Designing Access Controls
Make Decisions about Remote Access (VPN)
Table 3-33. PCU’s Preliminary Decisions for VPN Options
Factor | Weight | VPN Protocol | Authentication | Encryption | Client | Gateway | |||||||
|
|
|
| Method |
|
|
|
|
|
|
|
| |
|
|
|
|
|
|
|
|
|
| ||||
Security | 3 | • | Option 1: | Digital | • | ESP with | Any | Any |
| ||||
|
|
| IPsec with | certificates |
| AES |
|
|
|
|
| ||
|
|
| IKE |
|
| • | AH with |
|
|
|
|
| |
|
| • | Option 2: |
|
|
| SHA1 |
|
|
|
|
| |
|
|
| L2TP3/IPsec |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| ||
User type and | 2 | • | Option 1: | • | Option 1: | • | Option 1: | • | Option 1: | • | Option 1: | ||
sophistication |
|
| PPTP |
|
| MPPE |
| Windows |
| Windows Server | |||
|
| • | Option 2: | • | Option 2: | • | Option 2: |
| native |
| 2000 or 2003 | ||
|
|
| IPsec with |
| Digital |
| Any | • | Option 2: | • | Option 2: | ||
|
|
| IKE |
| certificates |
|
|
|
| ProCurve VPN |
| Secure Router | |
|
|
|
|
|
|
|
|
|
| Client with |
| 7000dl | |
|
|
|
|
|
|
|
|
|
| preconfigured | • | For | |
|
|
|
|
|
|
|
|
|
| policy |
| ||
|
|
|
|
|
|
|
|
|
|
|
| vendors: | |
|
|
|
|
|
|
|
|
|
|
|
| – | Software |
|
|
|
|
|
|
|
|
|
|
|
|
| built into |
|
|
|
|
|
|
|
|
|
|
|
|
| router or |
|
|
|
|
|
|
|
|
|
|
|
|
| firewall |
|
|
|
|
|
|
|
|
|
|
|
| – | Hardware |
|
|
|
|
|
|
|
|
|
|
|
|
| appliance |
|
|
|
|
|
|
|
| ||||||
Administrative | 2 | IPsec with IKE | Preshared key | Any |
| ProCurve VPN | Secure Router | ||||||
workload and |
|
|
|
|
|
|
|
| Client | 7000dl | |||
IT budget |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| ||||
Endpoint and | 1 | • | Option 1: | • | Option 1: | • | Option 1: | For either: | For either: | ||||
administrative |
|
| PPTP |
|
| MPPE | Windows native | Any that supports | |||||
control |
| • | Option 2: | • | Option 2: | • | Option 2: | or Mac OS X | PPTP or L2TP/IPsec | ||||
|
|
| L2TP/IPsec |
| Preshared |
| Any | native |
|
|
| ||
|
|
|
|
| key |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| ||||||
Existing | 2 | IPsec with IKE | Digital | Any |
| ProCurve VPN | Secure Router | ||||||
network |
|
|
| certificates |
|
|
| Client | 7000dl | ||||
infrastructure |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| ||||||
Total |
| IPsec with IKE | Digital | • | Preferred | ProCurve VPN | Secure Router | ||||||
|
|
|
| certificates |
| policy: | Client, possibly | 7000dl | |||||
|
|
|
|
|
|
| – | ESP | with pre- |
|
|
| |
|
|
|
|
|
|
|
| with | configured policy |
|
|
| |
|
|
|
|
|
|
|
| AES |
|
|
|
|
|
|
|
|
|
|
|
| – | AH |
|
|
|
|
|
|
|
|
|
|
|
|
| with |
|
|
|
|
|
|
|
|
|
|
|
|
| SHA1 |
|
|
|
|
|
|
|
|
|
|
| • | Other |
|
|
|
|
| |
|
|
|
|
|
|
| policies to |
|
|
|
|
| |
|
|
|
|
|
|
| widen |
|
|
|
|
| |
|
|
|
|
|
|
| support |
|
|
|
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
|