Re: Cisco 3015 conentrator

"Bill Mathews" <[email protected]>
Newsgroups gmane.comp.security.vpn
Message-ID <[email protected]>
I would agree completely with it being "one of the nicer vpn
concentrators..." However, I would contend that you certainly should have
a firewall in front of it. It is a generally regarded best practice to
control as much access to your network from a central place (your
firewall) as possible. The filters are decent but do not offer full blown
protection. Although the VPN Concentrators are a very well implemented
solution, they are still vulnerable to things. I would suggest it be
behind your firewall as another layer of protection.

My $.02

-- 
Bill Mathews
Open Source Software Advocate
[email protected]
"Don't hate it because its Microsoft, hate because its bad"

The wise and noble Dana J. Dawson spiteth forth upon the land, these
thoughts:
> In a more helpful vein, The 3000 has default filters on the public
> interface that should do a reasonable job of restricting traffic to just
> that used by the various VPN technologies it supports.  You can tighten
> them down if you know you won't use a particular protocol, but you can't
> remove the list if you want to terminate VPN's (though nothing stops you
> from permitting all traffic through the filter, which would be a bad
> thing to do).  However, these filters don't provide any DoS protection
> to the 3000, so there would be a benefit in that regard in having an
> external firewall, assuming it provided such protection.  I've not seen
> any reports of a 3000 being hacked, but there was a vulnerability a
> while back that could allow unintended traffic through the concentrator
> but that's been fixed for a long time (I forget the details, but it'd be
> easy to find on Cisco's site).  It's not a gaping hole in your security
> if you don't protect with a firewall so I would argue that you don't
> *need* a firewall in front of it.  The 3000 is, in fact, one of the
> nicer VPN concentrators on the market in my opinion.  It's not perfect,
> but nothing is.
>
> HTH
>
> Dana
>
> --
>
> Dana J. Dawson                     [email protected]
> Senior Staff Engineer              CCIE #1937
> Qwest Communications               (612) 664-3364
> 600 Stinson Blvd., Suite 1S        (612) 664-4779 (FAX)
> Minneapolis  MN  55413-2620
>
> "Hard is where the money is."
>
>
> Brian Wotring wrote:
>
>>
>> Yes, and I recommend unplugging it and burying it in your backyard.
>>
>> On Nov 13, 2003, at 10:30 AM, Roger Qian wrote:
>>
>>> Hi,
>>>
>>> Does Cisco 3015 concentrator need a firewall to protect hacking?
>>>
>>> Thanks,
>>>
>>> Roger
>>> _______________________________________________
>>> VPN mailing list
>>> [email protected]
>>> http://lists.shmoo.com/mailman/listinfo/vpn
>>
>>
>> --
>>     Brian Wotring ( [email protected] )
>>     PGP KeyID: 0x9674763D
>>
>> _______________________________________________
>> VPN mailing list
>> [email protected]
>> http://lists.shmoo.com/mailman/listinfo/vpn
>>
>
>
> _______________________________________________
> VPN mailing list
> [email protected]
> http://lists.shmoo.com/mailman/listinfo/vpn
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.