Risks of logging into VPN via a remote wireless router

Risks of logging into VPN via a remote wireless router

My company has a Cisco PIX Firewall. We have several users who have wireless routers (Linksys) at home and log into the VPN over them. What risks are we exposed to at the company?

    Requires Free Membership to View

    SearchSecurity.com members gain immediate and unlimited access to breaking industry news, virus alerts, new hacker threats, highly focused security newsletters, and more -- all at no cost. Join me on SearchSecurity.com today!

    Michael S. Mimoso, Editorial Director

    By submitting your registration information to SearchSecurity.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchSecurity.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

Assuming that your users are using a VPN software client on their local machine which then sends wireless to their router and then on to your company, there is not much more risk than if it were a hard-wired connection. The client on their local machine encrypts all the data prior to it going "over the air" to the wireless router. The only additional risk would be if someone could intercept the tunnel setup and act as a man-in-the-middle of the connection. I would not consider that a significant risk. I would want to ensure that the VPN is using strong cryptography and that it is always enabled, so that you are certain that the casual sniffer is not going to capture username and password pairs.


For more information on this topic, visit these other SearchSecurity.com resources:
Best Web Links: Virtual Private Networks
Best Web Links: Wireless Security Issues


This was first published in January 2003