Home > Infrastructure security: Remote access DMZ
Book Chapter:
EMAIL THIS

Infrastructure security: Remote access DMZ

12 Sep 2006 | Syngress Publishing

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

How to Cheat at Managing Information Security
Mark Osborne

315 pages; $39.95

Syngress Publishing

In this excerpt from Chapter 7: Infrastructure Security from How to Cheat at Managing Information Security, author Mark Osborne examines how remote access DMZs can mitigate risks of unsecured remote access endpoints and provides remote access design options network administrators can use to enhance the security of the network's infrastructure .

Many organizations have a legacy dial-in remote access server. This server will need access to a radius-based authentication server (see Figure 7.3). More modern remote access will be enabled by either an SSL or IPsec VPN server, using the ubiquitous Internet. It is good practice to "DMZ" both of these to allow better access control. I'll come right out and say it: Many VPN servers provide lame firewall service and aren't certified to EAL4. Rant over.

Threat Analysis

The threats and countermeasures look something like the list in Table 7.2.

Table 7.2 Threat Analysis of Remote DMZ
ActivityThreatCountermeasure
Public network connectivityHacking/unauthorized access through insecure, nonmandated protocolsFirewall
 Hacking/brute-force attack providing entry via authorized protocols by repeated trial of user ID and passwordStrong authentication
 Getting access to confidential informationEncryption
 Man-in-the-middle attackEncryption plus strong authentication
Mail inwardViruses and wormsOptional mail virus scanning


Remote Access Design Options

Personally, these days I usually run encryption over the PSTN. The local operators in some parts of the world aren't very secure and run it through IP over the Internet, so it makes sense. To achieve this goal, a direct connection into the VPN concentrator from the access server is required.Typically, a port on the same virtual LAN (VLAN) or a new VLAN and an extra network interface card (NIC) in the concentrator will do it.

For strong authentication, I am particularly fond of the one-time password generators, so you should consider deploying:

  • Cryptocard
  • RSA SecuriD
  • Vasco token -- Digipass

These can be used with the PSTN, SSL VPN, or IPsec VPN. They should speak "radius" as a native tongue so they require no further integration.

As a one-time evangelist of PKI, I should recommend digital certificates, but I'm not, simply because they are too difficult to manage for a typical medium-sized organization. (Please note that I'm not suggesting that risk/threat is a function of size only; capital expenditure and head count to maintain large infrastructure often are. Many investment banks are "medium-sized" but need and use Rolls Royce countermeasures.)
More on remote access management
Download the full chapter and how to secure your network infrastructure.

Use these tactics to protect sensitive data and secure remote access to your network.

Use these five best practices to secure remote access endpoints.

If you are dying to use an integrated firewall appliance, this is your chance. As mentioned before, many of them have virus capability, and extra virus scanning of your remote access connection is a useful addition. Many of them can also speak SSL-VPN and IPsec-VPN, so you can end up with all the functionality in one box. That has to be good for the flexible enterprise. But please make sure that virus scanning occurs on the decrypted VPN stream. Use the dummy virus EICAR to check.

Lastly, and as mentioned earlier in this chapter, it would be good to have IDS included. As an old fossil, I would not jump at the chance to integrate IDS into an appliance. An IDS is a detective control, and therefore I like it to have complete separation (in other words, segregation of duties).

Want more from Chapter 7: Infrastructure Security? Download the full chapter.

Reprinted with permission. Copyright Syngress Publishing © 2006.

BROWSE BY TAG
DMZ Setup and Configuration,   NAC and Endpoint Security Management,   Enterprise Network Security,   Secure Remote Access,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
DMZ Setup and Configuration
How to set up a DMZ
How to configure firewall ports for webmail system implementation
When should a database application be placed in a DMZ?
How will many firewalls serving as the default gateway affect the DMZ?
Should a domain controller be placed within the DMZ?
If one server in a DMZ network gets attacked from outside, will the other servers be corrupted?
Should an ISP keep corrupted machines off of a network?
A security checklist: How to build a solid DMZ
How to secure servers when implementing internal network applications
How is internal mail channeled through an enterprise firewall?

Secure Remote Access
What security software should be installed on Internet café computers?
Information security book excerpts and reviews
Diverse mobile devices changing security paradigm
Cisco warns of security appliance flaws
How to configure NAP for Windows Server 2008
Can home PCs provide a way for viruses and spyware to enter a corporate LAN?
What are the security risks of opening all the ports on an internal router?
Should an ISP keep corrupted machines off of a network?
As hype subsides, NAC moves ahead
NAC's future

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
DMZ  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary




Search Additional Security Research and Solutions
Find Security Channel Research for Resellers and Partners
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts