Home > Ask the Networking Experts > VPNs with Lisa Phifer Questions & Answers > My company uses RSA SecurID authentication for dial-up remote access. Can we continue to use this with an IPsec VPN?
Ask The Networking Expert: Questions & Answers
EMAIL THIS

My company uses RSA SecurID authentication for dial-up remote access. Can we continue to use this with an IPsec VPN?

Lisa Phifer EXPERT RESPONSE FROM: Lisa Phifer

Pose a Question
Other Networking Categories
Meet all Networking Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 20 July 2004
My company uses RSA SecurID authentication for dial-up remote access. Can we continue to use this with an IPsec VPN?

>
EXPERT RESPONSE
The Internet Key Exchange (IKE) standard used with IPsec only supports peer device authentication by pre-shared keys, raw digital signatures, or digital certificates. However, most IPsec VPN products implement extensions to support "legacy" user authentication, including weak username/password logins and stronger two-factor token methods like SecurID.

Most IPsec VPN products use one of two common alternatives to support user authentication: Extended Authentication (XAUTH) or the Layer Two Tunneling Protocol (L2TP) over IPsec.

  • L2TP over IPsec is implemented by the native Microsoft VPN client in Windows 2000, XP, and 2003. Add-on L2TP over IPsec clients are also available for other most other operating systems. You'll also need a VPN gateway that supports L2TP over IPsec. In this approach, an IPsec connection is first established in transport mode. User authentication occurs using L2TP (UDP/1701), which is encrypted by sending it over the IPsec transport.

  • XAUTH is implemented by most non-Microsoft VPN clients and VPN Remote Access Concentrators. XAUTH inserts a non-standard exchange in the middle of the IKE protocol, after peer authentication but before the IPsec tunnel is established. XAUTH is vulnerable when used with group passwords that are easily guessed -- to learn more, read this Cisco advisory or article by John Pliam. However, when XAUTH is combined with a strong group secret or certificate and two-factor user authentication, risk is much lower.

    The IETF is now working on a new version of IKE that will provide native support for a variety of user authentication methods, including generic token cards. To learn more, see the latest IKEv2 Internet Draft.


  • Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    VPNs with Lisa Phifer
    Would you consider a Microsoft VPN tunnel through a WEP encrypted access point to be secure?
    I've heard rumors that some service providers can see unencrypted VPN traffic of their customers. Is this true?
    I need to select a Cisco ADSL router which is capable of acting as a VPN server for Microsoft VPN clients that come through the Internet.
    I am having issues with the IKE communication between the two Cisco VPN concentrators.
    What about using SSL VPN with e-mail clients?
    Can you have two VPN connections to the same machine simultaneously?
    Why can't I access my folders on the server through the VPN?
    I need a very basic VPN solution to connect two offices to allow two servers to talk to one another.
    Can one use VPN over a peer-to-peer network within a home?
    After setting up my wireless router, I can no longer get on the VPN.

    Remote Offices
    Network optimization from Cisco, Blue Coat helps deliver Olympic video
    Upgrading distributed networks
    WAAS accelerates collaboration, increases revenue at engineering firm
    Remote Desktop troubleshooting
    Configure branch office VLANs to route across WAN
    Cisco and new ISR aggressively target branch office
    Remote access still faces hurdles of security, disaster recovery
    Remote office backup, archiving and disaster recovery for networking pros
    Branch offices get security, services boost
    Reduce branch office threats in 10 steps

    Remote Access VPNs
    Creating Remote Access and Site-to-Site VPNs with ISA Firewalls: from 'The Best Damn Firewall Book Period, Second Edition'
    Can I set up a VPN on my wireless router?
    VPN security: Hiding in plain sight, using network encryption
    SonicWall acquisition could hurt Aventail users
    Does IPv6 support encryption in the IP stack?
    What equipment do I use to connect two LANs in different cities? What are the steps?
    Are there any architectures of IPsec VPN apart from lookaside and flow-through?
    NAC -- Strengthening your SSL VPN
    WAN optimization and acceleration appliances tackle SSL traffic
    Remote access keeps physicians connected
    Remote Access VPNs Research

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    high-speed dialup  (SearchNetworking.com)
    IPLC  (SearchNetworking.com)
    K56flex  (SearchNetworking.com)
    modem doubling  (SearchNetworking.com)
    telecenter  (SearchNetworking.com)
    terbo  (SearchNetworking.com)
    V.xx  (SearchNetworking.com)
    virtual systems management  (SearchNetworking.com)
    visitor-based networking  (SearchNetworking.com)
    WAN interface card  (SearchNetworking.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice



    Expert networking advice and tips for IT professionals
    Visit KnowledgeStorm's comprehensive and easy to use business white paper directory.
    HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersNetworking Product Trials
    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2000 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts