Determining where you will terminate your VPNs
Determining where you will terminate your VPNs
Figure 2-4. VPN tunnel terminating on trusted burb
Figure 2-5. VPN tunnel terminating on a virtual burb
You can configure a VPN security association on Sidewinder to terminate in any burb. For example, Figure
Trusted | Internet | ||
burb | burb | ||
Internet | |||
Protected Network |
|
| |
Sidewinder | = VPN tunnel | ||
|
| ||
|
| = Data |
Figure 2-5 shows another option that allows you to terminate VPN traffic in a "virtual" burb. A virtual burb is a burb that does not contain a network interface card. The sole purpose of a virtual burb is to serve as a logical endpoint for a VPN association.
Trusted | Internet |
|
burb | burb |
|
Proxies | ||
|
| |
Protected Network |
| Internet |
|
| |
Proxies |
|
|
Virtual |
| |
burb |
| |
Sidewinder | = VPN tunnel | |
|
| = Data |
Terminating a VPN association in a virtual burb accomplishes two important goals:
Separation of VPN traffic from
Enforce a security policy that applies strictly to your VPN users
By terminating the VPN in a virtual burb you effectively isolate the VPN traffic from
Note: The VPN implementation depicted in Figure
Planning Your VPN Configuration | |
|
|