Virus.Org  IT Security News and Information Portal. We offer the latest IT security news, updates, product reviews, books, and articles for all you IT security professionals out there. Enter and get the best IT security information on the Internet.

 

. Welcome to the Virus.Org Mailing List Archive  
.
.


[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]


Re: [VPN] SSL VPN
.

  • To: "Bartsch, Vincent" <[EMAIL PROTECTED]>
  • Subject: Re: [VPN] SSL VPN
  • From: Alex Pankratov <[EMAIL PROTECTED]>
  • Date: Mon, 28 Apr 2003 19:58:54 -0700
  • Cc: "'[EMAIL PROTECTED]'" <[EMAIL PROTECTED]>
  • In-reply-to: <[EMAIL PROTECTED]>
  • References: <[EMAIL PROTECTED]>
  • Sender: [EMAIL PROTECTED]
.
 
Vincent,

coincidentally I was looking at securing TS traffic just last week, so as an alternative you may want to look at MS own article:

http://support.microsoft.com/?kbid=315055,

"HOW TO: Use IPSec Policy to Secure Terminal Services Communications in Windows 2000".

This is not much, it does not talk on how to setup authentication or about NAT traversal, etc, etc.

Amongst SSL-based solutions, http://stunnel.org is the first thing that comes to mind. I dont see any reason why it should not work, so I'd try it first.

On the more general topic, I recently wrote a small article about very simple aspect of TCP-based VPNs, which can seriously undermine robustness of the former. The issue worths considering depending on your deployment scenario.

http://www.cipherica.com/papers/tcp-vpn-dos.pdf

cheers,
alex.

Bartsch, Vincent wrote:
I am researching everything about SSL and it's use as a VPN solution. I am aware of some of it's limitations but I was wondering has anyone tried this: allowed a SSL connection to a web server that lets the user to open a connection to a terminal server. Or can it be configured to connect to a terminal server via a SSL connection directly? Has anyone tried this, were they
successful?

Again, I am just researching this thought. Any word back on this would be most appreciated,
thanks.

Vincent


_______________________________________________
VPN mailing list
[EMAIL PROTECTED]
http://lists.shmoo.com/mailman/listinfo/vpn

 
.
.
 
Copyright (c) Virus.Org 1997-2006.
All Trademarks Acknowledged.
Please view our Terms and Conditions and our Privacy Policy.