Allowing POP3, IMAP4, and HTTP access to your IMAIL system will cause
passwords to be sent over the internet in clear text.  If these are mail
only passwords then your risk is limited, but if they are "universal"
passwords then potential security risks go up exponentially.  One way around
that is VPN (Virtual Private Networking) so that the connection is secured
before you even send the password.  This can be accomplished by placing VPN
software on your router, and remote client stations that will access your
servers across the internet.  The router encrypts all outbound packets and
the workstation decrypts them, responses from the remote workstation are
encrypted and then decrypted by your router so IMAIL does not need to be VPN
aware.  This suggestions does come with some costs and maintenance, but
allows you to extend the walls of your security policy to wrap around and
include your remote users.

Short answer:
POP3, IMAP, and IMAIL's HTTP are authenticated services and passwords are
"sniffable" in transit.
-V
----- Original Message -----
From: imfo <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Thursday, November 04, 1999 8:56 AM
Subject: [IMail Forum] Security Question


> We run imail v5.07 on our internal network
> Only SMTP packets are allowed IN through our firewall (Checkpoint FW-1)
> What are the security implications of opening up each or any of
> POP3, IMAP4, HTTP
> to allow our users access their mailboxes from the internet.
> I know we can install a security (encryption) module in the firewall (for
> some $$$), but does say allowing POP3 access only compromise our security
?
>
> TIA
> Ronan
>
>
> Please visit http://www.ipswitch.com/support/mailing-lists.html
> to be removed from this list.
>

Please visit http://www.ipswitch.com/support/mailing-lists.html 
to be removed from this list.

Reply via email to