Gentoo Archives: gentoo-user

From: lee <lee@××××××××.de>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] {OT} Allow work from home?
Date: Tue, 19 Jan 2016 01:19:31
Message-Id: 87ziw28j4q.fsf@heimdali.yagibdah.de
In Reply to: Re: [gentoo-user] {OT} Allow work from home? by wabenbau@gmail.com
1 <wabenbau@×××××.com> writes:
2
3 > lee <lee@××××××××.de> wrote:
4 >
5 >> Rich Freeman <rich0@g.o> writes:
6 >>
7 >> > On Sun, Jan 17, 2016 at 6:38 AM, lee <lee@××××××××.de> wrote:
8 >> >> Suppose you use a VPN connection. How do does the client
9 >> >> (employee) secure their own network and the machine they're using
10 >> >> to work remotely then?
11 >> >
12 >> > Poorly, most likely. Your data is probably not nearly as important
13 >> > to them as their data is, and most people don't take great care of
14 >> > their own data.
15 >>
16 >> That's not what I meant to ask. Assume you are an employee supposed
17 >> to work from home through a VPN connection: How do you protect your
18 >> LAN?
19 >
20 > Depends on the VPN connection. If you use an OpenVPN client on your PC
21 > then it is sufficient to use a well configured firewall (ufw, iptables
22 > or whatever) on this PC.
23
24 The PC would be connected to the LAN, even if only to have an internet
25 connection for the VPN. I can only guess: Wouldn't that require to put
26 this PC behind a firewall that separates it from the LAN to protect the
27 LAN?
28
29 > If you use a VPN gateway then you could
30 > configure this gateway (or a firewall behind) in a way that it blocks
31 > incoming connections from the VPN tunnel.
32
33 Hm. I'd prefer to avoid having to run another machine as such a
34 firewall because electricity is way too expensive here. And I don't
35 know if the gateway could be configure in such a way.
36
37 > IMHO there is no more risk to use a VPN connection than with any other
38 > Internet connection.
39
40 But it's a double connection, one to the internet, and another one to
41 another network, so you'd have to somehow manage to set up some sort of
42 double protection. Setting up a VPN alone is more than difficult enough
43 already.

Replies

Subject Author
Re: [gentoo-user] {OT} Allow work from home? wabenbau@×××××.com
Re: [gentoo-user] {OT} Allow work from home? "J. Roeleveld" <joost@××××××××.org>