Remote User Access – VPN vs SDP from a security perspective

Proliferation of Remote Access

Remote user access and WFH has significantly changed the secure access paradigm for organizations. Remote access has increased due to the pandemic as most of the employees have now started to connect to the organization’s on-premises and cloud resources via remote connectivity, primarily through virtual private networks (VPNs).
VPN as it is very well known, provides encrypted tunnel from a remote location to the organization’s on-premises and cloud resources by assuring the encryption of the traffic and the authentication of the user and permissioned user access to the network resources.

As the modern cyber-attacks have started to evolve, security researchers and recent security incidents have proven that the security controls that are offered by traditional VPN solutions (IPSEC VPN and SSL VPN) are not adequate anymore.

Proliferation of Remote Access
Remote user access and WFH has significantly changed the secure access paradigm for organizations. Remote access has increased due to the pandemic as most of the employees have now started to connect to the organization’s on-premises and cloud resources via remote connectivity, primarily through virtual private networks (VPNs).
VPN as it is very well known, provides encrypted tunnel from a remote location to the organization’s on-premises and cloud resources by assuring the encryption of the traffic and the authentication of the user and permissioned user access to the network resources.

As the modern cyber-attacks have started to evolve, security researchers and recent security incidents have proven that the security controls that are offered by traditional VPN solutions (IPSEC VPN and SSL VPN) are not adequate anymore.

Current Challenges in Remote Access and Traditional VPN Solutions
The challenges that the organizations face while having VPN connections are:
  • Cisco AnyConnect VPN
    • Reference:https://www.cvedetails.com/vulnerability-list/vendor_id-16/product_id-20904/Cisco-Anyconnect-Secure-Mobility-Client.html
  • Pulse Secure (Secure Connect) SSL VPN
    • Reference: https://www.cvedetails.com/vulnerability-list/vendor_id-15824/product_id-33650/year-2020/Pulsesecure-Pulse-Connect-Secure.html
  • FortiGate FortiOS SSL VPN
    • CVE-2018-13379, CVE-2020-12812, CVE-2019-5591
  • Citrix NetScaler
    • CVE-2019-19781
    • Citrix NetScaler vulnerability existing in Citrix Application Delivery Controller (ADC), Citrix Gateway, and Citrix SD-WAN WANOP appliances
  • Palo Alto Global Protect
    • CVE-2020-2050

Current Challenges in Remote Access and Traditional VPN Solutions

The challenges that the organizations face while having VPN connections are:

  • Cisco AnyConnect VPN
    • Reference:https://www.cvedetails.com/vulnerability-list/vendor_id-16/product_id-20904/Cisco-Anyconnect-Secure-Mobility-Client.html
  • Pulse Secure (Secure Connect) SSL VPN
    • Reference: https://www.cvedetails.com/vulnerability-list/vendor_id-15824/product_id-33650/year-2020/Pulsesecure-Pulse-Connect-Secure.html
  • FortiGate FortiOS SSL VPN
    • CVE-2018-13379, CVE-2020-12812, CVE-2019-5591
  • Citrix NetScaler
    • CVE-2019-19781
    • Citrix NetScaler vulnerability existing in Citrix Application Delivery Controller (ADC), Citrix Gateway, and Citrix SD-WAN WANOP appliances
  •  Palo Alto Global Protect
    • CVE-2020-2050
Paradigm Shift: Zero Trust Remote Access using Software Defined Perimeter
To address the challenges mentioned above and efficiently eliminating the inherent risks posed by traditional VPN solutions, it is recommended to enhance the control and implement a more modern and secure approach to ensure control over remote user access. In comes Software-Defined Perimeter (SDP), a sophisticated new approach to provide zero-trust secure remote access which combines continuous posture monitoring, user and device validation and seamless network resource access in a frictionless manner across a multi-cloud and on-premises environment.

Paradigm Shift: Zero Trust Remote Access using Software Defined Perimeter

To address the challenges mentioned above and efficiently eliminating the inherent risks posed by traditional VPN solutions, it is recommended to enhance the control and implement a more modern and secure approach to ensure control over remote user access. In comes Software-Defined Perimeter (SDP), a sophisticated new approach to provide zero-trust secure remote access which combines continuous posture monitoring, user and device validation and seamless network resource access in a frictionless manner across a multi-cloud and on-premises environment.