Showing posts with label IPSec. Show all posts
Showing posts with label IPSec. Show all posts

Monday, April 16, 2018

Private Lines and Virtual Private Networks

By: John Shepler

Businesses often have need for a private line to communicate between headquarters and branch offices, factories & warehouses, retail franchises or suppliers. What’s important is reliable connections with security and transparency. The ideal private line gives you the same experience as your local area network.

Find private line and virtual private network solutionsClassic Point to Point Private Lines
Telephone companies have offered private lines since the analog days. Security systems and radio station studio to transmitter links are examples of private lines that were often little more than pairs of wires that ran directly from one location to another via the central office.

Digital communication introduced the T1 point to point private line that serves the same purpose. Bits go in one end and come out the other. T1 lines at 1.5 Mbps, DS3 at 45 Mbps and OC3 at 155 Mbps all offer private line service. Latency and packet loss are low. Speeds are fixed at the capacity of the line.

These private lines work well for connecting a central headquarters as a hub to branch offices as spokes. It takes one line per branch with the central switch or router directing traffic. The lines themselves serve as very, very long network wires to interconnect the LANs at the various locations.

Ethernet Private Lines
Since Ethernet is the protocol used on virtually all local networks today, it makes sense to have the private line running the same protocol. The telco solutions already mentioned require a protocol conversion module to convert between Ethernet and the proprietary protocol that runs on the lines themselves.

Carrier Ethernet private lines run the Ethernet protocol on the line itself. Carrier Ethernet is available as Ethernet over Copper for lower speed connections and Ethernet over Fiber for 10 Mbps to 10 Gbps, with 100 Gbps becoming more available.

Ethernet services have more carriers competing for business which tends to reduce prices per Mbps. The cost per Mbps is almost always less for Ethernet and scalability is much easier. You can have a Gigabit Ethernet port installed and order any bandwidth from 10 Mbps up to 1000 Mbps. When you want an increase or decrease in capacity, a simple phone call to the carrier will make that happen quickly with no equipment changes required.

MPLS Networks
Private lines are a great solution if you only need to interconnect a few locations in a small geographical area. As the number of locations and their distance from headquarters increases, the cost goes up quickly. Each line has a charge and it varies with distance.

A popular alternative is the MPLS or Multi-Protocol Label Switching network. This is a privately run network that uses a proprietary protocol called label switching instead of the more common TCP/IP. The fact that access is limited to subscribers only and the uniqueness of the LS protocol provide a level of security even though you are sharing the network with other users.

MPLS operators work to ensure that you have no awareness of other traffic. Bandwidth, latency, jitter and packet loss are carefully managed to meet the needs of all subscribers with extra margin for bandwidth bursting when needed.

MPLS is also known a MPLS VPN or Virtual Private Network. That’s because it isn’t truly private and fully dedicated to your use like a private line. If you are feel that you need a additional level of security, you do have the option to encrypt your data before it enters the MPLS network.

Why choose MPLS? It’s a big money saver over long distances where private lines get expensive. All you need is a short private line connection to the network at each location and instructions to the operator as to how to route your traffic.

Internet VPN Solutions
The Internet is the least cost wide area networking solution with highest geographic connectivity. Performance can vary widely. It’s also the least secure network you can find. Anyone and everyone can easily get a connection, and they do.

How can you make the Internet act like a private line? You provide your own encryption from point to point. Two popular approaches are IPsec based on software installed on each computer and SSL or Secure Socket Layer that is already built into web browsers.

Choosing a Private Line Solution
Which approach is best? It depends highly on how many locations you have, where they are, what traffic you intend to send, and what level of performance you require.
There are cost/benefit tradeoffs to each of the above solutions. What’s right for you? An expert consultant will be happy to review your private line or VPN network needs and provide one or more solutions that can do what your business needs done.

Click to check pricing and features or get support from a Telarus product specialist.



Follow Telexplainer on Twitter

Monday, December 17, 2012

Different Types of VPN Providers

Your network is private and you work hard to keep it that way. What about when you connect to the outside world? Do you open your castle gate to let in everybody and everything festering on the Internet? Or, do you protect your network over long distances by using a private or virtually private network?

Check out the business grade private and virtually private network options...Before there were VPNs (Virtual Private Networks) there were private networks. There still are. Some situations require so much security that the only way to be sure you maintain control and avoid all intrusion is by using private line point to point connections. You might even go one step further and encrypt the data traveling on those private lines on the odd chance that someone has figured out how to tap in.

Private lines make the most sense when you have only two locations to connect. You can order order a “nailed up” T1 line from point to point. By “nailed up” I mean that the connection is hard wired and stays that way as long as you pay the monthly lease. There is no traffic other than yours on this circuit. Whatever you aren’t using to full capacity simply idles while waiting to be used day and night.

Need a lot more bandwidth? You can order DS3 private lines at 45 Mbps or move up to fiber optic service starting at 155 Mbps. An alternative is Carrier Ethernet over copper or fiber. With Ethernet you have many more bandwidth options and the cost is generally lower than with traditional telecom services.

Note that these circuits are dedicated to your locations, but your data may be multiplexed with data from other users while it is on the line. SONET fiber service and Ethernet over Fiber has so much bandwidth that it doesn’t make economic sense to use an entire strand or even a wavelength for 50 or 100 Mbps of traffic.

This is the beginning of virtual private networking. In this case, the provider divvies up the available bandwidth by TDM (Time Division Multiplexing) time slots or virtual private circuits. Since the network is privately operated, you have the protection that the general public has no outside access to any of this traffic and no way to snoop on your data stream or cause trouble.

If you need really massive amounts of bandwidth, you can rent wavelengths on fiber circuits at typically 5 Gbps or rent dark fiber strands themselves that can support nearly unlimited bandwidth. These offer an increased security in that only your traffic is on the wavelength or fiber strand.

Another VPN methodology is the MPLS network. MPLS or Multi Protocol Label Switching also runs on privately operated networks. It transports IP traffic as well as other protocols but doesn’t use IP labels for routing. Instead MPLS switches install special tags on each packet upon entry to the network and remove them before egress. This is where the virtual private designation comes in. You share the network with other users, but the proprietary MPLS technology protects the privacy of your data while it is on the network. You’ll hear this service referred to as MPLS VPN.

The most common application for VPN is when using the Internet as your connection from point to point or to the general public. If you do business on the Internet, you don’t really have a choice. You may also want to have home workers or traveling employees connect to your business systems without the expense of private lines. The challenge is how to make an inherently risky network like the Internet into something your can trust with sensitive date.

The answer is “tunneling.” This is a concept for creating private channels through a public network. The tunneling is accomplished by encrypting each packet so that it makes no sense to anyone but the intended parties. There are two software methods commonly used to accomplish this.

The legacy method is IPsec or Internet Protocol security. This requires special software to be installed on the company server and client computer. IPsec does the encryption and decryption and must be specially set up to create the virtually private tunnel. One installed, you have a VPN connection from wherever you want to use that particular computer. Other computers must have the same software installed or they won’t work on the VPN.

A competing method is called SLL or Secure Socket Layer. This is the technology you use when accessing your bank account or secure email. It’s become so standard that it is built into all Web browsers and many email programs. With SSL, you need a user account ID and a password to access your remote account. The nice feature is that you an access your account from just about any computer, private or public, and know that your data is securely encrypted.

Are you in need of a business-grade private or virtually private network connection? If so, check out the options and decide which works best for your applications.

Click to check pricing and features or get support from a Telarus product specialist.



Follow Telexplainer on Twitter

Wednesday, October 19, 2011

Types of VPN Connections

Virtual private networking is heavily used in business. In fact, you probably have used a VPN connection today without even realizing it. It’s not a belt and suspenders service anymore. VPN connections are absolutely essential to prevent being robbed blind.

Virtual Private Networking provides security at a reasonable cost...First, let’s take a look at private vs virtually private networks. Your hardwired LAN is a private network. It would take some real effort and a lot of risk for someone to tap into your network wiring and install a device to capture traffic. The same is true if you establish a wide area network or WAN using point to point private lines. A PTP T1 line falls into that category. While it is not impossible to sneak into your wiring closet or even the telephone company and put a tap on the line, it is so difficult that only those with the most secure requirements will go to extremes to protect against this type of attack.

What distinguishes a private network is that 100% of the traffic is yours and yours alone. You are not sharing the lines with anyone else. The advantage to a private network is inherent security. The disadvantage is cost. You pay for all the construction, maintenance and monthly lease fees. It’s unlikely that your private network will be fully loaded at all times. Whatever capacity is unused goes to waste.

Contrast the private network with a public network like the Internet. They are polar opposites. The Internet allows anyone and everyone access by design. Traffic on the Internet is everybody in the pool. Your packets are intermingled with everyone else’s. Even so, a wired connection to the Internet isn’t the worst situation. That belongs to the unsecured wireless network. No need to plant malware in someone’s computer when everything they are doing is perfectly visible on any WiFi enabled computer within range. You are most vulnerable reading private unencrypted emails in a popular public hotspot. Anyone with a laptop computer and some easy to obtain spyware can be reading your messages right along with you.

It seems like such a crying shame that the one network that any employee can access at home or while traveling is such a security nightmare. That’s where the technique of encryption becomes valuable. It doesn’t matter if someone is monitoring your traffic if all they see is gibberish. You encrypt your message at one end and decrypt it at the other end and you have a created what is known as a secure tunnel through the Internet. The public network has now become a virtually private network. It’s not a private network because you are still sharing the transport with many others. It’s virtually private because no one can read your traffic and make any sense out of it.

There are two popular methods of creating Internet or IP VPNs. One is IPsec or Internet Protocol security. The other is SSL or Secure Socket Layers. IPsec is based on software installed in both the company server and the client computer. IPsec encrypts and decrypts each packet, so once you have it installed you have a virtually private line to the company no matter where you hooked to the Internet. Of course, you need to use the specific laptop or other computer set up to work with this system. You can’t just go to any computer and connect back to headquarters.

If you want to do that, you need SSL (Secure Socket Layer). The beauty of SSL is that the software is already built into Web browsers and some email programs. SSL has been popularized for ecommerce and online banking. When you go to a SSL enabled webpage, you’ll notice that the http:// has become https:// The “s” means secure page. To access it you need a user account ID and a password at a minimum. Some sites go further and ask personal challenge questions or display special graphics that give you confidence you are logged into the correct site.

For corporate wide area networks, an alternative to private lines is the MPLS network. These are multi-tenant networks that spread the cost of building and running the system among many users. MPLS networks are considered VPNs because they use a proprietary label switching protocol that isn’t compatible with IP tools. This unique protocol plus access controlled to a limited number of business clients and not the general public give MPLS networks an enhanced level of security.

Do you need private or virtually private network connects to conduct business? If so, compare VPN options and prices to help decide which mix of network techniques is right for your company.

Click to check pricing and features or get support from a Telarus product specialist.




Follow Telexplainer on Twitter

Monday, January 31, 2011

DIA and VPN For Europe

Level 3 Communications, a Tier 1 Internet networking services company with a global fiber optic footprint, is bringing its Dedicated Internet Access (DIA) and Virtual Private Network (VPN) services portfolio to European markets, including France, Germany and the United Kingdom. As the worldwide business climate improves, international connectivity will become more and more important for business success in a global marketplace.

DIA and VPN network services for European, as well as other international markets. Click for pricing and availability.Major multinational corporations and larger Internet Service Providers may operate their own Autonomous System (AS) networks that give them the ability to peer with other networks and purchase IP transit services to get to the Internet backbone. But many businesses don’t have or want the level of investment that it takes to operate an International private network. These companies still need high quality, reliable Internet access for e-commerce, communication with their customers, and private connections between far-flung company locations.

Dedicated Internet Access is the service of choice for most business users. What dedicated means is that you have exclusive use of the bandwidth that you purchase to connect to the Internet. But isn’t that always the case? Not really. Residential users and smaller businesses get by with shared bandwidth arrangements such as DSL, Cable broadband, two-way high speed satellite Internet, and 3G or 4G wireless.

The motivation behind bandwidth sharing is that costs are shared as well. The cost of shared bandwidth broadband services is usually well below equivalent speed dedicated bandwidth services. The price you pay is acceptance of not having a guaranteed bandwidth. Indeed, the bandwidth at any given time is a function of how many other users are sharing the service and what they are doing. Just a few people download huge software, database or video files can bring a speedy line to a crawl.

You don’t experience this with Dedicated Internet Access. You have the full T1 line speed of 1.5 Mbps or E1 line speed of 2.0 Mbps available in both upload and download directions at all times. Ethernet access connections are becoming popular as replacements for legacy T1/E1 lines. Ethernet is highly scalable from 1 Mbps on up to 10 Gbps. The lower line speeds can be provisioned over twisted pair copper, while higher speeds require fiber optic connections.

The VPN or Virtual Private Network is a way to take advantage of the universal reach of the Internet while adding a layer of security to protect your data during the time it is traversing the Internet.

Many companies have private point to point connections to securely link multiple business locations within a metropolitan areas or in nearby states. International private lines are also available, but they are pretty expensive for smaller companies to connect with sales offices overseas.

The Virtual Private Network makes it possible for businesses of all sizes to interconnect their domestic or global facilities. Another popular use for VPNs is to provide access to company networks for employees working from home or on the road. Without VPN capability, the organization would have to install a dedicated line between the corporate data center and they employee’s home at considerable cost.

The way a VPN works is that it encrypts the data packets so that they can’t be decoded by anyone who happens to gain access to them along the way. The process is said to create a “tunnel” through the Internet. There a two popular ways to do this. One is IPSec, which requires special client software at each end to perform the encryption and decryption of the data. Another approach is SSL or Secure Socket Layer. This technique requires only a standard Web browser for access. It uses the same encryption employed by ecommerce sites so that visitors can make online purchases securely.

Do you have need for Dedicated Internet Access or Virtual Private Network service to support your business or organization? If so, get prices and availability for DIA and VPN services to meet your requirements.

Click to check pricing and features or get support from a Telarus product specialist.


Note: Physical map of Europe courtesy of Wikimedia Commons



Follow Telexplainer on Twitter

Wednesday, June 16, 2010

IP VPN vs MPLS VPN

Security is an issue anytime you send data into a cloud network. One way to ensure that your data cannot be observed or tampered with is to build your own WAN network from point to point private lines. Another approach is to use a virtual private network that runs on resources that you don’t have exclusive use of. That’s what is meant by a VPN.

Check out IP VPN and MPLS options quickly and easily. The beauty of using dedicated private line connections is that you are in control of both access and resource utilization. You need to manage bandwidth demand and packet priority. What you don’t have to worry about is someone else crowding you for resources. There is no one else. If you are really concerned about malicious parties tapping into your line surreptitiously, you can chose to encrypt the data while it traverses the WAN connection. That’s the ultimate in network security. It’s also the highest cost approach.

What’s attractive about VPN solutions is that they are much less expensive to lease and require fewer resources on your part. Both the cost and resource savings come from sharing the facilities with other parties. The Internet is a prime example of how massive utilization can drive down costs. If you want to really minimize costs, a shared access connection, such as DSL or Cable broadband, is the cheapest approach by far.

The same things that make the Internet cheap also make it insecure. Anybody and everybody worldwide can connect to the Internet for what you are paying or less. Perhaps they’re using a public library or WiFi hotspot network without paying a cent. Many of these networks make no effort to even verify user identity. It’s the perfect breeding ground for mischief makers and criminal activities.

Fortunately, there is a way to secure your data as it traverses the Internet. The trick is encryption. You encrypt your data packets using a key that only you know. Anyone else who has access to your data stream sees only gibberish. A popular standard for doing this is called IPsec for IP security. It requires hardware and/or software that you manage at each location for the encryption/decryption process.

IPsec lets you create a virtually private network out of the Internet, a completely public network. This is generally what is meant by the term IP VPN. One big advantage of this IP VPN approach is that laptop computers can be configured with this system to give corporate access to remote or home workers. All that’s needed is the VPN enabled computer and a broadband Internet connection.

While the Internet is cheap, it offers no guaranteed performance. You take your chances on network congestion, packet corruption, latency and jitter. File transfers generally work fine, but voice and video can degrade without warning. Many businesses want a more reliable network to connect their branch offices, warehouses, retail locations, and so on.

MPLS networks come to the rescue as an improved form of virtual private network. The MPLS network doesn’t have public access, but it is a shared resource. Your costs are reduced compared to dedicated private lines because the cost of regional, national or international connections are amortized across the total user base. What makes MPLS networks a VPN solution is that your data connections are essentially tunneled through the cloud wrapped in proprietary routing labels. You define your connections and the network operator instructs the MPLS network on how to route your packets.

MPLS networks are often referred to as MPLS VPN because they are inherently virtually private. Connections to the network tend to be through dedicated private lines, such as T1 or Ethernet. If you want an even higher level of privacy, you can choose to encrypt your data while it traverses the MPLS network. In addition to improved security compared to the Internet, MPLS networks offer performance guarantees for bandwidth, jitter, latency and packet loss. That makes MPLS VPN a popular choice for mission-critical business applications.

Do you have a need to connect multiple business locations? Which type of VPN makes the most sense for your needs? Is it IP VPN or MPLS VPN? One easy way to sort out the options is to get complimentary network consultation and price quotes through our Affordable VPN site. You may well be spending far more than you need to for the performance and security you desire.

Click to check pricing and features or get support from a Telarus product specialist.




Follow Telexplainer on Twitter

Wednesday, November 11, 2009

MegaPath’s Black Friday Strategy

Black Friday will soon be upon us. This is the day after Thanksgiving that marks the traditional start to the Christmas shopping season. It’s a day that retailers brace for and depend on. For as Black Friday goes, so goes the profitability of the year.

Credit Card Swipe - Is your business Black Friday ready?The name Black Friday is generally attributed to the accounting practice of using red ink to show losses and black ink to show profits. Many retailers struggle all year long just to pay the bills and keep the lights on. Black Friday represents, at least symbolically, the change of the company’s fortunes from red ink to black ink. That’s how important the holiday shopping season is every year. It can be the difference between profit and loss, survival of the business or bankruptcy.

Since Black Friday and its online equivalent called Cyber Monday (The Monday after Black Friday) kickoff the most stressful and highest sales volume month of the year, it behooves retail businesses to have robust processes in place ahead of time. That includes the ability to process credit card transactions rapidly and securely. Lose your connection to the credit card processing companies, even for an hour, and you risk a stampede of irate customers out your front door and directly to your competitor. It’s even worse online. If your site is down or slow or you can’t accept credit card payments, your competitors are just a click away.

With this in mind, MegaPath is asking retailers, “Are You Prepared For Black Friday?” Even with predictions that consumers will be spending slightly less this year than last, there will still be a torrent of sales activity this shopping season. In fact, it might be argued that with less spending each customer becomes more valuable. Anything you can do to give that customer a pleasant shopping experience will work to your advantage.

MegaPath is a major competitive telecommunications carrier and leader in managed IP services. They serve the retail sector with high speed network connections specifically designed to support secure payment transactions. They call their service a “Payment Processor Extranet.” As the name implies, this is a specialized form of connectivity unlike simple Internet broadband. MegaPath’s Payment Processor Extranet connects to your retail site-to-site MPLS VPN service to securely carry credit card and other payment information from your point of sale locations to credit, debit gift and private label card payment and check payment processors. You choose which processors you work with and can and or change them at any time. MegaPath provides a fully redundant proactively monitored communications network to the processors to ensure that your transactions will get through.

For gas stations, convenience stores and other retailers not connected in a MPLS network, MegaPath offers “StoreConnect,” an IPSec encrypted service that works over a wide variety of broadband connections including DSL, cable, wireless and T1 lines. Like the Payment Processor Extranet, this service gives smaller retailers access to the leading payment processors for fast, secure and reliable transactions.

One of the most important processes involved in payment transactions is PCI or Payment Card Industry security. This standard involves a firewalled secure network protected by encryption and strong access control. MegaPath’s retail solutions are designed from the ground up to be PCI compliant.

So, what’s it going to be this year? Will you depend on slow dial-up access from your POS terminals that will likely keep your customers waiting and irritated as they stand in line? Or will you make the transaction process as transparent to your customers as possible with fast and reliable broadband connectivity? If you choose to make your transactions fast, efficient, reliable and secure, there’s no time to waste. Get more information about MegaPath and other retail connectivity solutions and be ready to make the most from the Black Friday weekend and the entire holiday shopping season.

Click to check pricing and features or get support from a Telarus product specialist.




Follow Telexplainer on Twitter