I guess the question I have is where would you place it? On the dirty
segment, on a DMZ segment, or on an internal segment? Anywhere you place
it, it adds complexity to the routing and security controls in place.
One nice aspect of the one-box solution is you won't have two support
contracts, two products to patch and watch for vulnerabilities for, etc.
-iden_fw
>From: "Churcher, Simon" <[EMAIL PROTECTED]>
>To: "'[EMAIL PROTECTED]'"
><[EMAIL PROTECTED]>
>Subject: [FW1] Is split tunneling secure
>Date: Fri, 8 Dec 2000 16:41:45 -0000
>
>
>Hi All,
>
>I have seen a couple of arguments in our corporation about whether an
>integrated VPN/Firewall (Checkpoint) is more or less secure than a two box
>solution (ie a Nortel contivity for the VPN and a Nokia Firewall).
>
>I'm strongly leaning toward the integrated solution being more secure.
>
>Anyone have any comments on this?
>
>thanks,
>
>simon
>
>
>________________________________________________________________
>The information contained in this message is intended only for the
>recipient, may be privileged and confidential and protected from
>disclosure. If the reader of this message is not the intended recipient, or
>an employee or agent responsible for delivering this message to the
>intended recipient, please be aware that any dissemination or copying of
>this communication is strictly prohibited. If you have received this
>communication in error, please immediately notify us by replying to the
>message and deleting it from your computer.
>
>Thank you,
>Standard & Poor's
>
>
>================================================================================
> To unsubscribe from this mailing list, please see the instructions at
> http://www.checkpoint.com/services/mailing.html
>================================================================================
_____________________________________________________________________________________
Get more from the Web. FREE MSN Explorer download : http://explorer.msn.com
================================================================================
To unsubscribe from this mailing list, please see the instructions at
http://www.checkpoint.com/services/mailing.html
================================================================================