tdh1987 Posted June 21, 2021 Posted June 21, 2021 (edited) Hi guys Due to the unprecedented rise in cyber attacks on the education sector I’ve decided to close off access to the Smoothwall VPN as I am unsure how secure it is. I've also closed the firewall rule (see below) The only entry point I'm aware of now is the rule that allows Smoothwall HQ to administer the box. What are others thoughts on the built-in VPN. Should it be left off, or are we happy there are few or no vulnerabilities to worry about? I'm referring to the OpenVPN client that tunnels in from an off-site laptop or desktop. Thanks Tom Edited June 21, 2021 by tdh1987
dazza007 Posted June 21, 2021 Posted June 21, 2021 You are not alone there! The Open VPN client is not updated and that left me very concerned too! I have put in Remote Desktop with MFA from within 365 thanks to the expertise on here. I would be interested to find out what vulnerabilities the client has. The advice is to have MFA for remote access. Having the smoothwall with limited support at the moment worries me with this situation occurring.
Primus Posted June 21, 2021 Posted June 21, 2021 If you're using the SSL VPN with certificates then the certificate is a form of MFA - the user needs both their password and a certificate to connect to the VPN. 1
dazza007 Posted June 21, 2021 Posted June 21, 2021 Thank you. Therefore if you install the VPN (as it is a manual install), the opvn file needs to be taken off the computer? or can the certificate be "transferred" in a hack on the computer?
ibpalle Posted June 23, 2021 Posted June 23, 2021 Only the public parts of the Smoothwall VPN certificates is present in the ovpn file. There is no user certificate. If a user had access to the certificate information or the ovpn file they would be able to try a connection - obviously they need a username and password that works in order to be able to connect. The certificate information is embedded in the ovpn file now, there is no need for the certificate included in the client archive generated on the Smoothwall. That is the public key for the server certificate.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now