP thru SecuRemote ...?

Hi,
 
I really tried, but I could not understand the advantage or purpose of using PPTP AND SecuRemote.
 
I can't see anything on PPTP that cannot be implemented better (easier, safer and more manageable) with Securemote / SecureClient...
 
Wins, domains and so can be reached and managed using for example SDL...
 
I'd like to better understand the need itself for the combinated funcionality and maybe I can suggest alternatives.
 
Best regards
 
Aylton
----- Original Message -----
Sent: Monday, May 21, 2001 12:41 AM
Subject: RE: [FW1] PPTP thru SecuRemote ...?

Andreas,

I do agree with you that it is easier, especially if you have dual firewalls, then you can tunnel through to the internal network after connecting via securemote. I have had the config working, but not consistantly. ie. it was working in my test network for a while and now it does not and I did not change anything, so I can not give you a definitive answer. If someone else can I would be interested in hearing about it.

JP

Reply via email to