I guess the question I have is where would you place it?  On the dirty 
segment, on a DMZ segment, or on an internal segment?  Anywhere you place 
it, it adds complexity to the routing and security controls in place.

One nice aspect of the one-box solution is you won't have two support 
contracts, two products to patch and watch for vulnerabilities for, etc.


-iden_fw

>From: "Churcher, Simon" <[EMAIL PROTECTED]>
>To: "'[EMAIL PROTECTED]'"  
><[EMAIL PROTECTED]>
>Subject: [FW1] Is split tunneling secure
>Date: Fri, 8 Dec 2000 16:41:45 -0000
>
>
>Hi All,
>
>I have seen a couple of arguments in our corporation about whether an
>integrated VPN/Firewall (Checkpoint) is more or less secure than a two box
>solution (ie a Nortel contivity for the VPN and a Nokia Firewall).
>
>I'm strongly leaning toward the integrated solution being more secure.
>
>Anyone have any comments on this?
>
>thanks,
>
>simon
>
>
>________________________________________________________________
>The information contained in this message is intended only for the 
>recipient, may be privileged and confidential and protected from 
>disclosure. If the reader of this message is not the intended recipient, or 
>an employee or agent responsible for delivering this message to the 
>intended recipient, please be aware that any dissemination or copying of 
>this communication is strictly prohibited. If you have received this 
>communication in error, please immediately notify us by replying to the 
>message and deleting it from your computer.
>
>Thank you,
>Standard & Poor's
>
>
>================================================================================
>      To unsubscribe from this mailing list, please see the instructions at
>                http://www.checkpoint.com/services/mailing.html
>================================================================================

_____________________________________________________________________________________
Get more from the Web.  FREE MSN Explorer download : http://explorer.msn.com



================================================================================
     To unsubscribe from this mailing list, please see the instructions at
               http://www.checkpoint.com/services/mailing.html
================================================================================

Reply via email to