tgreene
Executive Editor

Lack of endpoint security definition clouds SSL VPNs

Opinion
May 23, 20062 mins

* Lessons about SSL VPN

Endpoint security is fast becoming a key element of SSL VPNs, but it’s a lot more subtle than it sounds at first.

The idea is that the endpoint – a PC that is trying to connect to the VPN – is found compliant with corporate security policies before it is allowed to connect to the VPN. But there is no formal definition for what endpoint security is, says Joel Snyder, who tests products for Network World and who presented lessons learned about testing SSL VPN equipment during the recent Interop show in Las Vegas.

“There is no definition. It’s just a buzzword,” he says, citing a number of reasons.

Defining compliance is the first hurdle. Most people say endpoint checks should look for patched operating systems, updated antivirus software that is running and a personal firewall properly configured and turned on. But where should the line be drawn between compliance and non-compliance? Should antivirus software that is 12 hours late for an update flunk the machine and drop user rights from accessing a business application to accessing e-mail only?

Should the status of the machine be tested before or after the VPN connection is established? The gut reaction might be to say before it is established, but the parameters that are actually checked might depend on who is trying to gain access. There would be no need, for example, to make a user wait for an endpoint check if they are authorized only to read e-mails.

One touted advantage of SSL VPNs is that they support at least some access from any machine with a Web browser. But endpoint checking often won’t work on just any machine, Snyder says. It may require administrative privileges to allow such checks. “The check won’t work in the real world. You will be denied,” Snyder says.

While endpoint security has these troublesome aspects, it may not always be necessary, he says. If a user is granted access to a limited number of network resources via a proxy, endpoint scanning may not be critical, Snyder says. On the other hand, if a user has full network-layer access with authorization to upload files, then endpoint security becomes critical, he says.

Given the imperfections of endpoint security, SSL VPN users need to find a balance between granting access and maintaining security.