PPTP VPN. RSA vs MS-CHAP v2

PPTP VPN. RSA vs MS-CHAP v2

NewsGroups | Search | Tools
 comp.dcom.vpn  Post an article  get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content  add this group's latest topics to your Google content  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
PPTP VPN. RSA vs MS-CHAP v2 Scooty 10-08-2007
Posted by Scooty on October 8, 2007, 11:29 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi all
I am hoping someone could offer some insight into the following
I have evaluated the RSA Authentication Manager using token based
authentication. This uses EAP and I believe this is very secure
I currently have a Windows 2003 RRAS server located in a DMZ that uses
RADIUS to talk back to the server on the inside network that runs the
RSA software. The firewall is set to only allow port 1723 PPTP and
port 47 GRE from the outside to the RRAS server, the firewall is also
set to only allow ports 1812 and 1813 from the RRAS server in the DMZ
to the inside server running RSA Auth Manager and IAS
I have also setup the RRAS server to still use RADIUS to talk back to
the same inside server using Microsofts IAS using MS-CHAP v2 as part
of my testing
I would like to know how secure MS-CHAP v2 is compared to using the
RSA method
I like the MS-CHAP v2 as I don't need to install any 3rd party
software on the users workstations like I do with the RSA solution
Also ensuring I have a strong password policies in place I like the
fact that I can use my AD username and password to authenticate,
whereas the RSA uses a user set PIN and a token that changes every 60
seconds, it doesn't really integrate with AD but instead just does an
LDAP query of users in AD at predefined intervals. I also find the
interface of RSA Authentication Manager 6.5 pretty clunky

Any pros and cons would be most appreciated


Similar ThreadsPosted
MS PPTP to MS PPTP Server August 19, 2006, 11:49 am
openvpn & pptp February 7, 2005, 5:56 pm
Is PPTP from inside NAT possible? February 21, 2005, 1:03 am
pptp secure? March 16, 2005, 7:50 am
Can't get PPTP to work May 19, 2005, 3:19 pm
PPTP VPN and subnets June 1, 2006, 8:41 am
Netscreen-25 and PPTP VPN October 12, 2006, 12:54 am
PPTP VPN Startup Connect October 16, 2005, 3:55 pm
VPN pptp - strange problem September 5, 2006, 6:02 pm
PPTP vith 2 NIC's?? September 22, 2006, 2:29 pm

other useful resources:
The Federal Communications Commission (FCC)
Telecommunications Industry Association
Electronic and Software Security Products and Services
International Telecommunication Union

Custom CGI Perl and PHP programming by 1-Script.com

Contact Us | Privacy Policy
The site map in XML format XML site map