tgreene
Executive Editor

How endpoint security works

Opinion
Aug 2, 20052 mins

* About endpoint security

If you are interested in using VPNs nowadays, you should also be interested in using endpoint security.

This software sits on remote machines that are trying to access the VPN and checks whether the device meets security policies for the company that set up the VPN. If not, access is denied. Some vendors’ software refers remote users to a separate remediation Web site where they can get what their machine needs to comply. Other vendors would say the machine has failed and to contact a network administrator for further instructions.

Either way, machines that have unpatched operating systems, virus scanning software that’s turned off or not updated, a misconfigured firewall or no firewall turned on or a list of other shortcomings don’t get access.

The threat is that if an insecure machine does gain access, it might be commandeered and then the entire network is opened up to the hacker. This is particularly true of IPSec VPNs that open up a network layer connection to the network, giving users the same access as if their computer were connected via a Category 5 cable.

With SSL VPNs the threat can be mitigated by access controls on what resources each user is allowed to reach, but endpoint security should be used when employing downloadable agents offered by some vendors that open up network layer connections.

While much of the attraction of SSL VPNs is that they require no client software, that is true only when granting access to non-critical network resources. If access to sensitive data is required, endpoint-checking software – a client – will be needed. Seems you can’t get around it, but it’s worth it.