VPN Products
Patrick Ethier
patrick at SECUREOPS.COM
Wed Dec 13 18:00:01 EST 2000
Hi Cindy,
I have a friend who reviewed it lately. He found that there where a lot of
bugs in the Web GUI. This means that you have to restrict access to the
admin port as much as possible. The bug was reported a few weeks ago and may
have been fixed, look at the Bugtraq on www.securityfocus.com for more
details.
Basically, by issueing an HTTP GET without supplying a filename reboots the
firewall and supplying a very long username has similar results.
Like I said, these may have been fixed by now, check with Bugtraq and
SonicWall for more details.
The filtering aspect of the product seems ok but I haven't tested it
personally. The VPN portion also seems sound but all I have done with it so
far is connect my OBSD IKE to it.
Regards,
Patrick Ethier
patrick at secureops.com
-----Original Message-----
From: Cindy Slosar [mailto:cindy_slosar at YAHOO.CA]
Sent: December 13, 2000 4:07 PM
To: VPN at SECURITYFOCUS.COM
Subject: VPN Products
Hi all,
I'm leaning towards implementing the Sonicwall SOHO
VPN solution and was wondering if anyone can provide
any feedback, good and/or bad. Or, if someone knows
of a better solution/product that I should be
considering for a hardware-based VPN, that would be
greatly appreciated too.
Thanks in advance,
Cindy
_______________________________________________________
Do You Yahoo!?
Get your free @yahoo.ca address at http://mail.yahoo.ca
VPN is sponsored by SecurityFocus.COM
VPN is sponsored by SecurityFocus.COM
More information about the VPN
mailing list