Gentoo Archives: gentoo-user

From: "J. Roeleveld" <joost@××××××××.org>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] {OT} Allow work from home?
Date: Tue, 19 Jan 2016 07:51:16
Message-Id: 26922444.3UqPPD9Wmp@andromeda
In Reply to: Re: [gentoo-user] {OT} Allow work from home? by lee
1 On Tuesday, January 19, 2016 02:15:17 AM lee wrote:
2 > <wabenbau@×××××.com> writes:
3 > > lee <lee@××××××××.de> wrote:
4 > >> Rich Freeman <rich0@g.o> writes:
5 > >> > On Sun, Jan 17, 2016 at 6:38 AM, lee <lee@××××××××.de> wrote:
6 > >> >> Suppose you use a VPN connection. How do does the client
7 > >> >> (employee) secure their own network and the machine they're using
8 > >> >> to work remotely then?
9 > >> >
10 > >> > Poorly, most likely. Your data is probably not nearly as important
11 > >> > to them as their data is, and most people don't take great care of
12 > >> > their own data.
13 > >>
14 > >> That's not what I meant to ask. Assume you are an employee supposed
15 > >> to work from home through a VPN connection: How do you protect your
16 > >> LAN?
17 > >
18 > > Depends on the VPN connection. If you use an OpenVPN client on your PC
19 > > then it is sufficient to use a well configured firewall (ufw, iptables
20 > > or whatever) on this PC.
21 >
22 > The PC would be connected to the LAN, even if only to have an internet
23 > connection for the VPN. I can only guess: Wouldn't that require to put
24 > this PC behind a firewall that separates it from the LAN to protect the
25 > LAN?
26 >
27 > > If you use a VPN gateway then you could
28 > > configure this gateway (or a firewall behind) in a way that it blocks
29 > > incoming connections from the VPN tunnel.
30 >
31 > Hm. I'd prefer to avoid having to run another machine as such a
32 > firewall because electricity is way too expensive here. And I don't
33 > know if the gateway could be configure in such a way.
34 >
35 > > IMHO there is no more risk to use a VPN connection than with any other
36 > > Internet connection.
37 >
38 > But it's a double connection, one to the internet, and another one to
39 > another network, so you'd have to somehow manage to set up some sort of
40 > double protection. Setting up a VPN alone is more than difficult enough
41 > already.
42
43 Some of the companies I work with have the laptops set up that when they are
44 not connected to the office-LAN, they will only talk via a VPN link to the
45 company.
46 No network connectivity (apart from what's necessary for the VPN) will work
47 till the VPN is set up.
48
49 Any ideas on how to do this using Linux without having to become root to set
50 it up myself?
51 I like network manager for the ease of setting up WIFI links.
52
53 --
54 Joost