12-27-2012 10:54 AM - edited 03-11-2019 05:41 PM
Is Spilt-Tunneling considered as a security Risk?
Regards,
Hesham
12-27-2012 11:32 AM
Depends who you talk to :-)
IMO, yes it does pose some risk. Consider this scenario:
In a scenario where split tunneling is not allowed, the attacker will lose the connection to the infected machine every time it connects via VPN, thus lowering the risk of sensitive information being accessed.
One solution is to allow split tunneling, but attach and ACL to the group policy that only allows limited functionality.
12-27-2012 11:35 AM
A host connect to VPN service using split tunneling may be used as way for malicious external party to interact with (protected) internal resources.
Using full tunneling gives the headend side more control over actions performed by user, enforcing policies, rules etc.
At the same time a rootkit/worm/virus/bot might still be able to operate regardless of split tunneling settings.
12-27-2012 12:06 PM
Hi,
In the case when connecting to a corporate network with a work laptop for example I would go with Full Tunnel / Tunnel All instead of Split tunneling.
When you use Full Tunnel / Tunnel All
With Split Tunneling you will still have the ability to control the traffic thats entering the corporate network through the VPN but some (or maybe even most) of the traffic will totally pass all the security you might have in place normally for the user when he/she is directly connected to the corporate network.
Naturally in addition to whatever VPN implementation you go with you should take care of the security of the actual computer since without it the other parts of the security might be made useless.
Also can't forget the fact that the user has to be able to use the computer in a way that he/she doesnt make it possible for the computer to get infected by some action of his/her own. I'd imagine wether you are using Full Tunnel or Split tunnel, if the security of the actual computer and "know how" of the user aren't on a high enough level, you could still end up with the same negative result.
Though I have no doubt that in most cases the deciding factor (for a customer) when deciding between Split Tunnel and Full Tunnel is which is more convinient to the user. Sometimes you just need to exempt some of the traffic from the tunnel. And I have no doubt also that at some point those same computers wont be protected by any form of firewall.
- Jouni
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide