Thomas Shinder Blog RSS

All Blogs  »  Thomas Shinder Blog  »  ISA Central  »  Blog article: 10 things you should do to protect your network against wireless devices

10 things you should do to protect your network against wireless devices

#3: Force client health checking for all hosts connecting from anonymous access WAP segments
VPN client connections from hosts on the anonymous access wireless DMZ segment provides a quick and dirty way to allow authorised users access to corporate resources from the untrusted network segment. Although this solves the immediate problem of allowing authorised users "just in time" access to corporate resources from an unmanaged client, it exposes us to problems related to the unmanaged client computer itself. The unmanaged client has a high probability of harboring viruses, worms, and Trojans that can put the corporate production network at risk.

One way to handle this problem is to use a VPN client hygiene solution, which will analyse the software environment on the VPN client and compare it with your corporate security requirements. A number of VPN server solutions provide this capability, including ISA Server 2004’s VPN Quarantine controls. Most VPN client hygiene solutions also enable to you provide remediation services so that VPN clients that do not meet corporate security requirements can automatically update themselves to a state where they meet security requirements.

For the rest of the story, check out: http://insight.zdnet.co.uk/0,39020415,39276190,00.htm

HTH,

Tom

Thomas W Shinder, M.D.

Site: www.isaserver.org

Blog: http://blogs.isaserver.org/shinder/

Book: http://tinyurl.com/3xqb7

MVP — ISA Firewalls

2 Responses to “10 things you should do to protect your network against wireless devices”

  1. Jason Jones Says:

    June 26th, 2006 at 6:40 am

    Take a bow VPN-Q 2006 ;-)

  2. Thomas Shinder Says:

    June 26th, 2006 at 7:04 am

    Hi Jason,
    Good point!
    Thanks!
    Tom

Leave a Reply

This is a captcha-picture. It is used to prevent mass-access by robots. (see: www.captcha.net)

You must read and type the 5 chars within 0..9 and A..F, and submit the form.

  

If CAPTCHA image is missing or you cannot read the characters above, please generate a




Receive all the latest articles by email!

Receive Real-Time & Monthly ISAserver.org article updates in your mailbox. Enter your email below!
Click for Real-Time sample & Monthly sample

Become an ISAserver.org member!

Discuss your ISA Server issues with thousands of other ISA Server experts. Click here to join!

Solution Center