Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Nortel Contivity 2600 |
|---|---|
| Date: | Sun, 04 Sep 2005 14:39:44 +0400 |
I am facing a similar position, however my vendor insists that Nortel VPN has to be in Internet .. It cannot use natted IP.. I do not exactly buy this suggestion but am still looking for conclusive evidence to confront him with this.. Any help appreciated Regards Samir ----- Original Message ----- From: "Rodrigo Blanco" <rodrigo.blanco.r@gmail.com> To: <camfischer@gmail.com> Cc: <pen-test@securityfocus.com> Sent: Saturday, September 03, 2005 3:04 PM Subject: Re: Nortel Contivity 2600 Hello, I would think of DoS at first (certain versions of the Conctivity have DoS vulnerabilities). Although its VXworks architecture seems very robust, it does not look right to me to have a VPN concentrator directly accessible on the Inernet, why not place it in a DMZ (firewall protection makes sense, and so does IDS/IPS)? By the way, bear in mind Contivity also has a firewall module that can run on its same platform, this could be very reccomendable if you are to place it directly on the Internet. Hope this helps, Rodrigo. On 9/1/05, Cam Fischer <camfischer@gmail.com> wrote:
Hi list! I am looking for good reasons why I should move a Nortel Contivity 2600 VPN device behind a firewall. Currently the device sits on the internet, and is used for VPN traffic from other offices, and also for VPN dial-in users. Are there any risks with this configuration? What comments can be made around whether or not I should be placing this behind the firewall / IDS.... Thanks!
---------------------------------------------------------------------------- -- Audit your website security with Acunetix Web Vulnerability Scanner: Hackers are concentrating their efforts on attacking applications on your website. Up to 75% of cyber attacks are launched on shopping carts, forms, login pages, dynamic content etc. Firewalls, SSL and locked-down servers are futile against web application hacking. Check your website for vulnerabilities to SQL injection, Cross site scripting and other web attacks before hackers do! Download Trial at: http://www.securityfocus.com/sponsor/pen-test_050831 ---------------------------------------------------------------------------- --- ------------------------------------------------------------------------------ Audit your website security with Acunetix Web Vulnerability Scanner: Hackers are concentrating their efforts on attacking applications on your website. Up to 75% of cyber attacks are launched on shopping carts, forms, login pages, dynamic content etc. Firewalls, SSL and locked-down servers are futile against web application hacking. Check your website for vulnerabilities to SQL injection, Cross site scripting and other web attacks before hackers do! Download Trial at: http://www.securityfocus.com/sponsor/pen-test_050831 -------------------------------------------------------------------------------
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: Nortel Contivity 2600, Rodrigo Blanco |
|---|---|
| Next by Date: | RE: Business justification for pentesting, Vic N |
| Previous by Thread: | Re: Nortel Contivity 2600, Rodrigo Blanco |
| Next by Thread: | Re: Nortel Contivity 2600, Rodrigo Blanco |
| Indexes: | [Date] [Thread] [Top] [All Lists] |