Mobile app version of vmapp.org
Login or Join
Cofer257

: Securing Access to Server We have servers at an ISP and a firewall in place. At our main office, we have a VPN. For an added layer of security, I'm thinking a good model may be to have

@Cofer257

Posted in: #Security #Vpn

We have servers at an ISP and a firewall in place. At our main office, we have a VPN. For an added layer of security, I'm thinking a good model may be to have developers connect to the corporate VPN and then only allow traffic in to the servers through the firewall from the VPN's IP.

My questions:

1) Does this sound like a sound method for connection?

2) What is the best method for validating user at VPN? I've used a cryptocard in a previous environment, but I'm not real familiar with the technology or competitors.

Thanks,
D

10.02% popularity Vote Up Vote Down


Login to follow query

More posts by @Cofer257

2 Comments

Sorted by latest first Latest Oldest Best

 

@Miguel251

Asked on Server Fault. The response was having individual users with named accounts was probably enough and that VPN access would give extra protection but may not be necessary.

10% popularity Vote Up Vote Down


 

@Turnbaugh106

It's a valid model but I would be wary of doing it this way.

You place your ability to connect to the server in the hands of your VPN provider (even the best providers are never that good) and introduce a single point of critical failure with no available fail-over.

10% popularity Vote Up Vote Down


Back to top | Use Dark Theme