LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-12-2023, 09:44 PM   #16
sundialsvcs
LQ Guru
 
Registered: Feb 2004
Location: SE Tennessee, USA
Distribution: Gentoo, LFS
Posts: 10,679
Blog Entries: 4

Rep: Reputation: 3947Reputation: 3947Reputation: 3947Reputation: 3947Reputation: 3947Reputation: 3947Reputation: 3947Reputation: 3947Reputation: 3947Reputation: 3947Reputation: 3947

There's obviously quite a bit of misunderstanding here, so let me try to explain:

There are two entirely-different "use cases" here. One is that you want to securely connect two internal networks. The other is that you want to conceal your access to the outside world – or, merely, to secure your conversations among industrial spies within the same coffee shop.

In the latter case, you are establishing a VPN connection to a commercial provider who will then dump your now-unencrypted communications onto the public internet. The distinction here is not "the security of the pipe," but what it is ultimately connected to. No one will be able to intercept your messages, until they emerge at some IP-address (somewhere) that is publicly known to be "a public VPN endpoint." By then, "VPN will have done its job."

The "road warrior situation" entirely depends upon whether the participants are using digital certificates as opposed to PSKs = Pre-Shared-Keys = Stupid Passwords. If they are doing things properly, then each participant has a unique digital certificate which cannot be forged, although it can (and should be) "password protected." Without the password, the certificate cannot be used. But, if the underlying [unique ...] certificate has been [uniquely ...] revoked, then it worthless. Therefore, as soon as the company realizes that a particular laptop has been stolen, they can invalidate that computer's access, whether or not the encryption password surrounding that particular certificate had been compromised.

Last edited by sundialsvcs; 09-12-2023 at 09:52 PM.
 
Old 09-14-2023, 09:48 AM   #17
mfoley
Senior Member
 
Registered: Oct 2008
Location: Columbus, Ohio USA
Distribution: Slackware
Posts: 2,587

Original Poster
Rep: Reputation: 179Reputation: 179
All: Great feedback from everyone! LQ has the experts. Based on everything said, I went the Sonicwall route. As it turns out, there is no cost to start as the TZ400 device comes with 2 licenses and an additional 1 user license is about $50, 5 user license about $130. These are one-time costs, not subscriptions.

I had help from an expert with Sonicwall to configure the TZ400 device and add the first user (me). I downloaded NetExtender (the VPN client) to my Windows computer and configured it with server IP, credentials, etc. This is a remote computer so basically this is the "Road Warrior" situation. Thus far, this works fine.

Perhaps last issue on this mentioned by sundialsvcs in post #16: What certificate? I didn't see any certificate configs associated with the Sonicwall VPN stuff. Are you referring to the certificate warning that comes up when one connects via RDC?
 
Old 09-14-2023, 02:14 PM   #18
yvesjv
Member
 
Registered: Sep 2015
Location: Australia
Distribution: Slackware, Devuan, Freebsd
Posts: 577

Rep: Reputation: Disabled
Something similar to this below, each client device has a unique certificate created.
https://www.sonicwall.com/support/kn...0503620790668/

I'd use openssl to create the csr and probably Digicert afterwards.
Check with your sinicwall rep.
 
Old 09-15-2023, 09:53 AM   #19
sundialsvcs
LQ Guru
 
Registered: Feb 2004
Location: SE Tennessee, USA
Distribution: Gentoo, LFS
Posts: 10,679
Blog Entries: 4

Rep: Reputation: 3947Reputation: 3947Reputation: 3947Reputation: 3947Reputation: 3947Reputation: 3947Reputation: 3947Reputation: 3947Reputation: 3947Reputation: 3947Reputation: 3947
If(!) you properly use digital certificates, both commonly-used VPN technologies (OpenVPN and IPSec) are equally reliable and secure. Tools are available for both to simplify the deployment of new road-warrior machines and the management of chores like certificate revocation. If your SonicWall has these features, feel free to exploit them: that’s what your company paid the big bucks for.

Good and easy-to-use client packages are readily available for both VPN technologies, and for every operating system. Your users “click on an icon at the top of the screen, wait for it to turn from grey to black, and that’s it.” They have no idea what actually happened, and they have no reason to care.

Per contra, PSKs = Pre-Shared Keys = Simple Passwords” will never be secure … Do not use them.

The only “truly interesting feature” of OpenVPN is its so-called tls-auth, which can conceal the presence of the VPN endpoint. Which entirely shuts down “nuisance” attempts to break in to it. (As long as you are using “port-free” UDP rather than TCP/IP … UDP being the default.)

Last edited by sundialsvcs; 09-15-2023 at 10:10 AM.
 
  


Reply

Tags
linux, sonicwall, vpn. windows



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Anybody running mixed Linux/Win server environment? petebart Linux - Server 6 07-12-2010 09:25 AM
Mixed Linux/WIndows environment on a Client/Server Network custangro Linux - Networking 3 12-06-2006 08:29 PM
Kerberos in a mixed environment cygnus-x1 Linux - Security 1 09-22-2006 10:59 AM
Backup Software for mixed environment jedimastermopar Linux - General 2 09-24-2004 03:34 PM
Remote Desktop With Mixed Environment JCScoobyRS Linux - Software 1 02-04-2004 07:16 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 06:21 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration