cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
798
Views
0
Helpful
3
Replies

PIX Firewall and VPN Ports

rob.wright
Level 1
Level 1

Question of convenience: is it fairly safe to permit outbound ports 500, 50 and 10000 to any outside address for VPN connections without compromising security?

Tired of setting up inside-to-outside statics on my firewall for every VPN session that requires ESP and GRE in our NAT environment.

3 Replies 3

benhur.p
Level 1
Level 1

I guess this is not safe;

mikegallagher
Level 1
Level 1

Interesting question with no simple answer. What is deemed "safe" or "not safe" is directly dependant on your company's security policy.

Mike

jasobrown
Level 1
Level 1

I would definitly say no ... Having someone on your internal network that has VPN access (that you may or maynot know of) to anywhere on the internet that you have no control of what traffic they are passing is in no way "secure" IMHO