Transcription of Guide to SSL VPNs - NIST
1 Special Publication 800-113 Guide to SSL VPNs Recommendations of the National Institute of Standards and Technology Sheila Frankel Paul Hoffman Angela Orebaugh Richard Park Guide to SSL VPNs Recommendations of the National Institute of Standards and Technology Sheila Frankel Paul Hoffman Angela Orebaugh Richard Park NIST Special Publication 800-113 C O M P U T E R S E C U R I T YComputer Security Division Information Technology Laboratory National Institute of Standards and Technology Gaithersburg, MD 20899-8930 July 2008 Department of Commerce Carlos M. Gutierrez, Secretary National Institute of Standards and Technology James M.
2 Turner, Deputy Director Guide TO SSL VPNS Reports on Computer Systems Technology The Information Technology Laboratory (ITL) at the National Institute of Standards and Technology (NIST) promotes the economy and public welfare by providing technical leadership for the nation s measurement and standards infrastructure. ITL develops tests, test methods, reference data, proof of concept implementations, and technical analysis to advance the development and productive use of information technology. ITL s responsibilities include the development of technical, physical, administrative, and management standards and guidelines for the cost-effective security and privacy of sensitive unclassified information in Federal computer systems.
3 This Special Publication 800-series reports on ITL s research, guidance, and outreach efforts in computer security and its collaborative activities with industry, government, and academic organizations. Certain commercial entities, equipment, or materials may be identified in this document in order to describe an experimental procedure or concept adequately. Such identification is not intended to imply recommendation or endorsement by the National Institute of Standards and Technology, nor is it intended to imply that the entities, materials, or equipment are necessarily the best available for the purpose. National Institute of Standards and Technology Special Publication 800-113 Natl.
4 Inst. Stand. Technol. Spec. Publ. 800-113, 87 pages (July 2008) iiGUIDE TO SSL VPNS Acknowledgements The authors, Sheila Frankel of the National Institute of Standards and Technology (NIST), Paul Hoffman of the Virtual Private Network Consortium (VPNC), and Angela Orebaugh and Richard Park of Booz Allen Hamilton, wish to thank their colleagues who reviewed drafts of this document and contributed to its technical content, especially Elaine Barker, Jim St. Pierre and Tim Polk of NIST. The authors would like to acknowledge Tim Grance and Karen Scarfone of NIST for their keen and insightful assistance throughout the development of the document.
5 The authors particularly want to thank Guy Snyder, darren Hartman and Thang Phan of ICSA Labs for their careful review and valuable contributions to improving the quality of this publication. The authors would also like to express their thanks to Mike Hillhouse of Juniper Networks and Mahesh Jethanandani of Cisco for their worthwhile comments and suggestions. iiiGUIDE TO SSL VPNS ivTable of Contents Executive ES-1 1. Authority ..1-1 Purpose and Document 2. Network and Transport Layer The Need for Network and Transport Layer Virtual Private Networking (VPN)..2-4 SSL Portal SSL Tunnel Administering SSL 3.
6 SSL VPN SSL VPN SSL VPN SSL VPN Features and Security High Availability and Portal Encryption and Integrity Access Endpoint Security Controls ..3-8 Intrusion SSL Protocol Versions of SSL and Cryptography Used in SSL Authentication Used for Identifying SSL SSL VPN 4. SSL VPN Planning and Identify SSL VPNs and FIPS 140-2 Versions of SSL ..4-3 Key Establishment Used by Hash Functions Used by SSL Certificates Used During SSL Design the Design the Access Control Design the Endpoint Security Select the Authentication Design the Guide TO SSL VPNS Cryptography Policy and FIPS Other Design Summary of Design Implement and Test Application and Client Deploy the Solution.
7 4-28 Manage the 5. SSL VPN Recommended Practices ..5-1 6. Alternatives to SSL Data Link Layer VPN Network Layer VPN Protocols ..6-2 Application Layer VPNs ..6-3 7. Case Identifying Needs and Evaluating Options ..7-1 Designing the Access Control Endpoint Security Authentication Architecture Selection of Hardware Device Placement and Firewall Routing High Client Software Portal Encryption Implementing a Example configuration steps ..7-6 Deploying and Managing the List of Appendices Appendix A Glossary .. A-1 Appendix B B-1 Guide TO SSL VPNS List of Figures Figure 2-1.
8 TCP/IP Layers ..2-1 Figure 3-1. SSL VPN Architecture ..3-2 Figure 4-1. Firewall with SSL VPN Functionality ..4-14 Figure 4-2. SSL VPN Device in Internal Network ..4-15 Figure 4-3. SSL VPN Device in DMZ Figure 4-4. SSL VPN Device with Two Interfaces ..4-17 Figure 4-5. Routing Problem with SSL VPN Traffic ..4-20 Figure 4-6. Example Portal Interface ..4-23 List of Tables Table 3-1. Access Control Examples ..3-7 Table 3-2. Access Control Examples with Endpoint Security Controls ..3-8 Table 4-1. Sample Access Control Policy ..4-9 Table 4-2. Sample Authentication Methods Table ..4-12 Table 4-3. Design Decisions Checklist ..4-24 Table 5-1. SSL VPN Life Cycle Phase Table 6-1.
9 Comparison of SSL and Alternatives ..6-4 Table 6-2. IP Protocols and TCP/UDP Port Numbers for VPN Protocols ..6-5 Table 7-1. Organization s Access Control Policy ..7-3 Table 7-2. Organization s Authentication Methods ..7-4 viGUIDE TO SSL VPNS Executive Summary Secure Sockets Layer (SSL) virtual private networks (VPN) provide secure remote access to an organization s resources. A VPN is a virtual network, built on top of existing physical networks, that can provide a secure communications mechanism for data and other information transmitted between two endpoints. Because a VPN can be used over existing networks such as the Internet, it can facilitate the secure transfer of sensitive data across public networks.
10 An SSL VPN consists of one or more VPN devices to which users connect using their Web browsers. The traffic between the Web browser and the SSL VPN device is encrypted with the SSL protocol or its successor, the Transport Layer Security (TLS) protocol. This type of VPN may be referred to as either an SSL VPN or a TLS VPN. This Guide uses the term SSL VPN. SSL VPNs provide remote users with access to Web applications and client/server applications, and connectivity to internal networks. Despite the popularity of SSL VPNs, they are not intended to replace Internet Protocol Security (IPsec) The two VPN technologies are complementary and address separate network architectures and business needs.