Soru

Zorluk: OrtaVirtual Private Networks and Remote Access Security

A network administrator notices that remote workers connected via a full-tunnel VPN are causing severe bandwidth saturation at the corporate perimeter by streaming internet media through the corporate gateway. To alleviate congestion, the administrator plans to modify the client configuration to allow split tunneling. Which of the following describes the primary security risk introduced by enabling split tunneling?

  1. The remote client device can act as a dual-homed bridge, allowing threats from the local untrusted network to bypass perimeter controls into the corporate network.Cevap
  2. B
    All RADIUS authentication requests will bypass the VPN concentrator, causing authentication payloads to be transmitted across the internet in plain text.
  3. C
    Encapsulating Security Payload (ESP) headers will be stripped from IPsec packets, forcing fallback to unencrypted Authentication Header (AH) transport mode.
  4. D
    The SSL/TLS VPN session negotiation will automatically default to port 80 instead of port 443 for external web traffic routing.

Cevap

The primary security risk of split tunneling is that the remote device can act as a dual-homed bridge, allowing malicious traffic from the local untrusted network to pivot into the corporate environment.
Enabling split tunneling directs non-corporate internet traffic out of the remote user's local network connection while tunneling corporate traffic. The primary security vulnerability is that the endpoint host acts as a bridge between the untrusted public network and the protected corporate network, creating an unmonitored path for malware or unauthorized pivot attacks.

Adım Adım Çözüm

1
Analyze full tunneling versus split tunneling functionality.
Full tunneling routes 100% of remote host traffic through the encrypted VPN tunnel and corporate firewall. Split tunneling splits traffic: corporate destination traffic enters the tunnel, while general internet traffic exits directly through the user's local ISP gateway.
Understanding traffic path differences clarifies where security boundaries and risks shift.
2
Evaluate the security implication of simultaneous local network and corporate network access.
Because the host maintains simultaneous active connections to an untrusted local/public network and the trusted internal network, an attacker or malware on the local network can compromise the endpoint and pivot directly into the internal corporate network.
This dual-homed state bypasses perimeter firewalls and intrusion prevention controls.

Anahtar Kavram

Split Tunneling Security Implications
Bu soruyu puanla