
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 119
ConfiguringtheVPNServer
RefertoAssignment1 forinformationonWindows2000hardening.
Shortforvirtualprivatenetwork, VPNisanetworkconstructedbyusingpublicwires
toconnectnodes. VPNsystemsuseencryptionandothersecuritymechanismsto
ensurethatonlyauthorizeduserscanaccessthenetworkandthatthedatacannotbe
intercepted
22
. W2K_VPNisaWindows2000ServercomputerrunningRRAS.It
allowsapredefinednumberof theremoteVPNclientstoconnecttothe
Critical_Resourcesdatabaseapplicationserver.
FirewallStrategyfortheVPNServer:
W2K_VPNsitsbetweenRouter_Econcardandthecoreswitch /Core_Net.Itserves
primarilyasa VPNServerforacceptingremoteaccessrequestsfromtheexternal
partnersandsuppliers.ItdoesnotactasaVPNgatewayfortheinternalclients.
TherearetwoapproachestodeployingafirewallwithaVPNserver.Wecaneither
placethefirewallbetweentheVPNserverandtheintranet,orplacetheVPNserver
betweenthefirewallandtheintranet. ForGIAC,wegowiththefirstapproach:thatis,
weplacethe VPNServerinfrontof theFirewall.
With thisstrategy,weneedtoaddpacketfilterstotheVPNserver’sInternetinterface
to onlyallowVPNtraffictoenterintoandgoingoutfromtheIPaddressofthat
interface.Forinboundtraffic,whenthetunneleddataisdecryptedbytheVPNserver,
itisforwardedtotheinternal firewall(s)forfurtherfilteringandinspection.Sincethe
onlytrafficcrossingtheVPNserverisgeneratedbyauthenticatedVPNclients,
firewallfilteringcanbeusedtopreventVPNusersfromaccessingspecificintranet
resources
23
.
22
http://www.webopedia.com/TERM/V/VPN.html
23
http://www.microsoft.com/windows2000/techinfo/reskit/enus/default.asp?url=/WINDOWS2000/techi
nfo/reskit/enus/intwork/inbe_vpn_HIDV.asp
Kommentare zu diesen Handbüchern