Link to home
Start Free TrialLog in
Avatar of cemack
cemack

asked on

VPN choice guidance needed - PPTP v L2TP on specific hardware

Hi,

Firstly, I am new to firewalls/vpn, network infrastructure in general, so I'm asking this question for all you security experts out there.

My scenario:

I have a single web server running w2k that is running behind a zyxel firewall hosted at a remote location.  The server has 2 network cards.  One is attached to the firewall and the other is currently disabled.

I need to create a VPN between my office and the server.

As I see it, I have 3 options:

1.  I can create a PPTP connection directly to the firewall (as the firewall supports this, but I need to use zyxel firewall client software)

2.  I can create a PPTP VPN server on the web server, and set the firewall to allow the connnection through (don't see any advantage to this however, except I wouldn't have to buy the zyxel firewall client)

3.  I can enable the second network card, use TCP/IP filtering on it to disable everything except what is required to enable L2TP, set up a VPN server on the web server and use it.   (the firewall does not allow L2TP passthrough, and is not an L2TP VPN Server)

I guess my question is, L2TP offers better security, but if it means having to enable another network card which wouldn't be behind a firewall, is it worth it?

Any discussion on this is more than welcome!


Chris

ASKER CERTIFIED SOLUTION
Avatar of KingHollis
KingHollis
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of TooKoolKris
TooKoolKris

Only somebody fully knowledged in the setup of your environment can really answer your question. Only you can decide if allowing communication on this other NIC is worth the security risks involved. Can it be done, sure. Yes you can control the filtering on this NIC as well. However what you are doing is effectively taking away communication control from the firewall and putting into the hands of your NIC and the policy that controls the communication of this NIC. If you feel confident enough about your ability to control the communication across this NIC then I would say have at it. However if you don't then I would say let the firewall do its job and find another way to accomplish your task.
Avatar of cemack

ASKER

Moderator:

Can this be split say 350/150 between KingHollis and TooKookKris please?  

Thanks to both for your replies, higher points to KingHollis just because he's a bit more specific.

I've decided to go with the straightforward option of PPTP using the firewall VPN server as security isn't my biggest concern, and it offloads the VPN processing to the firewall.
Chris:

Good move! Best of luck!

h.