Advertisement
Promo

Office applications Toolkit

SSL-based VPNs are gaining favour

Salvatore Salamone

Published: 27 Aug 2002 16:01 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

While the need for secure remote connectivity to applications and data continues to drive the virtual private networking (VPN) market, some companies are discovering that deploying an IP Security (IPSec) VPN brings complications they would rather avoid. These problems are especially pronounced when the VPN's primary goal is to provide remote users--customers, business partners, or employees--with secure access to a limited set of applications.

One alternative to a traditional VPN is an SSL-based VPN. An SSL-based VPN offers comparable security to the traditional IPSec VPN, but promises to be simpler to use. This ease of use has prompted analysts to predict a positive future for the technology, but this simplicity does come with a caveat: a reduction in functionality.

How SSL-VPNs work
SSL-based VPNs use an SSL/proxy server that sits behind the corporate firewall. A user wishing to securely connect to a company's network enters a URL that brings them to a proxy server. The user is authenticated by the proxy server, and the SSL/proxy server provides the link between various application servers and the remote user. The advantage over a traditional IPSec VPN is that no special client software is required. All a user needs is a Web browser that supports SSL.

In contrast, traditional VPNs require client software--a sticking point to VPN deployment for many companies. Businesses often encounter problems deploying the software to users' computers and have trouble configuring it correctly. In some cases, the VPN client software creates conflicts with other applications (particularly dialer programs that might share common systems resources).

Over the last few years, many VPN vendors have improved client software to ease distribution, installation, and configuration. Many CIOs have also adopted deployment methodologies that reduce problems. For instance, in some enterprises remote users, such as sales reps, bring laptops into the home office to have the VPN software installed by the IT staff rather than by the user. This way, the tech specialist can resolve any problems on the spot rather than trying to troubleshoot over the phone.

Such complications can be avoided with an SSL-based VPN because the user simply uses a Web browser and enters the URL of the SSL/proxy server.

A handful of vendors, including Aventail, Neoteris, NetSilica, and Netilla Networks, are offering SSL-based VPNs. Yo.net offers a VPN alternative that uses SSL and an authentication gateway to provide secure end-to-end access between a remote user's computer and a wide range of systems, applications, and network services. All but Aventail, which specialises in large corporate and extranet connectivity, are new to the marketplace. Aventail offers both IPSec and SSL-based VPNs.

The pros and cons of SSL-VPNs
On some levels, the two VPN approaches offer comparable features. Both are encrypted, though with different algorithms. SSL uses 40 or 128-bit RSA encryption, while IPsec uses 168-bit Triple-DES encryption.

Since SSL is a Web encryption technique, it might seem that SSL-based VPNs would be subject to another major limitation, since most corporate applications are not delivered through the Web. There are ways round this -- by using a proxy,m such as the box from Netilla or a similar vendor, to deliver access through Windows terminal server.

However, even without this addition, the SSL-based approach is proving very useful for some.

"We have two types of users--employees and customers--each needing access to different information," explained Andrew Goldstone, a network administrator at a medical supply company.

"Employees need access to everything, including a network-based e-mail system, our CRM application, and some custom-developed client/server applications," said Goldstone. Using IPSec VPNs, Goldstone can provide remote access to all of these applications.

Goldstone acknowledges a slightly different scenario when it comes to customers. "They only need access to an order tracking system, which is Web-based, so we use an SSL approach."

While some might find the limitations of SSL-based VPNs a major hurdle, the shortcoming may quickly diminish as many companies move to Web services-enabled applications. Such applications would be accessible using the SSL-based VPN approach.

For now, companies requiring secure access to Web applications might want to consider the SSL-based VPN approach as a simpler and easier-to-use alternative to traditional IPSec VPNs.


Have your say instantly, in the Tech Update forum.

For a weekly round-up of the enterprise IT news, sign up for the Tech Update newsletter.

Find out what's where in the new Tech Update with our Guided Tour.

Tell us what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
46 out of 77 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Video icon

Video

Win a BlackBerry with Vlingo voice recognition

Win a BlackBerry with Vlingo voice recognition

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010

Discussions

ator1940 ator1940

Microsoft Loses Patent Case Appeal

Friday 25 December 2009, 9:35 PM

6 comments
J.A. Watson J.A. Watson

Google it

Friday 25 December 2009, 1:40 PM

3 comments
J.A. Watson J.A. Watson

Google it

Friday 25 December 2009, 1:38 PM

3 comments
Shibley R Shibley R

Question!

Friday 25 December 2009, 11:09 AM

3 comments

Vista Upgrade Blog

How to Upgrade From Windows Vista to W...

Did you get the news? Microsoft has unzipped its kitty and kept its latest, supposedly the best, offering on display. This is the brand new version of Microsoft operating system, named... More

Post a comment

Tinsel on the TARDIS

There were shepherds on the hill, and the Doctor popped his head out of the TARDIS and said "you might want to see this" and they were astounded. WHY do we pay for a TV license?... More

Post a comment

Can I have fries with that? (Consumer...

Licence policies of Tech company's have been for a long time both complicated and 'Dick Turpin-esque', people just click 'I agree' without reading the Agreement. I do the same, but... More

1 comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters