* No need to panic if your VPN is properly configured
An advisory from a U.K. government group says that certain configurations of remote access IPSec VPNs are susceptible to attacks.
The advisory was dated last week, but the vulnerabilities it outlines have been known for years, so there is no reason for those who have been paying attention to panic. If properly configured, their VPNs are secure.
The vulnerability requires that encapsulation security payload (ESP), which is supposed to guarantee confidentiality, is used in tunnel mode – as between two VPN gateways. It also requires that ESP is used without integrity checking, which ensures the information has not been modified. The vulnerability also exists if the integrity check is provided by a higher layer protocol than Layer 3.
To close up the vulnerability, ESP should be configured to use both confidentiality and integrity protection.
This has long been the recommended use of ESP. Most IPSec gateways don’t even allow setting up ESP without also configuring integrity checking. As one long-time VPN tester put it, “It’s a non-issue except for systems with not enough sanity checking in the administration interface.”
The U.K. government warning didn’t list any specific gear in which it had found the vulnerability, but said it was a potential danger for any IPSec VPN.
There have been news reports about this advisory that treat it as if it is revealing the vulnerability for the first time. It is not, and IPSec VPN users shouldn’t panic. They should check whether their configuration falls into the danger zone and if it does, rectify it.
On a lighter note, SSL VPN vendor Aventail sent out a press release citing the advisory and noting that its gear was not susceptible to the vulnerability. Which makes sense, given that Aventail’s gear doesn’t use IPSec. Never be afraid to state the obvious.




