Hi everyone,
I think most of us have seen the news regarding the Fortinet vulnerabilities. Regarding this topic I got a very specific question from a customer. They asked if it possible to see what vendor is running on the other side of a site to site VPN tunnel. Many VPN tunnels are running on this CP gateway so maybe it possible to see it somehow. I suspect it is not possible, but maybe there are some creative ideas. Also nice to discuss this topic here.
The only way I can think of is that sometimes a VPN debug shows info. For example Check Point shows up in a debug:
Vendor ID Payload
Next Payload: NONE
Reserved: 0
Length: 00 2c (44)
VID Data:
VIDData:
-
Product: Check Point VPN-1
Version: NG with Application Intelligence R55 or above
-------
If you like this post please give a thumbs up(kudo)! 🙂