Great Circle Associates Firewalls
(March 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: VPN's over the internet
From: Steve Kennedy <steve @ gbnet . org>
Date: Fri, 1 Mar 1996 18:07:29 +0000 (GMT)
To: Mike . Jones @ unifiedtech . com (Mike Jones)
Cc: firewalls @ GreatCircle . COM, frankw @ in . net
In-reply-to: <199603011427 . JAA03140 @ samadams . unifiedtech . com> from "Mike Jones" at Mar 1, 96 09:27:19 am

According to Mike Jones

> Frank Willoughby writes...
> > A note or two of interest about VPN's over the Internet: 
> > o Many (most?) firewalls when performing firewall->firewall encryption
> >   are only providing an IP encryption tunnel through the firewalls.
> >   It is important to note that *NO* applications filtering is performed.
> >   While this may offer protection from a MITM (Man-In-The-Middle) attack 
> >   (Internet, etc), it offers *NO* protection from the other entity's
> >   network.  A problem on their network is a problem on your network.
> This is a *very good* point. I was talking to a customer recently who
> manufactures snowmobile equipment and works with the likes of Polaris,
> Arctic Cat, etc., and who would like to exchange some pretty sensitive
> (trade secret) information with them over the Internet. They initially
> wanted me to come in and talk about VPN's and FW-FW encryption, but
> after I brought this point up to them they suddenly realized that
> end-to-end encryption with something like PGP is better for some
> applications.

Have a look at the KarlBridge/KarlBrouter, this can do encrypted VPNs
(using proprietary software encryptin currently, DES on its way).

This will perform any filering BEFORE the tunnelling.

have a look at http://www.karlnet.com/ in the US
               http://www.gbnet.net/kbridge/ in UK/Europe


Regards

Steve

-- 
home steve @
 gbnet .
 org       * Flat 2, 43 Howitt Road, Belsize Pk, London NW3 4LU
work steve @
 demon .
 net       * tel +44-(0)171 483 1169    FAX +44-(0)181 444 6103
www  http://www.gbnet.net/ * 
bits steve @
 gbnet .
 net       * Orange mobile +44-(0)973 600050
Euro firewall info - send mail to majordomo @
 gbnet .
 net  (subscribe firewalls-uk)


References:
Indexed By Date Previous: Re: FW: rx but no tx wiring for ethernet
From: Jerry Champlin <jgc @ webspan . com>
Next: filtering RPC ports
From: "W.C. Epperson" <epperson @ vak12ed . edu>
Indexed By Thread Previous: RE: VPN's over the internet
From: Mike . Jones @ unifiedtech . com (Mike Jones)
Next: Re: VPN's over the internet
From: peter @ nmti . com (Peter da Silva)

Google
 
Search Internet Search www.greatcircle.com