Re: vpn tunel security





"Brian V" <diespammer@xxxxxxxxxx> wrote in message news:apOdncDYK8vKxtbanZ2dnUVZ_t6onZ2d@xxxxxxxxxxxxxx

"sali" <sali@xxxxxxxxxx> wrote in message news:fifkrq$56p$1@xxxxxxxxxxxxxxxxx
we have vpn corporate network with cisco/1721 and cisco/805 routers over the internet
since it is quite old equip, can somebody advice how secure are those tunnels going over internet today?
thnx

Both pieces of equipment are EOL/EOS which means they are running out dated software that most certainly has vunerabilites.



"sali" <sali@xxxxxxxxxx> wrote in message news:fifob5$66n$1@xxxxxxxxxxxxxxxxx
well, they were payed quite expensive, and for many years they work quite well [we have simply star topology, with static routes, no dynamic connection comming from outside]

since they are outdated eol/eos, does it mean they have to be replaced with new [also expensive] ones, or we can simply wait untile some of them experience some fatal hw shock, and be replaced then?

i am in the process of interrogating my network and trying to estimate potential treats and cost analysis

any experience and advice is helpfull
thnx

Please dont top post, it makes it very difficult for people to read and respond to the threads.
A simple "Star" topology would be refering to a private infrastructure, not a publically facing VPN setup. If by star you are refering to the VPN tunnels that you have then yes, without question you should be running modern updated equipment running current software. As attack signatures and vulnerabilities are introduced vendors bring out updated software to address those attacks. On your out dated equipment those vulnerabilites still exist and can be exploited. Internal routers are a different story in my opinion, those can run "older" software as they are not public facing and do not face the same exploits that edge routers face. You comment on equipment being "expensive", I beg to differ. Equipment these days is very reasonably priced. A modern 2801 router probably costs less than you paid for the 1700 series you have. What is the cost of your corporate private information, what would it cost you if your customer information was stolen? Is it worth more than the couple grand you'll pay for a new edge router? If so, then you have your answer already. In addition to that, VPN should never be run from the edge router, it should be being run from a corporate firewall or dedicated VPN appliance. Edge internet routers should be doing simple filtering, anti-spoofing, simple expoit stuff to keep the load off the firewall. A properly designed and implemented network edge may be much more reasonably priced than you think.

.



Relevant Pages

  • Re: Advice about Broadband Problems
    ... Have you got any electrical equipment nearby which may be interfering? ... the main BT telephone wall socket. ... If you find your connection is fine only if you are doing something, ... then its very likely that your equipment is configured to drop the Internet ...
    (uk.telecom.broadband)
  • Re: Advice about Broadband Problems
    ... Have you got any electrical equipment nearby which may be interfering? ... the main BT telephone wall socket. ... If you find your connection is fine only if you are doing something, ... then its very likely that your equipment is configured to drop the Internet ...
    (uk.telecom.broadband)
  • Re: How often should I pressure my doc?
    ... Is there any way you can get the Internet deal set up yourself? ... I did, and he purchased his equipment, and I purchased mine...and we're still doing tapes seven months later. ... He uses the orthopaedic equipment supplier who travels between here and there on a weekly basis to deliver the tapes to me. ... difficult for me for obvious reasons), business-like manner would be greatly appreciated. ...
    (sci.med.transcription)
  • Re: Laptops
    ... disk or virtual drive encryption using a choice of different encryption ... An alternative is to self destruct the data if the equipment is stolen. ... use both Internet and telephone connections to find your equipment. ... for component serial numbers and sends the information to the WebDetect ...
    (Security-Basics)
  • Re: Odd entries in my Security Router logs
    ... > be routed over the Internet. ... Do you NAT at your edge router and were ... Overloaded remote NAT devices or firewalls ... Some ISPs filter it out and some don't. ...
    (Incidents)