101communication LLC CertCities.com -- The Ultimate Site for Certified IT Professionals
   Certification Communities:  Home  Microsoft®  Cisco®  Oracle®  A+/Network+"  Linux/Unix  More  
    CertCities.com is proud to present our sponsor this month: Thomson Prometric
Editorial
Choose a Cert
News
Exam Reviews
Features
Columns
Salary Surveys
Free Newsletter
Cert on the Cheap
Resources
Forums
Practice Exams
Cert Basics
Links Library
Tips
Pop Quiz
Industry Releases
Windows Certs
Job Search
Conferences
Contributors
About Us
Search


Advanced Search
CertCities.com

CertCities.com
Let us know what you
think! E-mail us at:
.. Home .. Certifications .. Cisco .. Columns ..Cisco Column Thursday, August 21, 2003

TechMentor Conference & Expo PDF Brochure - Download It Now!

Save 30% on CertCities.com's Guide to IT Certification on the Cheap

 Link State Update   Eric Quinn
Eric Quinn



 Paranoia Is Good
Use Cisco's VPN Concentrator with ZoneAlarm to protect your users -- and yourself.
by Eric Quinn  
11/13/2002 -- Paranoia is good! And no, I'm not referring to the old role-playing game. I'm referring to the state that most security people live in. Change another well-known saying to "Even paranoid network admins have intruders," and you'll have a good idea of where this month's column is going.

The key to strong network security is to trust the users as far as you can throw them. Many companies who make money from protecting the perimeter of your network like to talk up the threats from outside. It's true that the most costly and knowledgeable threats are on the outside, but that doesn't change the fact that most network problems are caused directly or indirectly by your users; people that are trusted by the organization.

These same users need to connect to your network. Of course, it's a lot easier to manage computers that don't leave the building than ones that do. A muscle next to the left eye starts to twitch when you consider how many executives allow their children to use their laptop.

For these potentially untrustworthy devices that need to connect to your network remotely, Cisco has given users the option of creating VPN tunnels with firewall software configured on the remote workstation. Imaging being able to filter out inappropriate packets directly at the workstation, instead of configuring a CPU-intensive access list on a router or firewall.

First, you need to be using VPN Concentrator 3.5 or better along with client software of 3.5 or better. As for firewall support, while Cisco promises to increase the size of the list, the only two popular firewalls currently supported are ZoneAlarm and BlackICE Defender. At this time, ZoneAlarm is preferred because of its support for Concentrator-configured client protection policies. This is where the admin can configure Concentrator with a security policy and then, when the user creates a tunnel, the policy is pushed down to the user, configuring the firewall.

The protection policy is configured just like any interface filter is on the Concentrator. The difference is that rather than placing the policy on a physical interface, it needs to be linked to the firewall setting of a group. Go over to Configuration, Settings and choose the group you want to configure. Modify the group and select "Client FW" for firewall configuration. Select "Policy Pushed" and choose the policy you just configured.

Another option is to have a policy from a Zone Labs Integrity server sent down to the client. This type of server is used in large environments to keep a consistent policy across many different VPN Concentrators and clients. If you start having trouble keeping the policies for the groups up to date across your many concentrators, you may wish to explore this product.

With a bit of luck, some technology and a healthy dose of paranoia, the corporate network can be a bit safer.


Eric Quinn, CCNP, CCDP, CCSI, is a security instructor and consultant. He is also co-author of the CCNP Remote Access Exam Cram by Coriolis Press. He writes the “Link State Update” column for TCPmag.com, and is a contributing editor for CertCities.com. Reach him at .

 

More articles by Eric Quinn:

Post your comment below, or better yet, go to our Discussion Forums and really post your mind.
Current CertCities.com user Comments for "Paranoia Is Good"
11/22/02 - Anonymous says: Looking at Eric Quinn's Picture makes me paranoid. The picture is a nice touch to this article.
Add your comment here:
Name: (optional)
Location: (optional)
E-mail Address: (optional)
Comments:  
 
top

Sponsored Link:
Don’t let your IT Investment Go to Waste: Get Certified with Thomson Prometric!

Home | Microsoft | Cisco | Oracle | A+/Network+ | Linux/Unix | MOUS | List of Certs
Advertise | Certification Basics | Conferences | Contact Us | Contributors | Features | Forums | Links | News | Pop Quiz | Industry Releases | Reviews | Tips
Search | Site Map | MCPmag.com | TCPmag.com | OfficeCert.com | TechMentor Conferences | 101communications | Privacy Policy
This Web site is not sponsored by, endorsed by or affiliated with Cisco Systems, Inc., Microsoft Corp., Oracle Corp., The Computing Technology Industry Association, Linus Torvolds, or any other certification or technology vendor. Cisco® and Cisco Systems® are registered trademarks of Cisco Systems, Inc. Microsoft, Windows and Windows NT are either registered trademarks or trademarks of Microsoft Corp. Oracle® is a registered trademark of Oracle Corp. A+®, i-Net+™, Network+™, and Server+™ are trademarks and registered trademarks of The Computing Technology Industry Association. (CompTIA). Linux™ is a registered trademark of Linus Torvalds. All other trademarks belong to their respective owners.
All content copyright 2000-03 101communications LLC, unless otherwise noted. All rights reserved.
Reprints allowed with written permission from the publisher. For more information, e-mail