[itdiscuss] PPTP VPN

Bobby Stewart bStewart at brentwoodbaptist.com
Wed Nov 4 12:16:40 EST 2009


We use Kevin's method of having a separate server (except for the DMZ
part) and the PPTP endpoint server is a virtual machine so there wasn't
any additional hardware outlay.

 

Bobby Stewart
Network Analyst
Brentwood Baptist Church
Brentwood, TN
WWW.BrentwoodBaptist.com <http://WWW.BrentwoodBaptist.com> 
(615) 324-6149 office

(615) 830-0012 cell

 

From: discuss-bounces at itdiscuss.org
[mailto:discuss-bounces at itdiscuss.org] On Behalf Of Kevin Brunson
Sent: Wednesday, November 04, 2009 8:36 AM
To: 'IT Discussion Forum'
Subject: Re: [itdiscuss] PPTP VPN

 

Any port you have forwarded from your firewall to a domain controller is
a direct attack vector into your domain controller, and thus into AD.
If you have it going to an independent server (either member server or
workgroup), at least you have another step in the process.  They have to
take significantly more control of a server to use it as a jumping off
point to the rest of your network than they do to gain some piece of
data residing directly on the server.  

Even better, stick it in a DMZ, and then only open the ports users will
really need between the DMZ and the LAN.     

 

From: discuss-bounces at itdiscuss.org
[mailto:discuss-bounces at itdiscuss.org] On Behalf Of blloyd at buskercom.com
Sent: Wednesday, November 04, 2009 7:06 AM
To: discuss at itdiscuss.org
Subject: [itdiscuss] PPTP VPN

 

Just wondering, if I setup a PPTP VPN server on a domain controller, do
you think that is anymore insecure than setting it up on an independent
server?

 

Bill Lloyd 
IT Manager

 

2567 Athens Hwy.
Gainesville, GA 30507
Phone: 770-417-1604 Ext.: 250
Fax:     770-417-1747
Cell:     404-379-6963

blloyd at buskercom.com <mailto:blloyd at buskercom.com> 

This email and any accompanying attachments may contain confidential and
proprietary information. If you are not the intended recipient, you are
requested to delete this entire communication immediately. Emails cannot
be guaranteed to be secure or free of errors or viruses. The sender does
not accept any liability or responsibility for any problems that may
result from emails you receive.

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://optimus.thompsonic.com/pipermail/discuss/attachments/20091104/b702d0c5/attachment-0001.htm 
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: image/jpeg
Size: 14873 bytes
Desc: image001.jpg
Url : http://optimus.thompsonic.com/pipermail/discuss/attachments/20091104/b702d0c5/attachment-0001.jpeg 


More information about the discuss mailing list