18.07.2013 Views

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Understanding virtual burbs<br />

Figure 13-4. Virtual burb<br />

vs. a non-virtual burb<br />

VPN implementation<br />

13-16 Configuring Virtual Private Networks<br />

Consider a VPN policy that is implemented without the use <strong>of</strong> a virtual<br />

burb. Not only will VPN traffic mix with non-VPN traffic, but there is<br />

no way to enforce a different set <strong>of</strong> rules for the VPN traffic. This is<br />

because proxies and rules are applied on burb basis, not to specific<br />

traffic within a burb. By terminating the VPN in a virtual burb you<br />

effectively isolate the VPN traffic from non-VPN traffic. Plus, you are<br />

able to configure a unique set <strong>of</strong> rules for the virtual burb that allow<br />

you to control precisely what your VPN users can or cannot do.<br />

Figure 13-4 illustrates this concept.<br />

VPN without a virtual burb<br />

<strong>Sidewinder</strong> <strong>G2</strong><br />

Internal<br />

network<br />

Trusted<br />

burb<br />

Proxies<br />

Internet<br />

burb<br />

VPN with a virtual burb<br />

<strong>Sidewinder</strong> <strong>G2</strong><br />

Internal<br />

network<br />

Trusted<br />

burb<br />

Proxies<br />

Proxies<br />

Virtual<br />

burb<br />

= VPN tunnel<br />

= Data<br />

Internet<br />

burb<br />

Internet<br />

Internet<br />

Non-VPN<br />

Client<br />

VPN<br />

Client<br />

Non-VPN<br />

Client<br />

VPN<br />

Client<br />

Note: Both VPN implementations depicted in Figure 13-4 represent "proxied" VPNs<br />

because proxies must be used to move VPN data between burbs. The use <strong>of</strong> proxies enables<br />

you to control the resources that a VPN client has access to on your internal network.<br />

A virtual burb can support all the same services as a normal burb. If<br />

traffic coming from the virtual burb is destined to the <strong>Sidewinder</strong> <strong>G2</strong><br />

itself (for example, DNS or SSH) the rule that allows traffic across that<br />

burb must specify a NAT address <strong>of</strong> localhost. If localhost is not<br />

specified, the <strong>Sidewinder</strong> <strong>G2</strong> will not be able to route traffic back to<br />

the originator.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!