Showing posts with label Virtual Private Networking. Show all posts
Showing posts with label Virtual Private Networking. Show all posts

Wednesday, October 19, 2011

Types of VPN Connections

Virtual private networking is heavily used in business. In fact, you probably have used a VPN connection today without even realizing it. It’s not a belt and suspenders service anymore. VPN connections are absolutely essential to prevent being robbed blind.

Virtual Private Networking provides security at a reasonable cost...First, let’s take a look at private vs virtually private networks. Your hardwired LAN is a private network. It would take some real effort and a lot of risk for someone to tap into your network wiring and install a device to capture traffic. The same is true if you establish a wide area network or WAN using point to point private lines. A PTP T1 line falls into that category. While it is not impossible to sneak into your wiring closet or even the telephone company and put a tap on the line, it is so difficult that only those with the most secure requirements will go to extremes to protect against this type of attack.

What distinguishes a private network is that 100% of the traffic is yours and yours alone. You are not sharing the lines with anyone else. The advantage to a private network is inherent security. The disadvantage is cost. You pay for all the construction, maintenance and monthly lease fees. It’s unlikely that your private network will be fully loaded at all times. Whatever capacity is unused goes to waste.

Contrast the private network with a public network like the Internet. They are polar opposites. The Internet allows anyone and everyone access by design. Traffic on the Internet is everybody in the pool. Your packets are intermingled with everyone else’s. Even so, a wired connection to the Internet isn’t the worst situation. That belongs to the unsecured wireless network. No need to plant malware in someone’s computer when everything they are doing is perfectly visible on any WiFi enabled computer within range. You are most vulnerable reading private unencrypted emails in a popular public hotspot. Anyone with a laptop computer and some easy to obtain spyware can be reading your messages right along with you.

It seems like such a crying shame that the one network that any employee can access at home or while traveling is such a security nightmare. That’s where the technique of encryption becomes valuable. It doesn’t matter if someone is monitoring your traffic if all they see is gibberish. You encrypt your message at one end and decrypt it at the other end and you have a created what is known as a secure tunnel through the Internet. The public network has now become a virtually private network. It’s not a private network because you are still sharing the transport with many others. It’s virtually private because no one can read your traffic and make any sense out of it.

There are two popular methods of creating Internet or IP VPNs. One is IPsec or Internet Protocol security. The other is SSL or Secure Socket Layers. IPsec is based on software installed in both the company server and the client computer. IPsec encrypts and decrypts each packet, so once you have it installed you have a virtually private line to the company no matter where you hooked to the Internet. Of course, you need to use the specific laptop or other computer set up to work with this system. You can’t just go to any computer and connect back to headquarters.

If you want to do that, you need SSL (Secure Socket Layer). The beauty of SSL is that the software is already built into Web browsers and some email programs. SSL has been popularized for ecommerce and online banking. When you go to a SSL enabled webpage, you’ll notice that the http:// has become https:// The “s” means secure page. To access it you need a user account ID and a password at a minimum. Some sites go further and ask personal challenge questions or display special graphics that give you confidence you are logged into the correct site.

For corporate wide area networks, an alternative to private lines is the MPLS network. These are multi-tenant networks that spread the cost of building and running the system among many users. MPLS networks are considered VPNs because they use a proprietary label switching protocol that isn’t compatible with IP tools. This unique protocol plus access controlled to a limited number of business clients and not the general public give MPLS networks an enhanced level of security.

Do you need private or virtually private network connects to conduct business? If so, compare VPN options and prices to help decide which mix of network techniques is right for your company.

Click to check pricing and features or get support from a Telarus product specialist.




Follow Telexplainer on Twitter

Thursday, February 21, 2008

Do You Need a Business Cloud?

In the era of switched circuit communications, you could rightly envision a pair of wires leaving your telephone and going through the central office down a long line of telephone poles and ending up in the phone of the party you were calling. Every circuit was point to point. Network resource sharing was limited to lines and channels that happened to be open and available for use.

Packet switched communications changed all that. Now the circuits are connected to all the locations all the time. It's the data packets that are switched and guided through the myriad of network links. The idea that all these links are interrelated somewhere out there gives rise to the concept of a communications "cloud." Wide area networks are often drawn that way. Everyone connects with a line going to the cloud. The magic within the cloud makes sure that your voice and data get where they are supposed to go and nowhere else.

The main benefit of using a cloud is the ease of many-to-many communications to replace the one-to-one relationship of the switched circuit system. One perfect business application is connecting multiple offices together. Ideally, anyone at any branch can communicate with anyone else at any other location. You can do that with dedicated point-to-point lines, but someone has to act as a traffic cop to make the connections as needed. For phone service, that's the telephone company. For data, it's probably headquarters IT.

One of the first cloud-based networks was Frame Relay. It is still popular today. The Frame Relay Network is a privately owned network that spans a region, the country or the world. Each business location connects to the network using a FRAD or Frame Relay Access Device. T1 lines are common data connections. Within the network, frames of data (packets) are routed according to PVC or Permanent Virtual Circuit instructions. A CIR or Committed Information Rate establishes how much bandwidth you have.

A more advanced private cloud network is called MPLS or Multi-Protocol Label Switching. Once again, a provider owns and operates the network. Each business location that wants to use the network connects via private line, such as a T1 connection. The interface attachment is called a tag router. Packets are tagged by this router to identify their destination and quality of service requirements. This makes MPLS networks suitable for transmitting real-time streams such as voice and video.

The Internet is the most ubiquitous and well known cloud network. The design of the Internet does away with the concept of circuits completely. Each packet has a source and destination address. The Internet's core routers can choose among available paths to pick the best one to carry the packet incrementally on its way. A major difference with using the Internet is that it is a public, not private resource. Thus, security can be an issue. This is handled using encryption software to create a "tunnel" that keeps your data private. Thus creating a Virtual Private Network using a public resource. Because there are so many routes installed worldwide with access from practically anywhere, the Internet cloud is attractive for business to business communications.

Do you need a business cloud to communicate with branch offices or with suppliers and customers? Or would a private line meet your needs better? Let our team of experts show you the range of alternatives available for your locations and explain which are the most cost effective.

Click to check pricing and features or get support from a Telarus product specialist.




Follow Telexplainer on Twitter