Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Understanding Security

Status
Not open for further replies.

Javy1

Technical User
Jul 25, 2002
67
US
Hey Guys,

We use a VPN to run TS. Does this means that data is encrypted in both direction when people connect from home to the TS through the VPN tunnel at the office? Also if I people are using a wireless router from home and they have configure the router to use WEP and hide their SSID, does this add an extra layer of security to their TS connection. Should I use a wireless router with VPN? Is it easy to hack? If data is intercept it will they be able to read it? I new to wireless devices and I just want to have a sense of what I am getting here, since a few users are running wireless routers from home.

Thanks,

Javy
 
This would be better addressed in the General Security discussion forum (forum83). That being said...

The VPN communication (tunnel) is encrypted and when done properly will provide plenty of security. This is only the transmission of the data. Consider when a home user is on dial up or broadband, many times they have no protection and their system is wide open. Should their computer become compromised, they now have access to the same VPN tunnel with the same permissions as that user - a sobering thought.

I'm not a fan of wireless from a security perspective. WEP is a weak encryption. Aside from sniffing the data and breaking the encryption, there is also the possiblility they can hijack the signal (again if not configured properly) and hack the users computer on their LAN (taking us back to the first point about a compromised computer).

Since you can't control what the user does at home, your best bet is to secure their machine as much as possible. Install a personal firewall, and where possible, educate the user (if you can set up the wireless network for them, more power to you!).
 
I know i'm coming from a lightly different angle here, but i've got a VPN connection to one of our customers. I need to make this connection far more secure, as at the moment if anybody sniffs they will be able to access our customers LAN. All i've got is a strong password, and since they are actually a security company, they actually need more doing!

Is there any configuration or security setups that you guys recommend me to sort out. Ive not really worked with VPN before so is there any chance anybody can talk me through step by step what i will need to do to make my connection more secure? Ideally i'd like to install a certificate or a pre-share key but im not sure exactly how to do this.

Spec:

Windows 2000 Small Business Server
Clients are Win2000 Pro
DSL-504 Router


Thanks in advance guys.

Adam Tate
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top