Home > Ask the Security Experts > Questions & Answers > Evidence of the risks of split tunneling
Ask The Security Expert: Questions & Answers
EMAIL THIS

Evidence of the risks of split tunneling

Stephen Mencik EXPERT RESPONSE FROM: Stephen Mencik

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site
>
QUESTION POSED ON: 15 January 2003
Many thanks for the answer to my query. Steve backed up my theory. As I am not a professional hacker, it would be great to know how I could piggy back or hijack a VPN session from the Internet so that I can prove to our network guy that split tunneling is indeed a risk.

>

I don't know how I could describe for you how to do this without giving out sources and methods to those that could be hackers. Ethically, I really can't do that. However, I can point you to some other sources so that perhaps having the overwhelming evidence will convince your network guy.

From the SANS Institute: Telecommuting safely -- remote node or remote session?, by Mark Levine

From CSOonline: Addressing teleworker network security risks, by Chad Robinson of Robert Frances Group

From SearchNetworking.com: Know your split-tunnel "gotchas", by Tom Lancaster

From Security Management Online: Tunnel of Secure Transmission, by Christopher J. Carlson

Finally, by allowing split tunneling, you are in effect dual-homing your remote client on both your internal network and the Internet at the same time. Since you likely cannot control how your remote client is configured, that is the same as opening up your corporate network to whatever bad things can happen to that remote client. Is the antivirus up-to-date on that remote client? I hope so, because if a virus gets on it, it can easily spread to the corporate network, bypassing any antivirus at your corporate firewall. Does your remote user have a wireless network at home? If so, can his neighbor hack into that network and then use the tunnel that has been set up because the shared permissions of the home network are setup wrong? Probably.

I really cannot emphasize enough that split-tunneling is a really bad idea.


For more information on this topic, visit these other SearchSecurity.com resources:
Ask the Expert: The threat of split tunneling with PPTP
Ask the Expert: Split tunneling in a VPN environment
Best Web Links: Infrastructure and network security


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



Find Security Solutions for Your Business
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts