Upcoming Events

A Network Computing Webinar:
Avoiding Downtime: How Virtualization Can Help In Times of Trouble

June 12, 2013
11:00 AM PT / 2:00 PM ET

Are you caught between a desire for the benefits of the cloud and concerns about security and control? Then you should attend this insight-packed webinar to learn how private data networking technologies like MPLS IP-VPNs can address your concerns and allow you to safely and intelligently reap the savings, agility and other benefits associated with cloud computing.

Join us to hear top industry experts discuss the private data network technologies that are best suited for enterprise cloud access requirements. You won't want to miss this opportunity to learn how your organization can best mitigate risk while reaping the full potential benefits of the cloud.

Register Now!

More Events »

Subscribe to Newsletter

  • Keep up with all of the latest news and analysis on the fast-moving IT industry with Network Computing newsletters.
Sign Up

IPSec Vs. SSL: Picking The Right VPN

Nearly every SSL VPN product enables and encourages tight access-control policies--in fact, it's often difficult to allow open access. When a resource is added, specific access rights for it must be defined. For non-HTTP applications, that typically involves a quick address/port definition. However, depending on the product, HTTP application access can be controlled down to the URI (Uniform Resource Identifier) and the method used to access the resource. For example, if a user can access a Web server, but not the /admin directory, the SSL VPN gateway won't grant the access, thus adding another layer of protection to Web server permissions. Similar access controls can be applied to ftp and Windows file sharing.

Typically, access to resources can be granted or denied based on the client's location, whether it is up-to-date on OS patches or whether it can load the SSL VPN gateways mobile code for cache cleaning. Advanced protection features, such as URI access control and dynamic ACL (access control list), vary by vendor.

For those users who need secure access to non-HTTP applications, SSL VPN products offer two methods. With the so-called "clientless" method, the user downloads a Java or ActiveX component within his or her browser, setting up a proxy on a local-host address (for example, 127.0.0.1), and temporarily modifies the local hosts file to resolve host names to the local-hosts address. The user access level required on the client to start the local proxy on a port below 1023 and change the local hosts file varies with each product--most require local administrator access. Additionally, UDP protocols are rarely supported by SSL VPN products, so be sure you have a firm grasp on your application requirements and ensure the SSL VPN gateway will support them. Don't overlook in-house developed applications. The best practice would involve a detailed log of all applications, testing SSL VPNs with as many as possible.

If you want to go the tried-and-true route, use installed clients on the client and forward sensitive packets over the SSL VPN. Aventail and Juniper support this method. However, there's nothing to download or install and you don't need to jump through any hoops with the user's privileges.

Having It Both Ways


Page: « Previous Page | 123 4 | 56  | Next Page »


Related Reading


More Insights


Network Computing encourages readers to engage in spirited, healthy debate, including taking us to task. However, Network Computing moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. Network Computing further reserves the right to disable the profile of any commenter participating in said activities.

 
Disqus Tips To upload an avatar photo, first complete your Disqus profile. | Please read our commenting policy.
 
Vendor Comparisons
Network Computing’s Vendor Comparisons provide extensive details on products and services, including downloadable feature matrices. Our categories include:

Research and Reports

May 2013
Network Computing: May 2013


TechWeb Careers