Designing Access Controls

Make Decisions about Remote Access (VPN)

Table 3-33. PCU’s Preliminary Decisions for VPN Options

Factor

Weight

VPN Protocol

Authentication

Encryption

Client

Gateway

 

 

 

 

Method

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Security

3

Option 1:

Digital

ESP with

Any

Any

 

 

 

 

IPsec with

certificates

 

AES

 

 

 

 

 

 

 

 

IKE

 

 

AH with

 

 

 

 

 

 

 

Option 2:

 

 

 

SHA1

 

 

 

 

 

 

 

 

L2TP3/IPsec

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

User type and

2

Option 1:

Option 1:

Option 1:

Option 1:

Option 1:

sophistication

 

 

PPTP

 

EAP-TLS

 

MPPE

 

Windows

 

Windows Server

 

 

Option 2:

Option 2:

Option 2:

 

native

 

2000 or 2003

 

 

 

IPsec with

 

Digital

 

Any

Option 2:

Option 2:

 

 

 

IKE

 

certificates

 

 

 

 

ProCurve VPN

 

Secure Router

 

 

 

 

 

 

 

 

 

 

Client with

 

7000dl

 

 

 

 

 

 

 

 

 

 

preconfigured

For

 

 

 

 

 

 

 

 

 

 

policy

 

either—Other

 

 

 

 

 

 

 

 

 

 

 

 

vendors:

 

 

 

 

 

 

 

 

 

 

 

 

Software

 

 

 

 

 

 

 

 

 

 

 

 

 

built into

 

 

 

 

 

 

 

 

 

 

 

 

 

router or

 

 

 

 

 

 

 

 

 

 

 

 

 

firewall

 

 

 

 

 

 

 

 

 

 

 

 

Hardware

 

 

 

 

 

 

 

 

 

 

 

 

 

appliance

 

 

 

 

 

 

 

 

Administrative

2

IPsec with IKE

Preshared key

Any

 

ProCurve VPN

Secure Router

workload and

 

 

 

 

 

 

 

 

Client

7000dl

IT budget

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Endpoint and

1

Option 1:

Option 1:

Option 1:

For either:

For either:

administrative

 

 

PPTP

 

MS-CHAPv2

 

MPPE

Windows native

Any that supports

control

 

Option 2:

Option 2:

Option 2:

or Mac OS X

PPTP or L2TP/IPsec

 

 

 

L2TP/IPsec

 

Preshared

 

Any

native

 

 

 

 

 

 

 

 

key

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Existing

2

IPsec with IKE

Digital

Any

 

ProCurve VPN

Secure Router

network

 

 

 

certificates

 

 

 

Client

7000dl

infrastructure

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Total

 

IPsec with IKE

Digital

Preferred

ProCurve VPN

Secure Router

 

 

 

 

certificates

 

policy:

Client, possibly

7000dl

 

 

 

 

 

 

 

ESP

with pre-

 

 

 

 

 

 

 

 

 

 

 

with

configured policy

 

 

 

 

 

 

 

 

 

 

 

AES

 

 

 

 

 

 

 

 

 

 

 

 

AH

 

 

 

 

 

 

 

 

 

 

 

 

 

with

 

 

 

 

 

 

 

 

 

 

 

 

 

SHA1

 

 

 

 

 

 

 

 

 

 

 

Other

 

 

 

 

 

 

 

 

 

 

 

 

policies to

 

 

 

 

 

 

 

 

 

 

 

 

widen

 

 

 

 

 

 

 

 

 

 

 

 

support

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

3-50