Showing posts with label encryption. Show all posts
Showing posts with label encryption. Show all posts

Monday, October 21, 2024

Dark and Lit Private Lines

By: John Shepler

The Internet is a marvelous network. It enables all of us to connect to any of us anywhere in the world and at a very reasonable cost. Why wouldn’t you use the Internet for all your communications? Much of the time we do, both for personal and business needs. It works great… well, it works just fine a lot of the time. There are a few snags, though.

See what private network options are available for your business.Network Priority
One is priority for highly sensitive applications like interactive voice and video. Say, telephone calls. There is no priority. Your voice packets get the same treatment as your next door neighbors video stream or someone backup up files to the cloud. Get in line and take your turn. When things get too busy, called network congestion, your real-time stream may break up or stop completely for a short time.

Cloud Critical Applications
The same is true for business critical applications running in the cloud. If you are taking orders, interacting with a customer or needing fast answers to deal with rapidly moving situations you may be drumming your fingers as you wait for the system to respond. Trying to make a quick financial trade in the market? Maybe it executes immediately. Maybe not. You may or may not get the price you had in mind.

Network Security
Another issue is security on the Internet. There is none. If you want security, you need to add it yourself. That means encryption. A popular way to encrypt your traffic when out of the office is by using a VPN or virtual private network. This is end to end encryption that makes it safer to use public access points like WiFi in coffee shops or send sensitive documents across the Internet. SSL or, now, TLS encryption has made possible online shopping and banking with confidence using web browers over the Internet with or without a VPN.

Improving Performance with Private Lines
You can get better network performance with private lines. Think private road versus crowded superhighway. The idea is to limit the competition from other people’s traffic.

You can still use the Internet but make it run better with a private line called DIA or dedicated Internet access. This gives you a private, not shared, connection between your location and your Internet service provider. Of course the Internet core itself is still a shared resource, but most of the congestion is in the last mile where you and hundreds or thousands of other users share the same connection to the service provider.

Direct to the Cloud
A direct cloud connection is a private line between you and your cloud service provider. Since you are the only user on that line, your cloud services should run much more like they would if the servers were right down the hall in your building. This type of connection avoids the Internet and its vagaries completely.

Why not expand that concept to your own private WAN or wide area network? This means private lines to connect your offices, factories, data centers and branch locations or retail outlets. Think of it like having your LAN expand to include all of your other business locations. You have control of the traffic and no interference from other outside users. Both privacy and performance are improved.

Dark and Lit Fiber
So far we are talking about fiber optic services, likely Ethernet over Fiber, which is the most popular connection method today. These are “lit” fiber connections where the laser equipment that maintains the signal is owned and operated by a service provider. The ultimate in performance and privacy over metropolitan and wider areas is using “dark” fiber. Dark means the fiber strands that you lease have no termination equipment at either end. You are responsible for providing the equipment that “lights” the fiber and sets the protocol. Since the glass fiber strands have nearly unlimited bandwidth, you have tremendous ability to send traffic from point to point dependent only on your budget and technical staff.

Wireless Private Lines
Finally, there is a new type of wireless service called 5G private networking or 5G network slice that lets you have the advantage of private lines while portable or mobile. It’s something like your own private corporate WiFi, but over much wider distances. Coupled with fiber optic private lines for most of your traffic, private wireless can give you a comprehensive business network wherever you are.

Is private networking right for your business? Find out what private network and security options are available now.

Click to check pricing and features or get support from a Telarus product specialist.



Follow Telexplainer on Twitter


Wednesday, September 11, 2019

You Need a Black Cloud Software Defined Perimeter

By: John Shepler

Secure your network with black cloud SoftwareAre you a trusting person? Too bad. That’s going to get you hacked. Respect and privacy are admirable things, but they are not guaranteed by today’s Internet. In addition to all the incredible employees, partners, suppliers and customers that you hold in high regard, there is a dark underbelly of professional criminals, hobbyist & mercenary hackers, mischief makers, psychotics, and nation states with agendas all trolling the same network. Some are looking for victims of opportunity. Others have you in mind as a target. Can your firewall and VPN fend them off?

The Virtual Hopefully Private Network Connection
The VPN or Virtual Private Network was designed to make the Internet act more like a private line or MPLS (Multi-Protocol Label Switching) network. Even if you have a T1, DS3, OC3 or Ethernet private line at the office, you have a big security hole when an employee out on a sales or repair call stops by the coffee shop and connects back using the free Wi-Fi provided by the store.

Free really means free and open. That guy in the corner staring at his laptop is watching your traffic. He either hacked the shop’s WiFi or created his own look-alike “free” WiFi network that you connected to instead of the real one. This is called “man in the middle” and it is what VPN was designed to protect against. The VPN creates an encrypted connection called a “tunnel” from your employee’s computer to your office server. That makes it pretty hard for someone to get in the middle of the conversation unless they have the private key… and they don’t.

VPN Weaknesses
Not all VPNs have a rugged 256 bit military-grade encryption. Some use protocols that are relatively easy to crack with available hacker tools. PPTP (Peer to Peer tunneling Protocol) is over 20 years old and is desirable because it is fast and easy to setup and use. It’s also more vulnerable than protocols with stronger encryption.

Not all VPN vendors are equally capable. Weak ones may have back doors in their servers or other weaknesses that make it easy to hack the VPN server in the cloud and get everybody’s data. You won’t know until you are hacked and can’t figure out how.

An overall weakness of VPN is that it just protects the tunnel into your company. If that is compromised one way or the other, your entire network and everything on it is wide open to explore and perhaps attack. it would be better if only a small part of the company assets were exposed instead of everything all at once.

The Software Defined Perimeter Black Cloud
The idea behind a Software Defined Perimeter (SDP) is that trust is minimized by allowing access to resources user by user on a need to know basis. The research was done by the U.S. Department Information Systems Agency (DISA) and has come to be known as a “Black Cloud.” The black designation means that the network infrastructure is hidden within the cloud. There are no visible DNS or IP addresses.

SDP authenticates each user and only gives them access to the resources you have approved for that particular user so they can do their jobs. The user or IoT device has no idea what else is on the network. They can’t see it. If they can’t see it, they can’t get access. Someone impersonating that user can’t either.

A system of SDP Hosts and Controllers communicate and verify the authorizations. The Controller has the job of connecting the Initiating and Accepting Host data channels through a Gateway, once authentication and authorization has been completed through the control channels.

The SDP is not only between clients and the data center. It is also deployed within the data center to partition the network to isolate high-value applications. Only a limited number of users with have access to the highly protected application or even know it exists.

Encryption and cloaking are key to SDP security. The usual network probing, such as port scanning, won’t work because nothing will show up in the scan. In a way, SDP is creating virtual networks on a user by user, session by session, basis. What goes on behind the curtain is a complete mystery.

The End of Networks As We Know Them?
The TCP/IP network that has served us so well for decades has to go underground to keep its relevance in today’s high threat environment. We can no longer do business without the Internet and there are just too many bad actors on the public Internet. Technology must evolve to provide the illusion of a simple open Internet but with none of the familiar network topology visible.

Has your company network been hacked or are you concerned about the business disruption this might cause? Right now would be a good time to see what advances have been made in network security, especially managed security solutions in the cloud.

Click to check pricing and features or get support from a Telarus product specialist.



Follow Telexplainer on Twitter

Monday, April 16, 2018

Private Lines and Virtual Private Networks

By: John Shepler

Businesses often have need for a private line to communicate between headquarters and branch offices, factories & warehouses, retail franchises or suppliers. What’s important is reliable connections with security and transparency. The ideal private line gives you the same experience as your local area network.

Find private line and virtual private network solutionsClassic Point to Point Private Lines
Telephone companies have offered private lines since the analog days. Security systems and radio station studio to transmitter links are examples of private lines that were often little more than pairs of wires that ran directly from one location to another via the central office.

Digital communication introduced the T1 point to point private line that serves the same purpose. Bits go in one end and come out the other. T1 lines at 1.5 Mbps, DS3 at 45 Mbps and OC3 at 155 Mbps all offer private line service. Latency and packet loss are low. Speeds are fixed at the capacity of the line.

These private lines work well for connecting a central headquarters as a hub to branch offices as spokes. It takes one line per branch with the central switch or router directing traffic. The lines themselves serve as very, very long network wires to interconnect the LANs at the various locations.

Ethernet Private Lines
Since Ethernet is the protocol used on virtually all local networks today, it makes sense to have the private line running the same protocol. The telco solutions already mentioned require a protocol conversion module to convert between Ethernet and the proprietary protocol that runs on the lines themselves.

Carrier Ethernet private lines run the Ethernet protocol on the line itself. Carrier Ethernet is available as Ethernet over Copper for lower speed connections and Ethernet over Fiber for 10 Mbps to 10 Gbps, with 100 Gbps becoming more available.

Ethernet services have more carriers competing for business which tends to reduce prices per Mbps. The cost per Mbps is almost always less for Ethernet and scalability is much easier. You can have a Gigabit Ethernet port installed and order any bandwidth from 10 Mbps up to 1000 Mbps. When you want an increase or decrease in capacity, a simple phone call to the carrier will make that happen quickly with no equipment changes required.

MPLS Networks
Private lines are a great solution if you only need to interconnect a few locations in a small geographical area. As the number of locations and their distance from headquarters increases, the cost goes up quickly. Each line has a charge and it varies with distance.

A popular alternative is the MPLS or Multi-Protocol Label Switching network. This is a privately run network that uses a proprietary protocol called label switching instead of the more common TCP/IP. The fact that access is limited to subscribers only and the uniqueness of the LS protocol provide a level of security even though you are sharing the network with other users.

MPLS operators work to ensure that you have no awareness of other traffic. Bandwidth, latency, jitter and packet loss are carefully managed to meet the needs of all subscribers with extra margin for bandwidth bursting when needed.

MPLS is also known a MPLS VPN or Virtual Private Network. That’s because it isn’t truly private and fully dedicated to your use like a private line. If you are feel that you need a additional level of security, you do have the option to encrypt your data before it enters the MPLS network.

Why choose MPLS? It’s a big money saver over long distances where private lines get expensive. All you need is a short private line connection to the network at each location and instructions to the operator as to how to route your traffic.

Internet VPN Solutions
The Internet is the least cost wide area networking solution with highest geographic connectivity. Performance can vary widely. It’s also the least secure network you can find. Anyone and everyone can easily get a connection, and they do.

How can you make the Internet act like a private line? You provide your own encryption from point to point. Two popular approaches are IPsec based on software installed on each computer and SSL or Secure Socket Layer that is already built into web browsers.

Choosing a Private Line Solution
Which approach is best? It depends highly on how many locations you have, where they are, what traffic you intend to send, and what level of performance you require.
There are cost/benefit tradeoffs to each of the above solutions. What’s right for you? An expert consultant will be happy to review your private line or VPN network needs and provide one or more solutions that can do what your business needs done.

Click to check pricing and features or get support from a Telarus product specialist.



Follow Telexplainer on Twitter

Tuesday, March 24, 2015

Point to Point Fiber Optic Connections

By: John Shepler

Say you want to link two business locations securely and with medium to high bandwidth. Do you use the Internet for this or…

A point to point fiber optic laser light beam data burst. Find this design on many products now.The Advantage of Private Lines
The Internet has two big advantages: It goes almost everywhere on Earth and access is relatively cheap. Unfortunately, the Public Internet also has a couple of big limitations: Performance is iffy and security is genuine worry.

What’s better? Private lines. Particularly, dedicated point to point private lines. They’re called private because they really are.

Security is ratcheted up orders of magnitude because it’s really hard to hack into something where you have no access. Remember the old spy shows where someone surreptitiously taps into a phone line by connecting directly to the wires? That’s what it takes to get into a private line. You need access to the physical connections themselves. There’s none of this packet snooping on an Internet connection or, worse, over WiFi.

Want to make it even harder to get into your network? Go with fiber optics instead of wires. Even harder? Encrypt your data too. That’ll stop the little snoops in their tracks. Now they’ve got to get physically into your connection somewhere along the line and then break your encryption before they get caught. Good luck with that.

Security is Great. How About Performance?
You really can’t improve over private line performance unless you actually own the network from end to end. That’s actually a possibility. Of course, your LAN is limited to your building or campus. You’ll likely not be able to afford to string wires or trench fiber across town to link separate locations. But you may very well be able to lease dark fiber. If you install your own termination equipment, you pretty much have control over the entire link.

Most of us don’t need to go to that extent. We can lease point to point private line connections at just about any bandwidth we need. As long as you acquire enough bandwidth, network congestion should never be a problem. Packet loss, jitter and latency are minimized with dedicated private lines. There’s no traffic on the link other than yours.

You won’t get that performance consistently on the Internet. The Internet was designed to be robust in the face of line cuts and equipment failure. That’s a great goal, except you may find that your packets take varying routes even between two fixed end points. The packets will almost always get there with TCP/IP… eventually. That’s why real-time applications like VoIP telephone and video conferencing perform much better over private lines.

What Private Line Services are Available?
The two big contenders are SONET and Carrier Ethernet over Fiber. Yes, you can still get T1 lines and they work great. Bandwidth is a limitation, however, T1 is 1.5 Mbps. Bonding T1 lines will get you up to 10 or 12 Mbps, but that’s it. Even at 10 Mbps, fiber is a better deal if available. Fiber bandwidth start at around 10 Mbps and go up to at least 10 Gbps in most areas. For multiple locations or international connections, MPLS networks are an excellent choice.

About SONET Fiber Optic Bandwidth
SONET is the original switched circuit technology used for fiber optic transmissions. It’s implemented on a pair of fibers with a ring topology. That’s for reliability. If one fiber gets cut, the other picks up the load within 50 mSec and keeps going.

SONET is at the core of many networks, especially the legacy telco networks. The most basic service available is OC-3 at 155 Mbps. Other popular levels are OC-12 at 622 Mbps and OC-48 at 2.4 Gbps. Even T-Carrier DS3 service at 45 Mbps that is delivered on coaxial cables travels most of the way multiplexed over OC-3 fiber service.

SONET is a very mature and reliable technology. It’s the way most companies moved into fiber optic bandwidth when copper wireline just couldn’t cut it anymore. Prices have dropped dramatically over the last few years. Even so, there is a more flexible and cost effective solution available today. That is Carrier Ethernet.

Ethernet over Fiber Bandwidth Advantages
If you are wondering why Ethernet over Fiber is taking over the world, you need look no further than you own LAN. Ethernet is the dominant, pretty much universal, protocol used for computer networks. Electronic communications once was analog phone calls. Now the lion’s share of the traffic is digital data and the majority of that is IP video.

Carrier Ethernet, also called Ethernet over Fiber or EoF, is an extension of the LAN standards to make them work over long distances on common carriers. Ethernet has the advantage of directly interfacing to LANs with no protocol conversions required. Unlike SONET, it was designed to be highly scalable. You can get just about any bandwidth you want and upgrade or downgrade it quickly and easily.

Ethernet is also generally less expensive, Mbps per Mbps, than SONET or even the lower speed wireline services. Nearly all businesses can afford 10 Mbps EoF. Most go for 100 Mbps Fast Ethernet. Both GigE and 10 GigE are popular with more demanding applications and larger companies.

How do MPLS Networks Provide Private Lines?
MPLS or Multi-Protocol Label Switching networks are Wide Area Networks that are based on a propriety routing technology called label switching. It’s unique to these networks and hard to hack. That’s why MPLS is also known as MPLS VPN or virtually private networking.

Yes, MPLS is a multi-tenant network and not strictly a private line. However, MPLS networks serve a limited number of paying customers and are carefully managed to ensure that each customer has the resources committed to it at all times. You often even have the advantage or “burst” or use more resources than you have committed to as long as excess capacity is available.

Why MPLS? As large private networks, MPLS offers the opportunity to connect many locations at a lower cost than using multiple private lines. The cost advantage is such that it’s often better to use MPLS rather than dedicated private lines for even two internationally separated locations.

Your Best Bandwidth Option
Which bandwidth solution is right for your business? Before you choose, compare performance commitments and prices for SONET, Ethernet over Fiber and MPLS private line solutions

Click to check pricing and features or get support from a Telarus product specialist.

Note: Products with the point to point fiber laser data light burst design shown on this page, along with many other computer and networking themes, are available through the Gigapacket Tech Gifts Store.



Follow Telexplainer on Twitter

Monday, October 08, 2012

MPLS Network Design Supports Global Business

Many companies now have a business presence outside of the United States. This creates a need to connect these facilities back to headquarters and to other regional headquarters or satellite offices. What’s proving to be the best solution for enterprise-grade connectivity is international MPLS networks. Let’s take a look at why.

Check International MPLS Network prices for secure and reliable global business connectivity.The low end approach to worldwide communications is the Internet. It already goes everywhere and connects just about everyone. All you need are a broadband connection at each location and you are good to go... or are you?

The problem with the Public Internet is that it serves anyone and everyone with the price of admission, which can even be a free WiFi hotspot. This includes lots of casual users updating their Facebook pages and downloading movies, businesses selling to the general public, and a significant number of bad actors. Malicious attacks on corporate data centers and personal computers continue to grow because it is a lucrative endeavor. This means you don’t dare transmit sensitive data or allow access to your corporate servers without some type of encryption to create a VPN or Virtual Private Network tunneling through the insecure Public Internet.

The other issue is performance. Everybody’s packets are treated exactly alike on the Internet. There’s no such thing as Class of Service (CoS) to put time sensitive packets such as VoIP telephony or video conferencing in a “fast lane.” If you want preferential treatment, you need to move to a private network.

Private point-to-point line services have been the traditional mainstay of private digital business communications. If you only need to connect two locations, then it seems logical to order a dedicated line between those locations. If you need to add more locations, then you are in the Wide Area Network (WAN) business. Typically you create a star network with corporate headquarters at the center and links to each remote location. You then decide the routing to determine how locations communicate to each other.

The private network is highly secure and performs very well because you have total control of all resources. Unfortunately, you have to run the network yourself, solve any connectivity issues that arise, and pay for all those expensive lines.

A more practical approach is to use a privately operated MPLS network to connect from 2 to any number of locations. These can all be within U.S. borders or they can be located in just about any country overseas. All you need is a last-mile connection from each location to the MPLS network. The network operator will manage bandwidth, latency, packet integrity and class of service. That’s right, MPLS networks are designed to support multiple classes of service to support even the most sensitive data streams.

MPLS stands for Multi-Protocol Label Switching. This isn’t an IP network, although it can transport IP data. It can also transport just about any other protocol needed. The core of the network is based on label switching routers using a proprietary protocol. That makes it inherently more secure than the Internet or other IP based networks. MPLS service is often touted as a VPN or Virtual Private Network, even though encryption is not required.

What’s available today that may not have been previously is a number of MPLS networks with worldwide reach. They have POPs (Points of Presence) in dozens or more countries and contract with local service providers for the last mile connection. This can be anything from DSL to T1/E1 to SONET fiber or Ethernet. Each location can have the connection that supports its needs. All connect to the core of the MPLS network, which is high speed fiber with massive bandwidth. You have a sense that you are the only one of the network, even though there are many simultaneous users transmitting important data. The fact that the core infrastructure is shared greatly reduces costs compared with an all private line solution.

Do you have a need to connect multiple business locations in a small geographical area, nationwide, or across international borders? If so, get quick pricing quotes for International MPLS Networks and compare cost and quality with your other connectivity options.

Click to check pricing and features or get support from a Telarus product specialist.



Follow Telexplainer on Twitter

Friday, September 21, 2012

Secure Any Public WiFi Hotspot

You know how it is. You’re away from the office and the enterprise grade security on your corporate LAN. Or you’re out and about with your personal computer and away from the security of your encrypted WiFi router. You don’t have a 3G or 4G service for your laptop, but that doesn’t matter. There is WiFi available just about everywhere. The only problem is how much do you have to worry about these unsecured WiFi hotspots.

Get 3 days of free Private WiFiWorry a lot. Certainly, there isn’t some malicious hacker lurking in the dark corner of every coffee shop and restaurant. But how can you be sure that there isn’t somebody running Firesheep or another spyware program just when you want to send some private email or sensitive corporate data?

You can never be sure. The problem is that cybercrime has turned into big business and the tools needed to lurk on your conversations wirelessly are easy to obtain. You may never get hacked or you might lose sensitive data this afternoon. Isn’t it better to be safe than sorry?

The threat of someone lurking nearby with a packet sniffer on their otherwise innocent looking laptop has made many of us a bit paranoid. You may not care who’s watching you read the news or check the weather, but do you really want to open your email or log-into personal services in that environment? You can either pay up for 3G and 4G cellular services, which are harder to crack but not impossible, just forget doing much online when you are out and about, or set up Private WiFi for your computers.

What is Private WiFi? It’s a service that creates a Virtual Private Network (VPN) for anything you send over the Internet. If you work from home, your company may have set you up with a corporate VPN so that you can securely access company data. Usually, this involves installing special VPN encryption software on your PC that only works with similar software in the corporate data center.

What’s different about Private WiFi is that it isn’t limited to any particular business or any business at all. This is a VPN that secures your Internet connection, even over public WiFi networks. The way a VPN works is that it encrypts or scrambles the data you transmit and receive while it is on the wireless link. That way it is nearly impossible to decode, and way beyond the capability of the identity thieves sipping a late in the next booth. This is why they call it a virtual private network. It virtually creates a private connection for you across a public network.

The way Private WiFi works is that you install the VPN software on your computer and it creates an encrypted tunnel for your data anytime you use the Internet. That encrypted connection is between your computer and the secure Private WiFi servers. Those servers connect to the Internet using high speed connections. Private WiFi uses industry standard 128-bit encryption, the same technology used by your bank or credit card company. Everything you do on any WiFi or other Internet connection uses this VPN to protect your data.

Private WiFi works with both PCs and Macs and costs about ten buck a month. That’s a lot cheaper than other wireless access if you already have WiFi readily available to you. There are also family plans and corporate discounts available. If you aren’t sure this is for you, why not take a free 3-day trial and see how it works? Go ahead and start your Private WiFi Free 3-day trial now and stop worrying about who’s lurking at your favorite WiFi hotspots.

Click to get more information and view sample videos.




Follow Telexplainer on Twitter

Monday, October 24, 2011

IP WAN over MPLS Advantages

When we think of IP wide area networks, the first thing that comes to mind is the Internet. While the Internet does have almost universal connectivity and modest cost to access, there are some serious issues when it comes to business applications. Bandwidth, latency, jitter and packet loss have no guarantees and few expectations. Security is a joke. But aren’t other methods to interconnect business locations costly and hard to manage?

It is possible to set up a private IP network that lets you use your familiar IP addressing schemes and avoid encryption, firewalls, tunnels, and additional hardware. You’ll gain a performance advantage compared to using VPN techniques over the Internet and save yourself the administrative headaches of trying to manage a WAN with inherently indeterminate characteristics. Who offers something like this? It’s TelePacific, one of the nation’s largest competitive carriers.

TelePacific’s 1Net is an IP VPN running on a private MPLS network, not the Internet. Since MPLS or Multi-Protocol Label Switching can transport almost any protocol, it can be set up to mimic the Internet while keeping your data private. Only the locations that you set up can exchange traffic. No one outside of your user group can capture or view your data. You’ll have any to any connectivity within the group with security sufficient to address HIPPA or similar government regulations.

In fact, TelePacific set up just such a private IP Network for a medical imaging organization with 6 locations. They use it to transport patients’ private medical records among their location. Referring physicians can access patient imaging results within hours at their own computers. The system is also used for claims processing, patient scheduling and registration. Interestingly, this system also allows dedicated Internet access through a single firewall at corporate headquarters.

The TelePacific 1Net IP VPN has both cost and performance advantages over other secure networking solutions, including private line, ATM and Frame Relay. You can specify up to six different Classes of Service (CoS) to support sensitive real-time services such as VoIP telephone and teleconferencing. On Net, latency for all CoS is specified at 50 msec. That rises to just 100 msec for extended reach locations off the TelePacific network but still within the US. Network availability is 99.999% (5 nines) both on and off network locations.

The Classes of Service are CoS 1 for VoIP real time traffic, CoS2 for video conferencing and real time data traffic, CoS3 for high priority, delay sensitive business data like Ecommerce and Citrix, CoS4 for medium priority delay-sensisitive business data such as CRM and WebEx, CoS5 for general less delay sensitive business data like ERP, and CoS6 for best effort traffic with no prioritization. That’s typically Email and FTP.

Are you cringing at the cost and effort involved in linking your business locations by private lines or frustrated by the highly variable performance and difficulty in securing the Internet? Perhaps the best solution for your business needs is a private IP VPN based on MPLS networking. Check prices and features to compare with your other choices.

Click to check pricing and features or get support from a Telarus product specialist.


Note: MPLS network diagram courtesy of Wikimedia Commons.



Follow Telexplainer on Twitter

Wednesday, October 19, 2011

Types of VPN Connections

Virtual private networking is heavily used in business. In fact, you probably have used a VPN connection today without even realizing it. It’s not a belt and suspenders service anymore. VPN connections are absolutely essential to prevent being robbed blind.

Virtual Private Networking provides security at a reasonable cost...First, let’s take a look at private vs virtually private networks. Your hardwired LAN is a private network. It would take some real effort and a lot of risk for someone to tap into your network wiring and install a device to capture traffic. The same is true if you establish a wide area network or WAN using point to point private lines. A PTP T1 line falls into that category. While it is not impossible to sneak into your wiring closet or even the telephone company and put a tap on the line, it is so difficult that only those with the most secure requirements will go to extremes to protect against this type of attack.

What distinguishes a private network is that 100% of the traffic is yours and yours alone. You are not sharing the lines with anyone else. The advantage to a private network is inherent security. The disadvantage is cost. You pay for all the construction, maintenance and monthly lease fees. It’s unlikely that your private network will be fully loaded at all times. Whatever capacity is unused goes to waste.

Contrast the private network with a public network like the Internet. They are polar opposites. The Internet allows anyone and everyone access by design. Traffic on the Internet is everybody in the pool. Your packets are intermingled with everyone else’s. Even so, a wired connection to the Internet isn’t the worst situation. That belongs to the unsecured wireless network. No need to plant malware in someone’s computer when everything they are doing is perfectly visible on any WiFi enabled computer within range. You are most vulnerable reading private unencrypted emails in a popular public hotspot. Anyone with a laptop computer and some easy to obtain spyware can be reading your messages right along with you.

It seems like such a crying shame that the one network that any employee can access at home or while traveling is such a security nightmare. That’s where the technique of encryption becomes valuable. It doesn’t matter if someone is monitoring your traffic if all they see is gibberish. You encrypt your message at one end and decrypt it at the other end and you have a created what is known as a secure tunnel through the Internet. The public network has now become a virtually private network. It’s not a private network because you are still sharing the transport with many others. It’s virtually private because no one can read your traffic and make any sense out of it.

There are two popular methods of creating Internet or IP VPNs. One is IPsec or Internet Protocol security. The other is SSL or Secure Socket Layers. IPsec is based on software installed in both the company server and the client computer. IPsec encrypts and decrypts each packet, so once you have it installed you have a virtually private line to the company no matter where you hooked to the Internet. Of course, you need to use the specific laptop or other computer set up to work with this system. You can’t just go to any computer and connect back to headquarters.

If you want to do that, you need SSL (Secure Socket Layer). The beauty of SSL is that the software is already built into Web browsers and some email programs. SSL has been popularized for ecommerce and online banking. When you go to a SSL enabled webpage, you’ll notice that the http:// has become https:// The “s” means secure page. To access it you need a user account ID and a password at a minimum. Some sites go further and ask personal challenge questions or display special graphics that give you confidence you are logged into the correct site.

For corporate wide area networks, an alternative to private lines is the MPLS network. These are multi-tenant networks that spread the cost of building and running the system among many users. MPLS networks are considered VPNs because they use a proprietary label switching protocol that isn’t compatible with IP tools. This unique protocol plus access controlled to a limited number of business clients and not the general public give MPLS networks an enhanced level of security.

Do you need private or virtually private network connects to conduct business? If so, compare VPN options and prices to help decide which mix of network techniques is right for your company.

Click to check pricing and features or get support from a Telarus product specialist.




Follow Telexplainer on Twitter

Monday, July 11, 2011

Advantages of SSL VPN

Computer security is in the back, if not the front, of every Internet user’s mind right now. Hacking, security breaches, identity theft and malicious bots are terms that show up in national news reports as well as user forums. Everything moving to the cloud is adding to the anxiety of anyone who has sensitive data and wants to keep it personal and private. Little wonder the interest in virtual private networks is greater than ever before.

Consider SSL VPN as an easy way to establish secure connections with your customers...What is a virtual private network and why would you want that instead of an actual private network?

The answer revolves around our desire for universal connectivity. Most companies started connecting to other locations using private line services, such as T1, DS3 and OC3. These are point to point connections that are reserved for your private use. Only you and the network operators have access to those wires and the data they are transporting. It’s fairly difficult for third parties to tap a private line and examine the packets moving back and forth.

Private lines are defined as private, but that’s not really good enough for high risk companies such as banks and brokerages. To thwart even the most dedicated line “tapper,” they encrypted their data to ensure it stayed private. Encryption is a process that takes plain text and jumbles it in such a way that it appears to be indecipherable nonsense to anyone looking. At the far end of the link, the text is decrypted and returns to its original form.

Private lines are great for communicating within organizations or with a select few suppliers, vendors, consultants and so on. But what if you want to interact with the public at large? For that you need a public, not a private, network. That’s exactly what the Internet was created to do.

The advantage of the Internet is that it connects to nearly every place and every person on Earth. That’s also its weakness. The same universal connectivity that makes it easy for billions of potential customers to reach your website makes it equally easy to do mischief or outright crime. If there was only a way to make the connection between you and your customer secure while still using the public Internet.

That solution is called the VPN or Virtual Private Network. A public network connection can be made virtually private by encrypting the packets that travel between two locations. Your particular stream of traffic is scrambled while the rest of the traffic flowing through the same network connections could be transmitted in the clear.

SSL or Secure Socket Layer is a popular technique to provide the encryption between source and destination. What makes it so popular is that SSL is supported by all modern Web browsers and many other programs, such as Email clients. There is no need to buy or configure separate encryption software used in other VPN approaches.

Anyone with an Internet connection and browser can connect securely to any site that supports SSL. The resulting connection can be called a SSL VPN. It only persists for the length of the session, but can be established at any time. You know that you are on a secure link because the address starts with https: rather than http: The “s” means secure.

Adding SSL to a site involves buying a digital certificate from a trusted certificate authority. That certificate attests to the fact that the site in question is who it says it is and not some impostor. The secure site presents the certificate to the client to prove legitimacy. It may also ask the user for authentication, such as user ID and password, to prove that the user is also legitimate.

What sites use SSL? Most any site handling financial transactions, such as banks, online stores that accept credit cards, webmail providers, cloud storage providers, remote access services, most sites that store personal data and require user logins, and businesses using the Internet to connect remote locations and home workers.

Do you need to provide secure connections for your business? If so, look into the costs and features of Affordable Virtual Private Network solutions. One or more may be just right for your particular needs.

Click to check pricing and features or get support from a Telarus product specialist.




Follow Telexplainer on Twitter

Monday, December 06, 2010

Why Choose An MPLS VPN?

How do companies communicate among geographically diverse business sites securely? They use private networks or virtually private networks. MPLS networks are emerging as the virtually private networks of choice. Let’s see why.

The ultimate in performance and security is the totally private network. Private means for your use only. You don’t buy a private network, you build one. Many companies have done this by setting up a star network with a central router at their headquarters location. Each remote location connects to headquarters over a private point to point line, such as a T1, DS3, OC3 or Ethernet private line. It is up to the IT staff to manage this network and make sure all locations have the bandwidth and ability to reach other locations that they need.

What’s wrong with this? Not a thing if you have infinitely deep pockets. The cost of all those private line services mounts up as more locations are added. Don’t forget the staffing cost to keep everything running. You’ll need to buy lines that have enough bandwidth to meet peak loads, meaning that most of the time they’ll be running at a fraction of the maximum capacity. You’ll be paying for that maximum capacity as if you were using in continuously.

The staggering cost of proprietary private networks has encouraged many companies to look for lower cost alternatives that still get the job done. One alluring option is to piggyback on the public Internet, arguably the largest and lowest cost network solution in the world. You could just connect all your sites over the Internet, but that makes management squeamish for good reason. The unregulated Internet is something like the Old West, with stagecoach robbers lurking behind every rock. In this case it’s cyber criminals and curious hackers drooling at the thought of rifling through your corporate files.

Does this mean that using the Internet for wide ranging connectivity is an unacceptable option? No, not at all. The trick to using an unprotected public resource like the Internet is to install your own security. You do this by encrypting your packets so that they are unreadable to anyone who is not authorized. It’s SSL encryption that makes it possible to buy and sell on the Web with confidence. The general term for using encryption to protect data on a public network is tunneling.

So, is tunneling through the Internet to get from site to site the best cost solution? Yes, if cost and/or the ability to connect with the public at large is your highest priority. But what about performance? Ah, I’m afraid the Internet does leave something to be desired in that regard. Bandwidth, latency, jitter, and bit errors are completely uncontrolled. You may not care if all you are doing is serving up Web pages to people on DSL or Cable connections. But trying to optimize productivity when you are running your critical corporate data to corporate offices, factories and warehouses around the world can turn into an exercise in frustration. Oh, you want to establish high quality two-way video and telephone connections on the same network? Good luck with that.

This is where MPLS VPN networks rush in to save the day. An MPLS network is not for the general public. You have to pay more than Internet prices to use it and it only serves its clients. What you get for the extra cost is a privately run high performance network that is carefully engineered to support voice, video and data. There’s no encryption as we think of it on the Internet, but an MPLS network is considered to be a VPN. Why is that?

The answer is in the technology. MPLS stands for Multi-Protocol Label Switching. IP routers are not used to direct packets from place to place. Instead, each packet gets a special label as a wrapper. That label is used to route the packet instead of the IP header information. Labels are added as packets enter the network and removed as they leave. In a sense, the packets are protected by their labels in that they only travel paths set up in advance by the network operator and are unreadable by other clients or external snoops.

Most of the time, MPLS technology and network operators provide enough security that encryption isn’t needed. Even so, if you are particularly sensitive about the privacy of your data you can always encrypt your packets before they enter the network and decrypt them on the other end.

The reason that MPLS VPN networks are replacing proprietary point to point networks is that they offer a significant cost reduction. While you have all the bandwidth you need, any unused resources are available to support other clients of the network. The cost of the entire network is spread over the total user base, which makes the pricing attractive for you.

Are you in need of a multi-location business network or simply want to check pricing to see if you are spending too much now? If so, check MPLS VPN network availability and pricing now. For comparison, you can also get pricing on private point to point lines and IP VPN networks using the Internet.

Click to check pricing and features or get support from a Telarus product specialist.




Follow Telexplainer on Twitter

Wednesday, June 16, 2010

IP VPN vs MPLS VPN

Security is an issue anytime you send data into a cloud network. One way to ensure that your data cannot be observed or tampered with is to build your own WAN network from point to point private lines. Another approach is to use a virtual private network that runs on resources that you don’t have exclusive use of. That’s what is meant by a VPN.

Check out IP VPN and MPLS options quickly and easily. The beauty of using dedicated private line connections is that you are in control of both access and resource utilization. You need to manage bandwidth demand and packet priority. What you don’t have to worry about is someone else crowding you for resources. There is no one else. If you are really concerned about malicious parties tapping into your line surreptitiously, you can chose to encrypt the data while it traverses the WAN connection. That’s the ultimate in network security. It’s also the highest cost approach.

What’s attractive about VPN solutions is that they are much less expensive to lease and require fewer resources on your part. Both the cost and resource savings come from sharing the facilities with other parties. The Internet is a prime example of how massive utilization can drive down costs. If you want to really minimize costs, a shared access connection, such as DSL or Cable broadband, is the cheapest approach by far.

The same things that make the Internet cheap also make it insecure. Anybody and everybody worldwide can connect to the Internet for what you are paying or less. Perhaps they’re using a public library or WiFi hotspot network without paying a cent. Many of these networks make no effort to even verify user identity. It’s the perfect breeding ground for mischief makers and criminal activities.

Fortunately, there is a way to secure your data as it traverses the Internet. The trick is encryption. You encrypt your data packets using a key that only you know. Anyone else who has access to your data stream sees only gibberish. A popular standard for doing this is called IPsec for IP security. It requires hardware and/or software that you manage at each location for the encryption/decryption process.

IPsec lets you create a virtually private network out of the Internet, a completely public network. This is generally what is meant by the term IP VPN. One big advantage of this IP VPN approach is that laptop computers can be configured with this system to give corporate access to remote or home workers. All that’s needed is the VPN enabled computer and a broadband Internet connection.

While the Internet is cheap, it offers no guaranteed performance. You take your chances on network congestion, packet corruption, latency and jitter. File transfers generally work fine, but voice and video can degrade without warning. Many businesses want a more reliable network to connect their branch offices, warehouses, retail locations, and so on.

MPLS networks come to the rescue as an improved form of virtual private network. The MPLS network doesn’t have public access, but it is a shared resource. Your costs are reduced compared to dedicated private lines because the cost of regional, national or international connections are amortized across the total user base. What makes MPLS networks a VPN solution is that your data connections are essentially tunneled through the cloud wrapped in proprietary routing labels. You define your connections and the network operator instructs the MPLS network on how to route your packets.

MPLS networks are often referred to as MPLS VPN because they are inherently virtually private. Connections to the network tend to be through dedicated private lines, such as T1 or Ethernet. If you want an even higher level of privacy, you can choose to encrypt your data while it traverses the MPLS network. In addition to improved security compared to the Internet, MPLS networks offer performance guarantees for bandwidth, jitter, latency and packet loss. That makes MPLS VPN a popular choice for mission-critical business applications.

Do you have a need to connect multiple business locations? Which type of VPN makes the most sense for your needs? Is it IP VPN or MPLS VPN? One easy way to sort out the options is to get complimentary network consultation and price quotes through our Affordable VPN site. You may well be spending far more than you need to for the performance and security you desire.

Click to check pricing and features or get support from a Telarus product specialist.




Follow Telexplainer on Twitter

Thursday, May 06, 2010

Two Routes to Virtual Private Networking

Virtual Private Networks or VPNs have become the preferred solution for connecting multiple business locations. What’s caused this migration from private ad-hoc point to point connections is cost and ease of maintenance. By partnering with a managed service provider, you can have the benefits of secure multipoint communication without having to staff up or pay exorbitant monthly line lease fees.

Affordable VPN solutionsVirtual private networking is in the clouds. The question is which type of cloud to choose? You can implement your VPN solution using the public Internet. You can also choose to go totally private for higher performance.

The Internet based VPN is where the term virtually private got started. Everybody knows that there is little private about the Internet. It connects everyone, everywhere with nothing in the way of assured performance or data security. What the Internet has going for it is economy of scale. The monstrous size and diverse connection methods mean that broadband connections are fairly cheap at the consumer level and reasonably priced for dedicated business access with a service level agreement.

What about those security issues? It seems like any data you put on the network is subject to interception by those who could do you harm. It’s not even safe to connect a PC to the Internet without installing virus blocking software first. Some tests have shown that it takes only a matter of minutes to browse the Web with an unprotected computer to have it become infected by compromised sites or malicious messages.

Yet, we use the Internet every day for such sensitive applications as banking and shopping. The key to keeping your data secure is encryption. Establishing encrypted links through the Internet is called “tunneling.” You create a private tunnel through a public thoroughfare. Your network connection isn’t private, but it is virtually private.

Another form of virtual private networking is provided by privately run network clouds, such as Frame Relay or MPLS. These networks strictly limit access to paying customers. They are also managed to establish only those connections that you specify. Because you are sharing the network cloud with other users, your connections are described as virtually private rather than private line. They offer a high level of security, but may also be encrypted to provide an even higher level of guaranteed privacy.

Private networks offer assured performance, especially in the critical areas of latency and jitter that are important for VoIP telephone and real-time video. The Internet is offered with “best effort” performance, but generally lower costs. How do you choose the right solution for your application? Perhaps the best answer is the obvious one. Get price and performance quotes on competing solutions and recommendations from experts before choosing. That’s all made easy with a quick Virtual Private Networking inquiry at AffordableVPN.com. You’ll get a fast reply and the support you need to make the right VPN decision.

Click to check pricing and features or get support from a Telarus product specialist.




Follow Telexplainer on Twitter

Tuesday, January 19, 2010

Virtual Private Network Definition

You know what a network is, but what is a virtual private network? Is it a real network or something that only exists virtually? Just how private is a virtual private network?

Virtually Private Networks encrypt your data.A virtual private network or VPN is a real network. It’s the privacy that is considered virtual. For instance, the Internet is a public network. There is nothing private about it, or intended to be. But there are techniques to add privacy to Internet communications. Those techniques make it virtually private.

Let’s look at what makes a good private network in the first place. One thing you need is complete control over access. Only those people and devices that you explicitly allow on the network should have any access to it. The wired network in your company is private because you’ve strung the wires and know where everything is connected. But if you rent space in a larger office building and use that building’s network, you can’t be sure that your data is completely secure. Someone might be tapped in and listening somewhere in the facility.

Another example of networks that people think are secure but really aren’t are wireless access points or wireless routers. If you use the wireless device as it comes out of the box without enabling security features, you run the risk of eavesdroppers being able to tap into your data.

Control of access through control of the physical network and access lists for wireless access is a good start for privacy. But what about the common carrier networks that link your facilities around the country? Those WAN or wide area networks can be either private or public. If you lease a point to point T1 line, the only connections are at the two ends. Such links become part of your private network.

The next step up is privately owned and operated networks where you are not the only user. MPLS networks fall into that category. They offer a degree of privacy because access to your nodes is controlled per your direction. But there is other traffic on the network cloud from other companies. That’s why MPLS networks are called virtually private by nature.

Now let’s consider the Internet. It’s public through and through. Does that mean you can’t use the Internet for private communications? Of course you can. It’s done every day by companies large and small and millions of individual users. How do they do this? By encrypting the data traveling from point to point over the Internet. When you log into a secure website, you use SSL or Secure Sockets Layer. That’s a protocol that encrypts your data so that only someone with the proper key can read it. Only you and the site you are communicating with have that particular key. Others might intercept your data stream, but it’s all gibberish to them.

When data is encrypted at one end and decrypted at the other, it is said to travel through a tunnel in the Internet. That’s what’s meant by tunneling. Various encryption techniques can be used to create these tunnels and give you a virtual private connection. When someone is said to be using a VPN, they are generally talking about a broadband connection to their employer that is encrypted on their computer by a VPN software application. VPNs allow users located outside of a company’s secure facilities to securely access business data using DSL, Cable broadband, high speed satellite, or wireless Internet access.

What type of private or virtually private network connections are right for your organization? Get expert consultation and the most cost effective WAN network and VPN services now.

Click to check pricing and features or get support from a Telarus product specialist.




Follow Telexplainer on Twitter