Koozali.org: home of the SME Server

pptp VPN more secure ?

Offline fpausp

  • *
  • 728
  • +0/-0
pptp VPN more secure ?
« on: November 01, 2007, 08:46:20 AM »
Hi all,

I am using sme72 and the possebility of the build in pptp-vpn but i heard that this method is not really secure.

I know there is openvpn but the sme-vpn is easier to handle for me.

Is there a way to get more security for the pptp-connection, maybe with EAP or so on ?



regards
fpausp
Viribus unitis

guest22

Re: pptp VPN more secure ?
« Reply #1 on: November 01, 2007, 09:13:53 AM »
Hi all,

I am using sme72 and the possebility of the build in pptp-vpn but i heard that this method is not really secure.


Hi, any 'proof' the default VPN method not being secure please? What are your VPN requirements?

guest

Offline mmccarn

  • *
  • 2,651
  • +10/-0
Re: pptp VPN more secure ?
« Reply #2 on: November 01, 2007, 05:45:02 PM »
I have always felt that since pptp is based on usernames & passwords it is exactly as secure as your usernames and passwords.  A remote user checking webmail on a terminal with a key logger installed can easily reveal a username and password, for example.

OpenVPN, by contrast, is server and certificate based - an attacker has to crack into one end or the other to get certificate information, and possibly may need to spoof IP information, too.

I don't know of any other reason that PPTP would be considered 'insecure'.

The basic implication is that you need to carefully train any users who have access to your PPTP server to make sure they understand the importance of password security, etc, etc.

Offline fpausp

  • *
  • 728
  • +0/-0
Re: pptp VPN more secure ?
« Reply #3 on: November 02, 2007, 05:33:28 PM »
Hi,

What i mean is (excuse my english) if i can use the Extensible-Authentication-Protokoll (EAP) instead of MS-CHAP v2, i have seen this when i was confige my xp-client.

The pptp-client gives me two possibilities for logonsecurity under the point EAP - 1. MD5-Challenge and 2. Smartcard or other certificate.


regards
fpausp



Viribus unitis

Offline fpausp

  • *
  • 728
  • +0/-0
Re: pptp VPN more secure ?
« Reply #4 on: November 03, 2007, 07:34:48 PM »
Hi,


http://en.wikipedia.org/wiki/Point-to-point_tunneling_protocol


MSCHAP-v2 can be compromised if users choose weak passwords. The certificate-based EAP-TLS provides a superior security option for PPTP.
Viribus unitis