> How do you solve that one?

By using a firewall in addition to RRAS. RRAS only determines what packet
goes where. You still need to filter and check those packets.

This is one of my complaints of allowing RRAS to create an VPN endpoint. It
can give someone a false sense of security. If the RRAS server becomes
compromised, so is the VPN traffic as well as the network behind the VPN
endpoint.

IMO, using RRAS as a VPN endpoint should not be used in conjunction with a
DMZ zone, only behind a firewall.

John Tolmachoff MCSE, CSSA
IT Manager, Network Engineer
RelianceSoft, Inc.
Fullerton, CA  92835
www.reliancesoft.com


Reply via email to