Re: Cisco VPN Client config on 515



In article <1145396405.016488.231300@xxxxxxxxxxxxxxxxxxxxxxxxxxxx>,
AJ <aragorn.m@xxxxxxxxx> wrote:
So it works but I am wondering just how secure it is...

Essentially I will end up with an ACL on my outside interface allowing
10.18.0.0/24 into my internal network (I know I can control ports and
destination IPs etc) but this is my protected network. Is this a good
idea? Granted the IP on my outside interface has a public IP but isn't
it possible to get packets to arrive at the outside interface which
appear to originate from 10.18.0.0/24 without that traffic going over
my VPN tunnel?

Yes, if the sending network does not follow RFC1918 rules and permits
10.18.0/24 to be pass out of their network, then it is possible that
nothing inbetween will filter the packets, and that they would arrive
at your PIX interface if they are addressed to any of your public IPs.

If you are using private IPs internally, part of the solution to that is to
permit the private IPs of the VPN to go only to the private IPs of the
LAN: then the packets would not be able to get to your PIX unless
the next-hop for some reason routes that IP range to your PIX.

Even if you do not do that, the PIX should notice that the source IP
was not received over the VPN as expected and should drop the packet.
The message is roughly "Received packet is not an IPSec packet".
The PIX actively checks for IPs that should be tunneled but which are
arriving directly.
.



Relevant Pages

  • RE: [fw-wiz] Re: IP aliasing behind a PIX
    ... > network behind the PIX, but ... >> IPs behind a PIX firewall. ... >> network, the aliases work fine (i.e., the machines are accessible using ...
    (Firewall-Wizards)
  • RE: [fw-wiz] Re: IP aliasing behind a PIX
    ... > network behind the PIX, but ... >> IPs behind a PIX firewall. ... >> network, the aliases work fine (i.e., the machines are accessible using ...
    (Firewall-Wizards)
  • RE: IDS evaluations procedures
    ... If you allow invalid traffic into the network you still need to inspect it further to see if it is malicious too! ... By reducing the number of packets that you inspect you can reduce the number of alerts –especially false positives. ... An inline IPS discards all HTTP packets not containing www.xyz.com as a host header, this filters out all non-targeted worm nonsense –lets say 90% of the malicious traffic. ... The IDS will create 100 alerts/sec ...
    (Focus-IDS)
  • [fw-wiz] IP aliasing behind a PIX
    ... IPs (same network though) behind a PIX firewall. ... network, the aliases work fine (i.e., the machines are accessible using ... Then the alias works as well until I reboot the PIX. ...
    (Firewall-Wizards)
  • RE: [fw-wiz] Cisco Concentrator - pix515 Lan-to-Lan
    ... Check the pix static routes as well. ... If the remote network is a subnet ... I have a problem with configurin Lan-to-Lan on VPN concentrator 3000 ... I can see echo and eho-replay packets on my pix (debug ...
    (Firewall-Wizards)