corsasport.co.uk
 

Corsa Sport » Message Board » Off Day » Geek Day » VPN security issues » Post Reply

Post Reply
Who Can Post? All users can post new topics and all users can reply.
Icon:
Formatting Mode:
Normal
Advanced
Help

Insert Bold text Insert Italicized text Insert Underlined text Insert Centered text Insert a Hyperlink Insert Email Hyperlink Insert an Image Insert Code Formatted text Insert Quoted text
Message:
HTML is Off
Smilies are On
BB Code is On
[img] Code is On
Post Options: Disable smileys?
Turn BBCode off?
Receive email notification of new replies?

Tim

posted on 14th Feb 06 at 17:00

Security wise you'll be fine if you just make sure you untick the bindings (file & print sharing). You need to leave the 'client for microsoft networks' enabled to allow you to access their share though. They won't be able to come back up the tunnel to browse your network, unless you have a (stupid) ip_forward config on your machine.

PPTP/L2TP passthrough should be enabled on your firewall to let the traffic through (checkbox if you're using a hardware router). If you're using MS ISA server there's a similar option.


Melville

posted on 14th Feb 06 at 16:41

Its just through the windows client one. I have a funny fealling however that it wont work due to our firewall and will have to open some ports?


Tim

posted on 14th Feb 06 at 16:32

Using a VPN client or is this a site-to-site VPN they're proposing?

If you're just using the Windows client then simply remove File & Printer Sharing for MS Windows from the bindings. Any other clients should have an option to disable network access (i.e. allow access to/from the vpn only on the endpoint).

If it's site-to-site (i.e. configured on your firewall/vpn server), then what firewall/vpn server are you using?


Melville

posted on 14th Feb 06 at 15:46

We are looking to set up a deal to outsource some of our work (not IT outsourcing but accountancy work). We have received an email off the people telling us to set up a vpn connection to an IP address and then transfer the necessary scanned data into a folder via the VPN connection.

Now my only concern is if they can access our network and see anything they should'nt such as our whole client database as they could easily try to poach our clients if they had there details.

Thanks for any help, Mark