Selecting and Hardening Remote Access VPN Solutions [pdf]
media.defense.gov
Selecting and Hardening Remote Access VPN Solutions [pdf]
1–10 of 41 posts
Re: Selecting and Hardening Remote Access VPN Solutions [pdf]
#2Unsurprisingly no mention of wireguard, as it's not FIPS. However, unless you need FIPS compliance, it seems like the way to go these days.
Re: Selecting and Hardening Remote Access VPN Solutions [pdf]
#3Re: Selecting and Hardening Remote Access VPN Solutions [pdf]
#4Layer 7 solutions provide so much more capacity for granular AuthZ, and thereby eliminate the "soft underbelly" of corporate networks.
Re: Selecting and Hardening Remote Access VPN Solutions [pdf]
#5Strange how this implies that the end-all-be-all of VPNs is IPsec. I would've loved to hear their opinion on wireguard and this generation of mesh VPNs
Re: Selecting and Hardening Remote Access VPN Solutions [pdf]
#6Re: Selecting and Hardening Remote Access VPN Solutions [pdf]
#7Anyone have a non-PDF version of this? :-p
Re: Selecting and Hardening Remote Access VPN Solutions [pdf]
#8I'm saddened that the answer isn't "Just use BeyondCorp". Layer 7 solutions provide so much more capacity for granular AuthZ, and thereby eliminate the "soft underbelly" of corporate networks.
Re: Selecting and Hardening Remote Access VPN Solutions [pdf]
#9A lot of warnings against TLS based VPN solutions. I imagine these solutions are popular because they are more likely to function through corporate firewalls, where IPsec might be blocked. Unsurprisingly no mention of wireguard, as it's not FIPS. However, unless you need FIPS compliance, it seems like the way to go these days.
It's either too good for them or it's bad. :)