Figure 154 Hardware VPN Device Authentication
[View full size image]
1.1 would Ifte Lo use ihe VPN, $ Whg( are yogf ■ciedemjais1
[View full size image]
1.1 would Ifte Lo use ihe VPN, $ Whg( are yogf ■ciedemjais1

- <3aleway
This authentication event generally consists of opening a web page on the gateway and often involves the central site as well to prevent the edge devices from needing to maintain user credential information. The authentication event should be protected by SSL or some other secure mechanism and ideally should use OTP. This authentication provides some assurance that the individual using the hardware VPN device is authorized to do so. Unfortunately, this still does not encrypt the communications between the end system and the hardware gateway. This is by design because our requirement is to have no special software requirements on the end systems. This authentication approach is problematic, though, for the power teleworker who has many systems because some devices might not be able to perform the authentication function requested by the VPN device.
Furthermore, these systems usually limit access only by IP or Media Access Control (MAC) address. Because these attributes can easily be spoofed by the attacker, the resulting security is somewhat suspect. In the end, you really must trust the physical network behind any hardware VPN device. You can do this through a combination of user education, strong policies, automated network audit, and crossed fingers. This is one of the cases in which the business needs can override the security requirements, and there is only so much you as a security architect can do. Because this is a user's home, you can't very well install a security camera or keypad at the front door.
Without these user controls, however, there is no difference between a hardware VPN client and a large site-to-site VPN comprised of very small branch nodes. This is because, without user authentication, you have no Xauth. With no Xauth, you are using device identity only. This makes digital certificates almost mandatory because making authentication decisions on a preshared key alone is not recommended for networks of any reasonable size (Chapter 10). Figure 15-5 shows the hardware-based teleworker design.
Figure 15-5. Hardware-Based Teleworker Security Design
Figure 15-5. Hardware-Based Teleworker Security Design
The benefit of these systems is they are often built to be provisioned from the head end. So, you could have hundreds of hardware devices that get software and configuration updates from the central site as needed. This eases the management burden of maintaining the configurations at each site and should be a requirement for your VPN vendor. This same requirement applies to software VPN as well and is fairly pervasive in popular software VPN solutions today.
WARNING
This ease of management is somewhat complicated, though, if you aren't checking user credentials prior to granting VPN access (as described earlier). Here you will need unique preshared keys or digital certificates per device.
The requirements of the hardware VPN device are very similar to the software VPN solution:
• Network or session cryptography The hardware device should support cryptographically secure communications from the device to the central site.
• OTP Users accessing the hardware VPN device can optionally be authenticated prior to VPN access as described earlier in this section.
• Stateful firewall If clear access to the Internet is provided prior to VPN establishment or by split tunneling, a stateful firewall should be supported. This is considered an optional component because most deployments do not support split tunneling (Chapter 10).
• Other router/security features The capabilities of these devices vary greatly from vendor to vendor. In some cases, you might desire quality of service (QoS) controls or more advanced security capabilities (IDS). These functions are considered optional because they are not core to the requirements of this book's teleworker environment (though they may be core to your organization's teleworker requirements).
Continue reading here: Figure 167 Outof Band Management with PVLANs and Firewall
Was this article helpful?
Readers' Questions
-
j7 months ago
- Reply