Integrating RADIUS with an MSSP's remote access VPN

In a recent SearchSecurity webcast, speaker Lisa Phifer, vice president and owner of consulting firm Core Competence, addressed technological developments in virtual private networks. Here Lisa answers a user-submitted question that she didn't have time to answer during the broadcast. If you missed our webcast New directions in VPNs or would like to review it, you may listen to the recorded

    Requires Free Membership to View

webcast on-demand.

My company will be using an outside vendor to manage the VPN. I would like the VPN to use RSA RADIUS for AAA. Does it matter if I use SSL or IPSec? What problems should I expect?

A growing number of Managed Security Service Providers (MSSPs) will integrate their remote-access VPN offering with customer-supplied authentication databases and AAA servers. As you suggest, this is often done with RADIUS, chaining RADIUS Access-Requests from the provider's AAA server to your own AAA server based on the user's domain name and/or the VPN gateway they are attempting to access.

Problems (if any) usually relate to use of vendor-specific RADIUS attributes, but as long as you stick to standard RADIUS attributes you will probably have little trouble. You'll also want to make sure that your RADIUS shared secret is long and RADIUS traffic flows over a relatively secure link between your AAA server and your provider's AAA server.

It is quite common for both IPsec and SSL VPN products to behave as RADIUS clients for user-level authentication, but the method used to carry user credentials over the VPN differs. IPsec VPNs tend to use something like Extended Authentication (XAUTH), where all users first authenticate with a group-shared secret, then sub-authenticate the user with credentials like username/password. There are known security risks associated with XAUTH; for more info, see Cisco's Web site and John Pliam's paper. SSL VPNs often send user login traffic through the SSL tunnel after first authenticating only the server (VPN gateway). However, it's important for the client to really authenticate the SSL VPN server and not just blindly accept the server's certificate; see this SANS paper for more information.


This was first published in March 2004

There are Comments. Add yours.

TIP: Want to include a code block in your comment? Use <pre> or <code> tags around the desired text. Ex: <code>insert code</code>

REGISTER or login:

Forgot Password?
By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy
Sort by: OldestNewest

Forgot Password?

No problem! Submit your e-mail address below. We'll send you an email containing your password.

Your password has been sent to:

Disclaimer: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.