RE: [SLUG] re: VPNs

From: Grantham, Patrick (Patrick.Grantham@vacationclub.com)
Date: Tue Oct 09 2001 - 16:47:46 EDT


By design, all clients and servers are behind the router/firewall. Thanks
for the info!

-----Original Message-----
From: Bryan-TheBS-Smith [mailto:b.j.smith@ieee.org]
Sent: Tuesday, October 09, 2001 4:38 PM
To: slug@nks.net
Subject: Re: [SLUG] re: VPNs

"Grantham, Patrick" wrote:
> A single port? Which is it?

Depends on the VPN solution.

> It seems clear that you get the essence of what I am trying to
> accomplish. A linux file server running samba behind a
> firewall serving to win clients on the internet.

Are they firewalled and have a local virus scanner? If not, any
virus they get, your network gets.

> Is the Frees/WAN for linux?

Yes. It is an IPSec implementation for Linux. Many IPSec
implementations interoperate -- e.g., McAfee PGPnet with FreeS/WAN
(provided you make the PGPnet config changes required).

> Dumb down guides can provide a good spring board into more
> comprehensive texts.

> What about pptp?

Yes it exists for Linux.
No, you don't want to use it.
Why?
It is a _huge_ security hazard on many fronts (too many to list),
especially in the original release (cake to get in).
Even in the newer version, there are still countless issues.
IMHO, PGPNet is worth the price (under $20/node I believe?).

> Am I revealing my newbieness on this topic? I seem to recall
> a distinct separation on a MS white paper.

When it comes to security, throw every MS White Paper out the
window. No joke!

-- TheBS

-- 
Bryan "TheBS" Smith   mailto:b.j.smith@ieee.org    chat:thebs413
Engineer  AbsoluteValue Systems, Inc.  http://www.linux-wlan.org
President    SmithConcepts, Inc.    http://www.SmithConcepts.com



This archive was generated by hypermail 2.1.3 : Fri Aug 01 2014 - 15:07:44 EDT