HomeSecurityNorway recommends replacing SSL VPN to avoid breaches

Norway recommends replacing SSL VPN to avoid breaches

The Norwegian National Cyber ​​Security Center (NCSC) recommends replacing SSL VPN/Web VPN with alternatives due to the repeated exploitation of related vulnerabilities in devices to compromise corporate networks.

See also: Australia: MediSecure suffers data breach

Norway SSL VPN

The organization recommends that the transition be completed by 2025, while organizations subject to the "Security Act" or those in critical infrastructure should adopt more secure alternatives by the end of 2024.

Norway's official recommendation for users of Secure Socket Layer Virtual Private Network (SSL VPN/WebVPN) products is to switch to Internet Protocol Security (IPsec) with Internet Key Exchange (IKEv2) .

SSL VPN and WebVPN provide secure remote access to a network over the Internet using SSL/TLS protocols, securing the connection between the user's device and the VPN server using an "encryption tunnel".

IPsec with IKEv2 secures communications by encrypting and authenticating each packet.

While the cybersecurity admits that IPsec with IKEv2 is not without flaws, it believes that switching to it would significantly reduce the attack surface for secure remote access incidents due to the reduced tolerance for errors compared to SSL VPN.

See also: Nissan North America: Data breach affects 53,000 employees

The proposed implementation measures include:

  • Reconfiguring or replacing existing VPN solutions
  • Migrating all users and systems to the new protocol
  • Disable SSL VPN functionality and block incoming TLS traffic
  • Using certificate-based authentication
  • Where IPsec connections are not possible, the NCSC recommends using 5G broadband.
Norway recommends replacing SSL VPN to avoid breaches

Meanwhile, the Norwegian National Cybersecurity Center also shared temporary measures for organizations whose SSL VPN solutions do not offer the IPsec with IKEv2 option and need time to plan and execute the migration.

These include implementing central logging of VPN activity, strict geo-fencing restrictions, and blocking access from VPN providers, Tor exit nodes, and VPS providers.

Other countries besides Norway have also proposed using IPsec over other protocols such as SSL VPN, including the US and the UK.

See also: Santander: Customer and employee data breach

What are the best practices for network security?

  • Using strong and unique passwords is fundamental to network security
  • Regularly updating software and systems is critical to protecting against vulnerabilities.
  • The use of a firewall is essential for monitoring and controlling incoming and outgoing network traffic, preventing unauthorized access.
  • Employee training on security issues is also vital.
  • Regularly backing up data ensures that, in the event of a data breach or loss, the data can be recovered without significant loss.

Source: bleepingcomputer

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS