Security Infrastructure Overview - VPN Suresh Ramasamy.

14
Security Security Infrastructure Infrastructure Overview - VPN Overview - VPN Suresh Ramasamy Suresh Ramasamy

Transcript of Security Infrastructure Overview - VPN Suresh Ramasamy.

Page 1: Security Infrastructure Overview - VPN Suresh Ramasamy.

Security Infrastructure Security Infrastructure Overview - VPNOverview - VPN

Suresh RamasamySuresh Ramasamy

Page 2: Security Infrastructure Overview - VPN Suresh Ramasamy.

AgendaAgenda

• What is VPN? What is VPN?

• Types of VPNTypes of VPN

• SSL vs IPsecSSL vs IPsec

• Design ConsiderationsDesign Considerations

• Questions? Questions?

Page 3: Security Infrastructure Overview - VPN Suresh Ramasamy.

What is VPN? What is VPN?

• Virtual Private Network allows security Virtual Private Network allows security connectivity, either one to one, or one connectivity, either one to one, or one to many.to many.

Page 4: Security Infrastructure Overview - VPN Suresh Ramasamy.

Your NetworkYour Network

Page 5: Security Infrastructure Overview - VPN Suresh Ramasamy.

Why do you need VPN?Why do you need VPN?

• Secure access to your officeSecure access to your office

• Secure tunnelling through public Secure tunnelling through public network from one site to anothernetwork from one site to another

• Encrypted Encrypted

• To reach networks with private IP To reach networks with private IP allocation (RFC1918)allocation (RFC1918)

Page 6: Security Infrastructure Overview - VPN Suresh Ramasamy.

Types of VPNTypes of VPN

• Remote Access VPNRemote Access VPN

• Site to Site VPNSite to Site VPN

Page 7: Security Infrastructure Overview - VPN Suresh Ramasamy.

VPN – the big pictureVPN – the big picture

Page 8: Security Infrastructure Overview - VPN Suresh Ramasamy.

Remote Access VPNRemote Access VPN

Page 9: Security Infrastructure Overview - VPN Suresh Ramasamy.

Site to Site VPNSite to Site VPN

Page 10: Security Infrastructure Overview - VPN Suresh Ramasamy.

SSL Based VPNSSL Based VPN

Page 11: Security Infrastructure Overview - VPN Suresh Ramasamy.

SSL vs IPsecSSL vs IPsec

• SSL requires browser with 128bit SSL requires browser with 128bit encryption supportencryption support

• IPsec requires client (Windows some IPsec requires client (Windows some exceptions)exceptions)

• Mode of authentication, supports Mode of authentication, supports digital certificate and password based digital certificate and password based authenticationauthentication

• Multi factor capable for IPSec (device Multi factor capable for IPSec (device dependent)dependent)

Page 12: Security Infrastructure Overview - VPN Suresh Ramasamy.

Design ConsiderationsDesign Considerations

• Placement of VPNPlacement of VPN– Inside or outside of firewall?Inside or outside of firewall?

• Type of AuthenticationType of Authentication– Password vs. Digital Certs?Password vs. Digital Certs?

• Factor of AuthenticationFactor of Authentication– Single Factor, Multi Factor, Token BasedSingle Factor, Multi Factor, Token Based– One time passwords? (RSA SecurID)One time passwords? (RSA SecurID)

Page 13: Security Infrastructure Overview - VPN Suresh Ramasamy.

ResourcesResources

• http://mia.ece.uic.edu/~papers/volans/thttp://mia.ece.uic.edu/~papers/volans/table.htmlable.html

Page 14: Security Infrastructure Overview - VPN Suresh Ramasamy.

Suggestions? Suggestions?