|
|
Scott Merrill wrote: OpenVPN has the same functionality as other commercial VPN solutions in this regard - namely that you can set per-user firewall settings. And that's it.Hi everyone. e.g user "salesguy" comes in, and the VPN server sets a ACL list limiting what internal hosts he can reach (say Intranet web server and Email). User "admin" comes in and the VPN server gives access to the entire network. What you want is really part of the newer "Network Admission Control" paradigm being thrown around by the likes of Cisco and Microsoft. This issue you are referring to isn't specific to VPN - you need to "policy" your own wired/wireless networks too as well as remote access. And again, none of this technology can stop an authorized user from downloading something they are allowed to download. Actually, I take that back - maybe a NIDS could do that - but you'd need a totally robust Document Classification system to be in place on your network before such a thing has much chance of working... -- Cheers Jason Haar Information Security Manager, Trimble Navigation Ltd. Phone: +64 3 9635 377 Fax: +64 3 9635 417 PGP Fingerprint: 7A2E 0407 C9A6 CAF6 2B9F 8422 C063 5EBB FE1D 66D1
Warning: require_once(../../../archive_common.php) [function.require-once]: failed to open stream: No such file or directory in /home/openvpn/domains/openvpn.net/public_html/archive/openvpn-users/2005-03/msg00062.html on line 214 Fatal error: require_once() [function.require]: Failed opening required '../../../archive_common.php' (include_path='/usr/local/lib/php') in /home/openvpn/domains/openvpn.net/public_html/archive/openvpn-users/2005-03/msg00062.html on line 214 |