General VPN question

General VPN question

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
General VPN question John Bosley 01-05-2006
Posted by John Bosley on January 5, 2006, 4:35 am
If you were  Registered and logged in, you could reply and use other advanced thread options
If an employee working from their home pc connects to a network using
PPTP/VPN and their pc has a virus, that virus can then attempt to spread
onto the attached network. The network has enterprise level virus scanning
on all machines. What technologies exist that can help mitigate this risk?
Is there any way to help ensure that a connecting machine is virus free and
fully patched?








Posted by Miha Pihler [MVP] on January 5, 2006, 4:57 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi John,

There are some solutions out there and one of them is VPN Quarantine that
can be achieved with Microsoft ISA Server 2004 (or RRAS Server on Windows
Server 2003).

In this case once the computer is connected to VPN, it is put into
quarantine network and does not have access to LAN yet. It is first checked
for what you want. E.g. does it have antivirus installed and is antivirus
running. Is antivirus up-to-date. Does a computer have all critical patches
installed etc...

VPN Roaming Clients and Quarantine Control in ISA Server 2004 Enterprise
Edition
http://www.microsoft.com/technet/prodtechnol/isa/2004/plan/vpn_roaming_clients_quarantine_control_ee.mspx

Implementing Quarantine Services with Microsoft Virtual Private Network
Planning Guide
http://www.microsoft.com/technet/security/prodtech/windowsserver2003/quarantineservices/default.mspx

Network Access Quarantine Control in Windows Server 2003
http://www.microsoft.com/windowsserver2003/techinfo/overview/quarantine.mspx

--
Mike
Microsoft MVP - Windows Security

> If an employee working from their home pc connects to a network using
> PPTP/VPN and their pc has a virus, that virus can then attempt to spread
> onto the attached network. The network has enterprise level virus
> scanning on all machines. What technologies exist that can help mitigate
> this risk? Is there any way to help ensure that a connecting machine is
> virus free and fully patched?
>
>
>
>
>
>
>



Similar ThreadsPosted
RE: General PKI Question July 8, 2005, 9:07 am
General EFS Question November 17, 2006, 10:16 am
General Network Security question October 19, 2005, 4:19 am
General antispyware question for - enterprise deployment August 5, 2005, 5:31 pm
firewall question and windows installer/spyware question September 24, 2006, 8:48 am
General Recommendation November 8, 2006, 10:33 am
IE6 and OE6 security in general March 7, 2007, 4:16 pm
General Recommendations April 25, 2007, 11:47 am
AVG 7/8 - general story April 24, 2008, 12:21 pm
Network security general discussion April 18, 2008, 12:24 pm

The site map in XML format XML site map

Contact Us | Privacy Policy