 




<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Overheard in the tech blogosphere &#187; SSL VPN</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/overheard/tag/ssl-vpn/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/overheard</link>
	<description>A Whatis.com blog</description>
	<lastBuildDate>Tue, 19 Feb 2013 14:32:17 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Overheard &#8211; Security and the SSL VPN</title>
		<link>http://itknowledgeexchange.techtarget.com/overheard/overheard-security-and-the-ssl-vpn/</link>
		<comments>http://itknowledgeexchange.techtarget.com/overheard/overheard-security-and-the-ssl-vpn/#comments</comments>
		<pubDate>Mon, 19 Jan 2009 14:06:21 +0000</pubDate>
		<dc:creator>Margaret Rouse</dc:creator>
				<category><![CDATA[IP VPN]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[SSL VPN]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/overheard/?p=1840</guid>
		<description><![CDATA[Despite the popularity of SSL VPNs, they are not intended to replace Internet Protocol Security VPNs. The two VPN technologies are complementary and address separate network architectures and business needs. William Jackson, quoting from Special Publication 800-113 I started to add to a short definition we have for FIPS &#8211; Federal Information Processing Standard &#8211; [...]]]></description>
				<content:encoded><![CDATA[<table border="0" cellspacing="5" cellpadding="5">
<tbody>
<tr>
<td><a href="http://cdn.ttgtmedia.com/ITKE/uploads/blogs.dir/8/files/2009/01/laptop_security.jpg"><img class="alignnone size-medium wp-image-1853" src="http://cdn.ttgtmedia.com/ITKE/uploads/blogs.dir/8/files/2009/01/laptop_security.jpg" alt="" width="75" height="68" /></a></td>
<td>Despite the popularity of SSL VPNs, they are not intended to replace Internet Protocol Security VPNs. The two VPN technologies are complementary and address separate network architectures and business needs.</p>
<p>William Jackson, quoting from <a href="http://csrc.nist.gov/publications/nistpubs/800-113/SP800-113.pdf">Special Publication 800-113</a></td>
</tr>
</tbody>
</table>
<p>I started to add to a short definition we have for <a href="http://whatis.techtarget.com/definition/0,,sid9_gci213964,00.html#">FIPS</a> &#8211; Federal Information Processing Standard &#8211; to promote our newest site, <a href="http://searchcompliance.techtarget.com">SearchCompliance.com</a> and somehow I got turned around and started reading about SSL VPNs.  (Somewhere in my reading I discovered that Federal agencies deploying SSL VPNs have to configure them to only allow FIPS-compliant cryptography and SSL.)</p>
<p>What got my attention was a blog post by someone named Shakya about how <a href="http://searchsecurity.techtarget.com/sDefinition/0,,sid14_gci1201867,00.html">SSL VPNs</a> are vulnerable to <a href="http://searchsecurity.techtarget.com/sDefinition/0,,sid14_gci499492,00.html">man-in-the-middle</a> attacks. The reason? Because many SSL VPNs weren&#8217;t built with wireless in mind.  Shakya does a really good job <a href="http://gutturola.blogspot.com/2008/12/hacking-online-banking-and-credit-card.html">explaining the vulnerability</a> in simple terms.  His blog is not for the faint of heart, but it reinforces this warning &#8212; never check your bank account balance at Starbucks!</p>
<p>Circling round again to SSL VPNs, the Department of Commerce put out a <a href="http://csrc.nist.gov/publications/nistpubs/800-113/SP800-113.pdf">Guide to SSL VPNs</a> last summer.  It&#8217;s really well written. If you are making a business case for implementing an SSL VPN or you&#8217;re an admin who needs help with documentation for the business side, I suggest you take a look.  As the report from  points out, an SSL VPN is not a magic security bullet.  There are still many instances when a VPN application installed on the end-user&#8217;s computer is the way to go.  Not everything will be done in the cloud.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/overheard/overheard-security-and-the-ssl-vpn/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
