home » solutions »
Wireless networking offers great business benefits but has the potential to totally compromise network and information security. Operating inside the perimeter firewall, yet accessible from outside, insecure wireless networks render the computers and systems on the supposedly 'protected' network wide-open to attack. Like many new technologies, ease-of-use was the initial developer's goal for wireless networking; security was an afterthought! Only the latest wireless security affords any credible resistance to attack; early systems like WEP can be easily broken.
A widely used solution to protect wireless connections is Virtual Private Network (VPN) technology. Although very secure, IPSec VPNs are relatively difficult to configure and use; a problem solved by Advanced Firewall using clientless L2TP VPN technology:
- L2TP VPN between the user PCs and SmoothWall Advanced Firewall
- 3DES data encryption to prevent eavesdroppers reading confidential information
- Connection authentication using x509 certificates and Microsoft Active Directory®, Novell eDirectory™ or other LDAP authentication systems
- Dedicated wireless network zone enables Advanced Firewall to control user access to the Internet and local network services, applications and servers
With L2TP VPN, the average Microsoft Office user can set-up an L2TP connection in only a couple of minutes. Once the VPN tunnel is established, the user's PC is protected from all other computers on the wireless network, as it will reject all traffic that does not originate from the Advanced Firewall remote gateway.
Advanced Firewall also supports wireless guest users not using L2TP VPN, who are isolated from authenticated L2TP VPN users and local network services. Guests, such as clients, visitors and temporary staff can be restricted to a captive portal of Internet services and websites controlled by the guest user security policies.
Wired network users can also benefit from secure VPN connections provided by Advanced Firewall, with the encryption of confidential information to prevent it being read by unauthorized persons on the local network. For both wireless and wired networks, IPSec VPN can be used as an alternative to L2TP, allowing the creation of secure local inter-network bridges between physically separated offices and buildings.
|
|