Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Is it true that routers, like the Sophos XGS 87 decrypt the data stream on VPN connections?

I have a NordVPN account and the router at our office is Sophos XGS 87. According Sophos literature they do deep packet inspection on TLS 1.0 to 3.0 (HTTPS) connections.

It seems the router acts as a "man in the middle" so that it acquires the encryption key and then uses it to inspect all encrypted traffic.

I asked NordVPN if this would impact the session with their VPN service. Their only reply, on repeated requests, is that they use AES 256bit encryption for the connection but they don't say what encryption is used to make the connection or if Sophos router can pose as client?

My concern is that if the router can pose as the VPN client it will decrypt-inspect-encrypt all traffic passing through it. I am working outside office hours, which the company allows me to do on their network, but I value my privacy and security.

If my concern is valid, then is this true of all VPN services?



This thread was automatically locked due to age.
Parents
  • It is quite simple. 

    There are two different approaches, DPI works. It can show you, which algorithm you use. Its like looking at you, while you lock the door. I can tell by simply looking at your hand, if you use a key, a fingerscanner or your face to lock the door. I cannot enter at this stage. 

    The other approach is to replace the keys and do a MITM "attack" to be able to copy the key to look into the content. 

    But to do this, you (as a client) needs to give your permission. Sophos (or any other vendor) cannot do this technically. If this would be possible, we could stop doing https / vpn etc. because everybody could read the traffic. 

    Be aware: If this device is managed, the conses to give permission could be done by a management platform. 

Reply
  • It is quite simple. 

    There are two different approaches, DPI works. It can show you, which algorithm you use. Its like looking at you, while you lock the door. I can tell by simply looking at your hand, if you use a key, a fingerscanner or your face to lock the door. I cannot enter at this stage. 

    The other approach is to replace the keys and do a MITM "attack" to be able to copy the key to look into the content. 

    But to do this, you (as a client) needs to give your permission. Sophos (or any other vendor) cannot do this technically. If this would be possible, we could stop doing https / vpn etc. because everybody could read the traffic. 

    Be aware: If this device is managed, the conses to give permission could be done by a management platform. 

Children
No Data