Jump to content

Recommended Posts

Posted

I came across this article which disscusses the various options for VPN.

 

The general bias appears to be OpenVPN (SSL VPN) good, IPSec bad,

 

Client-less SSL VPN is also frowned upon. I guess this touches upon SSL Explorer which was recommened in Cowman's remote access thread

 

 

I am tempted to go the SSL way but wonder if there would be a performance penalty. Faterall IPSec is emplemented at kernel level and so should be faster.

Posted

Sorry, VPN isn't something I've really looked at recently.

 

even Microsoft are moving away from PPTP.

 

Someone better tell CLEO then. We're using PPTP here in Cumbria/Lancashire for our VPN remote access solution because apparently it's 'more secure' than IPSec....

Posted
Someone better tell CLEO then. We're using PPTP here in Cumbria/Lancashire for our VPN remote access solution because apparently it's 'more secure' than IPSec....

 

Have a look at this warning about PPTP posted on the poptop website.

The designers of the protocol, Microsoft, recommend not to use it due to the inherent risks.

 

One of the problems it has is that it's vulnerbale to offline cracking a bit like WEP.

 

The reason it's still used might because of ease of configuration and ubequity (it is included in Windows clients).

 

Complexity can often be an enemy of security such as with the post-it note syndrome when it comes to using strong passwords.

 

Another reason for continued PPTP use might be that NAT routers are not so kind to IPSec.

Posted

Mmm.. I had some involvement with the early "PPTP is Icky" uh.. campaign back when it was much, much worse.

 

The 'Why not use PPTP?' comments on lack of two-factor authentication and sniffing have been true pretty much forever. However it's only "trivial" to break given a rubbish password.. and unlike ye olde LM Hash thing, you can't crack two or more passwords at the same time.

 

IPSec (a good idea at the start) was murdered by a 10+ year committee design process, but when implemented wisely it's clearly more secure than PPTP.

 

SSL tunnels (with mutual authentication i.e. server & client certs) are my favourite too.

Posted
Sorry, VPN isn't something I've really looked at recently.

 

even Microsoft are moving away from PPTP.

 

Someone better tell CLEO then. We're using PPTP here in Cumbria/Lancashire for our VPN remote access solution because apparently it's 'more secure' than IPSec....

 

I think its the combination of L2TP/IPSEC that is more secure.

 

Window 2000 + has the client built in.

 

Ashok.

Posted
Sorry, VPN isn't something I've really looked at recently.

 

even Microsoft are moving away from PPTP.

 

Someone better tell CLEO then. We're using PPTP here in Cumbria/Lancashire for our VPN remote access solution because apparently it's 'more secure' than IPSec....

 

I think its the combination of L2TP/IPSEC that is more secure.

 

Window 2000 + has the client built in.

 

Ashok.

 

Theres a good L2TP/Ipsec resource here, http://www.jacco2.dds.nl/networking/freeswan-l2tp.html

along with a windows integration howto http://www.jacco2.dds.nl/networking/win2000xp-freeswan.html

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...