Yes,
several implementations...
Safe-Net sells their own hardware that can be placed between your server and
the internet access point that we use now in one setup, that works great
with DHCP dial-up as it is only restricting the server not the particular
client IP. I also have implemented PTP VPN using Xedia routers at both
ends. Xedia routers also work with Safe-Net clients using pre-shared keys
a common password) and IPSEC, and again the policy that works is to
restrict access to the server's IP to VPN traffic only, not to restrict by
the client IP. The client IP really does not matter as long as all traffic
to and from the server is encrypted. I believe that you can do the same
thing with the Cisco as well. Give it a try! Restrict based on the server
address and leave the other end of the filter at 0.0.0.0. I can not provide
you with any first hand support on Cisco VPN via their Cisco IOS as we have
not tested that yet. Maybe Q1 next year.
Good luck and let me know how you make out,
-Vaughn
PS, I love my Xedia equipment! Their VPN stuff is not the bleeding edge,
but it works goooooood! Also has incredibly simple bandwidth management
built in. Great box! I configure and monitor it from home via my browser
and it runs up to 8 T-1's aggregated or separate.
----- Original Message -----
From: "Brian Politis" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Friday, November 05, 1999 10:40 AM
Subject: RE: [IMail Forum] Security Question
> Vaugh,
>
> Are you currently using a VPN setup? We are testing using SafeNet SoftPK
> and a Cisco router. Point to Point from a static IP works beautifully.
> Getting it to work from DHCP dial-ups using certificates for
authentication
> has been a nightmare. If you have something in place that works from a
> DHCP dial-up account please let me know... At this point I am probably
going
> to go looking for a different vendor.
>
> -----Original Message-----
> From: [EMAIL PROTECTED]
> [mailto:[EMAIL PROTECTED]]On Behalf Of Vaughn Thurman
> Sent: Friday, November 05, 1999 7:30 AM
> To: [EMAIL PROTECTED]
> Subject: Re: [IMail Forum] Security Question
>
>
> Allowing POP3, IMAP4, and HTTP access to your IMAIL system will cause
> passwords to be sent over the internet in clear text. If these are mail
> only passwords then your risk is limited, but if they are "universal"
> passwords then potential security risks go up exponentially. One way
around
> that is VPN (Virtual Private Networking) so that the connection is secured
> before you even send the password. This can be accomplished by placing
VPN
> software on your router, and remote client stations that will access your
> servers across the internet. The router encrypts all outbound packets and
> the workstation decrypts them, responses from the remote workstation are
> encrypted and then decrypted by your router so IMAIL does not need to be
VPN
> aware. This suggestions does come with some costs and maintenance, but
> allows you to extend the walls of your security policy to wrap around and
> include your remote users.
>
> Short answer:
> POP3, IMAP, and IMAIL's HTTP are authenticated services and passwords are
> "sniffable" in transit.
> -V
> ----- Original Message -----
> From: imfo <[EMAIL PROTECTED]>
> To: <[EMAIL PROTECTED]>
> Sent: Thursday, November 04, 1999 8:56 AM
> Subject: [IMail Forum] Security Question
>
>
> > We run imail v5.07 on our internal network
> > Only SMTP packets are allowed IN through our firewall (Checkpoint FW-1)
> > What are the security implications of opening up each or any of
> > POP3, IMAP4, HTTP
> > to allow our users access their mailboxes from the internet.
> > I know we can install a security (encryption) module in the firewall
(for
> > some $$$), but does say allowing POP3 access only compromise our
security
> ?
> >
> > TIA
> > Ronan
> >
> >
> > Please visit http://www.ipswitch.com/support/mailing-lists.html
> > to be removed from this list.
> >
>
> Please visit http://www.ipswitch.com/support/mailing-lists.html
> to be removed from this list.
>
> Please visit http://www.ipswitch.com/support/mailing-lists.html
> to be removed from this list.
>
Please visit http://www.ipswitch.com/support/mailing-lists.html
to be removed from this list.