Implementing Extranets: The Internet as a Virtual Private Network

Required Architectural and Tunneling Tradeoffs

As you can see from the above discussion, firewalls can be useful devices for increasing extranet security because a single firewall can be used to manage the security of many devices. Without a firewall, network managers would have to manage the security of each and every device on the network separately. This would be impossible in the case of networks with thousands of devices on them.

However, firewalls can make their contribution to increased extranet security only if they can examine the packets of information, the source and destination network addresses, or the source and destination port numbers of the information flowing past them.

This is not a problem if an extranet or virtual private network tunnel starts and stops at a firewall. However, this is a big problem if an extranet or virtual private network tunnel stretches from desktop to desktop. In the latter case, all of the information passing the firewall will be encrypted and the firewall will not be able to apply some types of filtering rules unless it first decrypts the information which violates the very idea of a secure and private desktop to desktop extranet connection. Unfortunately, there is no way around this problem. Tradeoffs will have to be made. If a secure desktop to desktop extranet is desired, some of the network security provided by firewalls will in fact be lost.

UNLIMITED FREE
ACCESS
TO THE WORLD'S BEST IDEAS

SUBMIT
Already a GlobalSpec user? Log in.

This is embarrasing...

An error occurred while processing the form. Please try again in a few minutes.

Customize Your GlobalSpec Experience

Category: Network Firewalls
Finish!
Privacy Policy

This is embarrasing...

An error occurred while processing the form. Please try again in a few minutes.