Wednesday, September 11, 2019

You Need a Black Cloud Software Defined Perimeter

By: John Shepler

Secure your network with black cloud SoftwareAre you a trusting person? Too bad. That’s going to get you hacked. Respect and privacy are admirable things, but they are not guaranteed by today’s Internet. In addition to all the incredible employees, partners, suppliers and customers that you hold in high regard, there is a dark underbelly of professional criminals, hobbyist & mercenary hackers, mischief makers, psychotics, and nation states with agendas all trolling the same network. Some are looking for victims of opportunity. Others have you in mind as a target. Can your firewall and VPN fend them off?

The Virtual Hopefully Private Network Connection
The VPN or Virtual Private Network was designed to make the Internet act more like a private line or MPLS (Multi-Protocol Label Switching) network. Even if you have a T1, DS3, OC3 or Ethernet private line at the office, you have a big security hole when an employee out on a sales or repair call stops by the coffee shop and connects back using the free Wi-Fi provided by the store.

Free really means free and open. That guy in the corner staring at his laptop is watching your traffic. He either hacked the shop’s WiFi or created his own look-alike “free” WiFi network that you connected to instead of the real one. This is called “man in the middle” and it is what VPN was designed to protect against. The VPN creates an encrypted connection called a “tunnel” from your employee’s computer to your office server. That makes it pretty hard for someone to get in the middle of the conversation unless they have the private key… and they don’t.

VPN Weaknesses
Not all VPNs have a rugged 256 bit military-grade encryption. Some use protocols that are relatively easy to crack with available hacker tools. PPTP (Peer to Peer tunneling Protocol) is over 20 years old and is desirable because it is fast and easy to setup and use. It’s also more vulnerable than protocols with stronger encryption.

Not all VPN vendors are equally capable. Weak ones may have back doors in their servers or other weaknesses that make it easy to hack the VPN server in the cloud and get everybody’s data. You won’t know until you are hacked and can’t figure out how.

An overall weakness of VPN is that it just protects the tunnel into your company. If that is compromised one way or the other, your entire network and everything on it is wide open to explore and perhaps attack. it would be better if only a small part of the company assets were exposed instead of everything all at once.

The Software Defined Perimeter Black Cloud
The idea behind a Software Defined Perimeter (SDP) is that trust is minimized by allowing access to resources user by user on a need to know basis. The research was done by the U.S. Department Information Systems Agency (DISA) and has come to be known as a “Black Cloud.” The black designation means that the network infrastructure is hidden within the cloud. There are no visible DNS or IP addresses.

SDP authenticates each user and only gives them access to the resources you have approved for that particular user so they can do their jobs. The user or IoT device has no idea what else is on the network. They can’t see it. If they can’t see it, they can’t get access. Someone impersonating that user can’t either.

A system of SDP Hosts and Controllers communicate and verify the authorizations. The Controller has the job of connecting the Initiating and Accepting Host data channels through a Gateway, once authentication and authorization has been completed through the control channels.

The SDP is not only between clients and the data center. It is also deployed within the data center to partition the network to isolate high-value applications. Only a limited number of users with have access to the highly protected application or even know it exists.

Encryption and cloaking are key to SDP security. The usual network probing, such as port scanning, won’t work because nothing will show up in the scan. In a way, SDP is creating virtual networks on a user by user, session by session, basis. What goes on behind the curtain is a complete mystery.

The End of Networks As We Know Them?
The TCP/IP network that has served us so well for decades has to go underground to keep its relevance in today’s high threat environment. We can no longer do business without the Internet and there are just too many bad actors on the public Internet. Technology must evolve to provide the illusion of a simple open Internet but with none of the familiar network topology visible.

Has your company network been hacked or are you concerned about the business disruption this might cause? Right now would be a good time to see what advances have been made in network security, especially managed security solutions in the cloud.

Click to check pricing and features or get support from a Telarus product specialist.

Follow Telexplainer on Twitter

Friday, August 23, 2019

T1, T3 and Ethernet Bandwidth

By: John Shepler

Are you considering new or additional bandwidth for your business office, retail store, or other commercial location? Professional grade options include high performance T1 lines, T3 (DS3) lines, and Ethernet options over copper and fiber optic cables.

Find T1, T3, DS3 and Ethernet bandwidth options now.T1 Lines
T1 Lines have been the mainstay of many, many businesses for decades. They still are, although for more special situations. The big advantage of T1 lines is that they are provisioned over standard twisted pair copper telephone wiring. If you can get landline phone service installed, it’s likely you can also get T1 service. That includes rural areas where there isn’t much else to pick from.

T1 lines are highly reliable, get fast service if something goes wrong, and are dedicated to your use only. The bandwidth is symmetrical. That is, the upload and download speeds are identical. That’s important if you exchange large data files or back them up to the cloud.

T1 lines can be configured for dedicated Internet access or point to point connections. They support ISDN PRI telephone trunks for multi-line phone and PBX systems. Their one limitation is the bandwidth, which is fixed at 1.5 Mbps. That’s rather slow in broadband terms, but perfectly useful for small business point of sale terminals, email and casual web browsing. Additional T1 lines can be bonded to increase the bandwidth to 3, 4.5, 6 or even 10 Mbps.

Ethernet over Copper Lines
Ethernet over Copper (EoC) is a modern technical upgrade to legacy T1. It uses the same copper telephone lines, but can support higher speeds. Bandwidths of 10 or 20 Mbps are common within metro areas. Some support is also available for rural businesses, but not as ubiquitous as T1 service. Additionally, EoC is generally less expensive per Mbps than traditional T1 lines. You can often get twice or more bandwidth for the same monthly lease cost.

T3 Lines
T3 lines are in the same technology family as T1 lines. The bandwidth is much higher, 45 Mbps vs 1.5 Mbps. T3 refers to the actual lines, which are coaxial, waveguide or microwave relay. These days T3 is delivered as a service on SONET fiber optic lines and referred to as DS3. Like T1, T3 or DS3 service is highly reliable, dedicated and symmetrical.

Ethernet over Fiber Lines
Ethernet over Fiber (EoF) is the modern technical upgrade to SONET fiber optic service. As such, EoF replaces T3 and DS3 with the same bandwidth at a better price. Unlike T3 and DS3, Ethernet over Fiber offers a wide range of bandwidth choices instead of the fixed 45 Mbps service. You can typically get EoF service from 10 Mbps on the low end up to 10 Gbps or even 100 Gbps. You also have the option of changing your mind at any time to upgrade or downgrade your service. Usually, no hardware changes are required. You are billed for the bandwidth level you order rather than a fixed 45 Mbps.

Until recently, fiber optic service was limited to major metropolitan areas and rather expensive. The entrance of competitive service providers and the high demand to supply cell towers to support 4G and 5G broadband has vastly increased the amount of fiber optic services available. Most offices, business parks and retail locations now have the option for competitive fiber bandwidth pricing. Some lines are even available to rural locations.

You have a wide range of possibilities for your business bandwidth that include T1, T3 (DS3) and Ethernet over Copper and Fiber. Check pricing and availability now.

Click to check pricing and features or get support from a Telarus product specialist.

Follow Telexplainer on Twitter

Tuesday, July 16, 2019

Fiber Optic Ethernet Transport Offers Huge Advantages

By: John Shepler

There are many ways to transport your data from one place to another. The new gold standard has become Fiber Optic Ethernet lines, also known as EoF or Ethernet over Fiber. You’ll have a hard time beating this solution on a cost/performance basis.

Check prices and availability of Fiber Optic Ethernet service now.What is Fiber Optic Ethernet Transport?
Ethernet wasn’t part of the equation when fiber optic lines started to be buried in the ground and strung of utility poles for the telecom industry. The original standard was SONET (Synchronous Optical NETworking). This standard was designed to be backwards compatible with existing DS1 and DS3 multiplexed telephone calls in order to carry them on fiber. Why fiber? There's much more bandwidth in a single pair of optic fibers compared with legacy copper twisted pair, microwave and coaxial copper line.

Ethernet was born in the computer industry for local area networking. Transmitting this data outside the wired building or campus required a protocol conversion so that T-carrier and SONET fiber could carry packets instead of digitized phone calls. Decades later the efficiency of carrying Ethernet directly instead of first converting to an older protocol was standardized. Two varieties emerged. Ethernet over Copper and Ethernet over Fiber. For shorter distances, wireless Ethernet over line of sight microwave, laser, and radio systems such as WiFi and WiMAX were also developed.

The Immense Advantage of Fiber Optic Ethernet
Carrier Ethernet has been adopted by competitive telecom providers as well as the legacy telco companies. The first advantage is that it is directly compatible with computer networks. It’s Ethernet, after all. There is no need to deal with the inefficiency of converting back and forth between some other protocol. Just plug in your network and go. If you order a service such as E-LAN, you can interconnect your LANs at multiple locations as if they were on one big network.

The second big advantage is that Ethernet is easily scalable. When you order traditional MAN (Metropolitan Area Network) or WAN (Wide Area Network) services, you get a line with a fixed speed. T1 is 1.5 Mbps, DS3 is 45 Mbps and OC3 is 155 Mbps. That speed determines how much data you can transmit per unit of time and it also determines the price you pay. What’s more, if you outgrow your line service, you have to upgrade to another line standard and get all new termination equipment. A higher speed service may or may not even be available for upgrade.

With Fiber Ethernet you really don’t have an upper limit. Each fiber strand can carry maybe 10 Gbps and could be wavelength multiplexed with dozens or even hundreds of 10 Gbps channels. Fibers are so small that cable bundles might have over a hundred fiber strands. It’s going to be pretty hard to run out of capacity.

The nice part is that you don’t have to pay for all of that capacity. You order a service level, say 100 Mbps or 1 Gbps, and that’s what you are charged for. If you find that you need more, you can get upgraded to a higher service level with a phone call or even with an online portal. You can get as much bandwidth as the port capacity that is installed at your location. That’s typically 1 Gbps minimum, with options for 10 Gbps or even 100 Gbps.

Best Advantage of All
Thanks to competition in the marketplace and the enormous inherent capacity of optic fibers, the price you pay per Mbps is lower than it has ever been, and usually far better than with older SONET technology. That price is for highly reliable circuits, often with service level guarantees. The bandwidth is both symmetrical, same upload and download speed, and dedicated for your use only.

Competing Bandwidth Options
If you only need bandwidths of 10 or 25 Mbps, Ethernet over Copper can give you similar advantages to Ethernet over Fiber. At lower speeds, 1.5 or 3 Mbps, a T1 line is still attractive.

The bargain basement bandwidth options include business cable broadband, wireless Internet service providers, Satellite broadband, telephone DSL lines, and cellular broadband. All of these were developed for the price sensitive consumer market and then offered to small businesses with needs that aren’t too demanding. Prices per Mbps are very attractive. Most of this comes from the fact that bandwidth is shared among users and not dedicated to a single customer. Bandwidth is also non-symmetrical. Download speeds are typically 10x upload speeds.

Wireless services tend to have pretty restrictive usage limits and are not suitable for downloading big software updates or transferring large files. Satellite is available nearly everywhere, but has latency issues that make it difficult to use for telephone and other real-time services.

Note that these services are almost always Internet access only. Fiber Ethernet can be set up as dedicated Internet access or point to point private lines.

What bandwidth service is best for your business? You have many more options that you may realize and pricing that could be better than expected. Find out now, what Fiber Optic Ethernet services are available for your business locations.

Click to check pricing and features or get support from a Telarus product specialist.

Follow Telexplainer on Twitter

Tuesday, July 09, 2019

Enterprise VoIP Moves to the Cloud

by: John Shepler

Enterprise VoIP has been replacing switched circuit analog telephone business systems for decades. PBX systems transformed into IP PBX, but they were still premises based hardware and software. Now those telecom rooms are emptying as business VoIP moves to the cloud and transforms into Unified Communications.

Find the cloud communications services you need now. What’s Cloud Got To Do With It?
Businesses started installing their own phone switching equipment when half a dozen buttons on a desk phone weren’t enough anymore. PBX actually stands for Private Branch Exchange. It mimics the phone company central office but sized just for your company. Even so, that can mean hundreds or thousands of people and phones. PBX systems that can handle this amount of traffic often require their own dedicated staff.

The impetus to move to the cloud centers around clearing out all that equipment and the staff to keep it updated and running smoothly. However, it’s not magic. The common joke about the cloud is that there really is no cloud, it’s just somebody else’s computer. That’s about it. Only cloud providers have huge facilities with huge staffs for economy of scale. You not only get away from the hassle of running a phone system, you can likely save money in the process.

New Capability and No Investment Required
One problem with in-house technology is that it’s easy to outgrow and it goes obsolete really fast. You avoid both issues with cloud services. A decent size cloud can handle as much expansion as you can think of. Software updates are routinely handled by the provider. Most PBX functions are now in software anyway. That means that adding or changing features doesn’t require junking racks full of perfectly good equipment. It’s a simple download to what is likely a virtual server.

Telephone calls are getting to be just one of many functions that companies want in their “phone” system. The old standard desk phone has to easily integrate with mobile smartphones where a lot of the conversations are taking place. Then there is text messaging, email and video conferencing. This is how business people communicate these days. The voice call is just one option. With IP telephony, the concept of voice as an application has been realized. What’s more, you may want to have multiple types of communication going on at the same time. That’s Unified Communications and cloud providers offer it under the name Unified Communications as a Service or UCaaS.

Special Needs of Call Centers
Many businesses find it advantageous to have their own in-house call center rather than outsourcing that function. With managed cloud services this is easily realized. You can add features such as an automated receptionist, call recording, automatic call distribution, interactive voice responses, call queues, skills-based routing, dedicated phone numbers, integration with CRM systems and reporting & metrics.

The beauty of cloud based call centers is that they don’t much care where the employees are located. None of your people will be sitting in the cloud data center anyway. This means that you can easily add remote workers and contractors to your team. They just let the system know when they are available and they’ll start getting assignments until they indicate they are unavailable.

What It Takes to Connect To the Cloud
You need to take special care in connecting your business and your people to the cloud if you want top notch performance. The Internet can be a bit dicey at the worst possible time, so you want the best connections possible. From your home office and remote offices, if possible, dedicated lines or SIP Trunks are best. Just avoid the Internet all together. Home workers may not even have that option or it can be too expensive for one worker locations, so the most reliable high speed broadband available is highly desirable. New SDN or Software Defined Networks make it easy to combine several broadband connection to make one faster and more reliable Internet connection. That can be the difference between distorted and interrupted calls and smooth seamless connections.

Are you getting frustrated with an under-performing phone system or feel you are missing out on productivity by not having the latest UCaaS features? You have many options available and complementary expert consulting to help you pick the most appropriate for your organization. Find out what Enterprise VoIP, Call Center and UCaaS services are available to you now, quickly and easily.

Click to check pricing and features or get support from a Telarus product specialist.

Follow Telexplainer on Twitter

Wednesday, June 26, 2019

How to Feed a Hungry WISP

By: John Shepler

We’re a wired nation, except when it comes to locations that are a bit off the beaten path. That includes farms, rural households, businesses beyond the city limits, new subdivisions and some industrial parks. While they may have telephone, thanks to universal service, the availability of broadband Internet access is less of a sure thing. This is where the wireless broadband supplier or WISP fills the gap.

Get the best bandwidth pricing for your WISP.Why WISPs?
WISP or Wireless Internet Service Provider is similar to a cell phone provider, except specializing in high speed Internet access. While even 4G cell service has fairly low usage limits, WISP services are much more generous and try to emulate the type of service you’d get from cable, telco or even fiber optic lines. The real cost to hooking up less populated areas is trenching cable bundles or flying them on utility poles. The WISP eliminates the wires and their associated cost. The tradeoff is that you generally need a small dish antenna and receiver outside to pick up the signal from the WISP tower.

Where Do WISPs Get Their Broadband?
While the WISP distributes broadband much like WiFi, the broadband they serve must come from somewhere. When the Internet was young, T1 lines did an excellent job of feeding the WISP, just like they did feeding cell towers out in the countryside. The beauty of T1 is that it can be sent virtually any distance over standard twisted pair telephone wiring. The downside is that the bandwidth is fixed at 1.5 Mbps per T1 line. Higher speeds can be accomplished by adding or bonding additional lines to double, triple or quadruple the speed. The practical limit is around 10 to 12 Mbps. Pricing goes up linearly as you add each line.

Higher Speed Copper Lines
A newer technology that also runs over twisted pair copper is Ethernet over Copper (EoC). This service offers higher speeds, say 20 or 30 Mbps or even higher. Transmission is distance limited, but EoC is now more available beyond the city limits. Cost is much more attractive per Mbps than T1, if moderate speeds are adequate for what you need.

Business Cable Broadband can provide hundreds of Mbps these days but has suffered from very limited deployment outside of metro areas. That has changed somewhat as the cable has been extended to outlying subdivisions and business parks. If you can get this service and the Cable Company is OK with using it for a WISP, the cost will be very attractive.

Fiber Optic Service
The new gold standard of bandwidth service is fiber optic lines. These used to be few and far between, but provider competition has made them far more common even in rural areas. You can thank 4G cellular for providing the incentive to trench fiber conduits into rural areas. Prices have come down dramatically with Ethernet over Fiber (EoF) services. These are highly reliable and easily scalable up and down in bandwidth to meet your needs. Bandwidths of 10 Gbps up to 100 Gbps are common now.

Microwave Transmission
Why not feed wireless with wireless? That’s not a crazy idea and is being used more and more as telco companies upgrade to 5G towers. Microwave is a point to point wireless service. You mount a small dish on your tower and point it toward the service provider. It’s like fiber but without the fiber.

SDN Combines Bandwidth
What if you need more bandwidth than any one supplier can provide? One option is to combine them using a technique called SDN or Software Defined Network, also known as SD-WAN or Software Defined Wide Area Network. The SDN controller manages traffic to get the best performance for each packet. You can combine T1, EoC, cable broadband, microwave, fiber optic lines and even satellite Internet to create a higher speed robust feed for your WISP tower.

Do you operate a WISP service or have one in the planning stage? Find out what bandwidths and pricing are available for your desired locations now. A friendly consultant will help you sort through the options.

Click to check pricing and features or get support from a Telarus product specialist.

Follow Telexplainer on Twitter