Home > Ask the Security Experts > Network Security Questions & Answers > Securing the intranet with remote access VPN security
Ask The Security Expert: Questions & Answers
EMAIL THIS

Securing the intranet with remote access VPN security

Mike Chapple, featured expert EXPERT RESPONSE FROM: Mike Chapple, featured expert

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 07 August 2009
Our business has a main office in the city and a branch office about 150 miles away. We need a highly secure corporate intranet. Conventional wisdom seems to say that we should have a single, firewalled and highly secure point of connection to the global Internet, probably at the main office. Is there a different, better configuration? What security-related factors should I take into account when considering different configurations?


BROWSE BY TAG
Network Security,   NAC and Endpoint Security Management,   Secure Remote Access,   Enterprise Network Security,   Secure VPN Setup and Configuration,   SSL and TLS VPN Security,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Network Security
How to set up a split-tunnel VPN in Windows Vista
What is the difference between static and dynamic network validation?
Port scan attack prevention best practices
How to prevent network sniffing and eavesdropping
How to implement virtual firewalls in a complex network infrastructure
How to manage network bandwidth with distributed ISP bandwidth
How to edit group policy objects to give a user local admin rights
How to prevent operating system cloning with AES 256-bit encryption
How to securely connect a LAN POS to a remote point-of-sale device
How to select a set of network security audit guidelines

Secure Remote Access
Endpoint protection best practices manual: Combating issues, problems
Best Mobile Data Security Products
Perimeter defense in the era of the perimeterless network
What security software should be installed on Internet café computers?
Information security book excerpts and reviews
Diverse mobile devices changing security paradigm
Cisco warns of security appliance flaws
How to configure NAP for Windows Server 2008
Can home PCs provide a way for viruses and spyware to enter a corporate LAN?
What are the security risks of opening all the ports on an internal router?

SSL and TLS VPN Security
Expert calls SSL protocol vulnerability a non issue
How SSL-encrypted Web connections are intercepted
Best Remote Access Products
How to set up a split-tunnel VPN in Windows Vista
A short enterprise VPN deployment guide
Creating an SSL connection between servers
Can S/MIME, XML and IPsec operate in one protocol layer?
Can secure USB devices prevent man-in-the middle attacks
How to secure SSL following new man-in-the-middle SSL attacks
SSLstrip hacking tool bypasses SSL to trick users, steal passwords

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
authentication  (SearchSecurity.com)
RADIUS  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


The strategy you outline is a common one and allows network communications to be carefully controlled at a single point; however, it also poses some challenges. First, it increases network latency (which will be noticeable to users) by forcing all of their traffic through the central office. Second, it creates a single point of failure. If the central office loses network connectivity, the remote office will go down as well. This isn't a great topology, especially if you consider the remote office a potential backup site for the central office.

I'd suggest establishing an Internet connection at both offices and using VPN technology to create a secure tunnel between the two for interoffice communication. Supplement that with similarly configured firewalls and content filtering at both locations. That strategy should adequately secure both sites without the drawbacks identified above.

For more information:




Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



Find Security Solutions for Your Business
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts