home news blogs forums events research newsletter whitepapers careers


UBM Network Computing
TechWeb
Visit our SOA/Web Services Immersion Center

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers






IPSec-Compliant VPN Solutions: Virtualizing Your Network

By Mike Fratto
our customizable newsletter, sends you security alerts, product updates and software patches on the products you use. Sign up now at www.networkcomputing.com /express/
 Are you itching to reduce WAN connectivity costs while maintaining or improving your network security? Virtual Private Networks (VPNs) may be the answer. VPN provides secure, dynamic connectivity across public IP networks by securing the traffic between two end points. Workstations and servers protected by the VPN view geographically remote sites as if they were part of the same network when tunneling IP traffic, but the traffic is unintelligible to nodes located outside the VPN.

To view the Report card.At the forefront of this technology are hardware devices that support the IPSec (IP Security) protocol and IKE (Internet Key Exchange, formally known as ISAKMP/Oakely Resolution). Other VPN protocols such as PPTP, L2TP and L2F offer some VPN services such as encryption and multiprotocol routing, but they are more well-suited to remote-access applications and moving non-IP traffic across the Internet. In fact, these seemingly competing VPN technologies serve different needs and can't be compared in a meaningful way on a per-product basis.

Of course, data leaving your LAN is subject to sniffing by unauthorized users, which is where IPSec devices come in to safeguard privacy. IPSec protects your data at Layer 3 using strong encryption and authentication. IPSec tunneling with IKE ensures that your data is encrypted end-to-end and that it has not been tampered with en route. At the time of this writing, six ICSA-certified interoperable IPSec products are on the market. It's likely more will have joined them by the time you read this.

While the IPSec VPN gateways with IKE support we tested--RedCreek's Ravlin 10, Shiva LanRover VPN Gateway (beta version), TimeStep's PERMIT Enterprise and VPNet's VSU 1010--are stable, aspects such as remote management, reporting and logging, and advanced management functions are still immature and require more work by vendors. However, the current crop of proprietary management stations will let trusted administrators assess problems remotely and securely.

What's Next? Vendors claiming to have IPSec-compliant implementations may be telling only half the story. The other half of IPSec tunneling is IKE, or key management, which provides secure management and exchange of cryptographic keys between distant devices. The IKE protocol exchanges keys, while IPSec encrypts and signs packets. While manual IPSec is possible, it means you must add and change keys to each device--an ineffective solution since keys can't be updated as often.

You also need a secure way to transmit those keys to other devices. IKE automates the process by using public-key cryptography to create a secure association, which is then used to perform a secure second public-key exchange, resulting in a symmetric key for encryption. IKE adds further functionality, such as rekeying the VPN while in session (if one key is compromised, only the portion encrypted with that key is recoverable) and perfect forward secrecy (no two keys are related).


For the Side Bar on

How We Tested IPSec-Compliant VPN Solutions

IPSec Certification

The IPsec-Compliant VPN Solutions Features charts, in Acrobat format.

The IPsec-Compliant VPN Solution Performance charts, in Acrobat format.


Related Links

Take A Hard Look At Virtual Private Networks
September 15, 1997

Aventail VPN 2.5: Not Your Father's Socks
October 1, 1997

Unlocking Virtual Private Networks
November 1, 1997

internetRx
November 1, 1997

IPv6 For VPNs: It's Looking Better All The Time
January 15, 1998

New Oak Server Turns Over A New VPN Leaf
January 15, 1998

RFP: VPNs Across Multiple Sites
July 1, 1998


Other Reviews

Two NIC Array Solutions Offer Fault Tolerance and Load Balancing
By Robert J. Kohlhepp

Company Directory
to browse our data, starting with a particular company.

Network Computing Links
allows you to request additional product information from our advertisers.

Print This Page


e-mail E-mail this URL






Ready to take that job and shove it?

Function:

Keyword(s):

State:
SPONSOR
RECENT JOB POSTINGS
CAREER NEWS
Go beyond Google and get vertical. These specialized search sites will help you find the business information you need -- fast.

Ari Balogh was named to the post of chief technology officer as the companys for a "realignment" of employees.










InformationWeek U.S. IT Salary Survey 2008
Salaries for business technology professionals are falling. Here's what you need to know in order to make good hiring decisions and personal career choices. Purchase Today: $299
 
ROLLING RIGHT ALONG
Follow key Network Computing Reviews from conception to completion. This Week: Holistic APM.



Network Computing Reports Emerging Enterprise Podcast Series: Secrets to Success








TechSearch


Microsite of the Week


Powerful Information at Your Fingertips



App Infrastructure   |   Messaging & Collaboration   |   Network & Systems Mgmt   |   Network Infrastructure   |   Security  |   Storage & Servers   |   Wireless   |   Enterprise Apps
About Us  |  Contact Us  |  Site Map  |  Media Kit  |   Briefing Centers
Other Techweb Sites:   InformationWeek Reports  |  Intelligent Enterprise  |  Light Reading  |  InformationWeek
Techweb  |  Dark Reading  |  Network Computing Germany  |   Byte & Switch  |  bMighty  |  Small Biz Resource  |  InformationWeek Analytics
Copyright © 2008  United Business Media LLC  |  Privacy Statement  |  Terms of Service  |  Your California Privacy Rights