Find White Papers
Home
About Us
List Your Papers
    
> Aventail > Why Replace your IPSec for Remote Access

Why Replace your IPSec for Remote Access

White Paper Published By: Aventail

To thrive in an increasingly competitive world, forward-thinking organizations are encouraging workforce mobility.  Read this white paper by security expert Dave Piscatello, for an assessment of key attributes in a secure remote access solution and how you can benefit from replacing your IPSec VPN.



Tags : 
ssl, vpn, ssl vpn, ipsec, ipsec vpn, secure remote access, remote access, vpn upgrade

Aventail
Published:  Aug 21, 2009
Type:  White Paper
Length:  9 pages


Why Replace Your IPSec forRemote AccessDavid Piscitello
To survive and thrive in an increasingly competitive world, forward-thinkingorganizations are encouraging workforce mobility and access agility-the ability forworkers to transparently access any business application everywhere: at any time,from anywhere, using any device, over any network.
Several obstacles prevent organizations from providing access agility today. Thefirst is the need to protect business applications and information from unauthorizeddisclosure and abuse, not only for the obvious business reasons but especially tocomply in a confusing, evolving, and unforgiving regulatory environment (e.g., SOX,GLB, HIPAA). To satisfy these security needs, an organization must providegranular, resource-based access based on the level of trust it can establish for agiven user, which may vary depending on access location and device.
The proliferation of devices and communications networks that workers use today toaccess business applications poses numerous obstacles. Access agility encompassesfar more than a worker connecting to the corporate network from a company-ownedlaptop, using company-installed software, over a modem connection. Workers mustaccess diverse business applications from the most convenient device available, at anytime and place, using any network. It is no longer practical to deploy secure accesssolutions that rely on resident client software. Moreover, secure access solutions mustperform well over networks that exhibit vastly different topologies, throughput, andlatency.
A final obstacle is the need to protect the organization at large from a relentless streamof malicious attacks that may originate from devices used by workers to accessbusiness applications. Viruses, worms, blended threats, SPAM, and spyware are moreprevalent today than ever before. Such attacks drain IT and network resources,threaten privacy and company reputation, and hamstring user productivity.Organizations must have solutions to block attacks from every possible point of entry,including remotely connected devices.
Today's secure remote access solutions fall short of satisfying these requirements. Infact, secure, everywhere access business objectives cannot be met until we discardexisting paradigms, and invent and adopt solutions that achieve high degrees of end-user transparency and accessibility (access agility), granular policy control, and are, bydesign, able to adapt to and accommodate new device, OS, application, and accesstechnologies.IPSec Remote Access: Too much and too hard.
IPsec is an effective solution for site-to-site Virtual Private Networking, but it is nowabundantly clear that IPsec is a severely limited solution for remote access. Adopters ofIPsec-based secure remote access must work within a world of inherent constraints,the sum of which all but eliminates it as an "everywhere access" VPN solution.
IPsec deployment is fraught with addressing complexities. The widespread use ofnetwork address translation (NAT) and private addressing will forever limit IPsecdeployment. VPN administrators cannot predict whether IPsec users will succeed inconnecting to corporate networks because they simply cannot be certain where NAT isapplied and what addresses are used in the remote network. Because the IPsecstandards offer so little help, VPN administrators must also manage internaladdressing: are addresses dynamically assigned, and from what pool? How are routingand security policies affected by such assignment? What if assignments change?Simply put, standard IPsec won't work everywhere.
IPsec has a limited authentication and authorization policy model. StandardIPsec provides mutual authentication of client and server using digital certificates andshared secret passwords. In practice, both authentication methods prove impractical.Shared secret passwords provide dangerously weak authentication and proveunmanageable in large, multi-organizational user deployments. The expense andcomplexities associated with issuing client certificates in IPsec deployment scenariosoften lead organizations to consider token- or challenge response-basedauthentication, and standard IPsec supports these poorly. Proprietary and interimsolutions exist, but are complicated and saddled with their own vulnerabilities. Theinformation IPsec VPNs use for policy definition is insufficient to satisfy theauthorization policies organization... [download for more]

Browse Technology Topics

Data Center

Virtualization, Cloud Computing, Infrastructure, Design and Facilities, Power and Cooling, Green Computing  
    

Data Management

Application Integration, Analytical Applications, Business Intelligence, Configuration Management, Database Development, Data Integration, Data Mining, Data Protection, Data Quality, Data Replication, Database Security, EDI, SOAP, Service Oriented Architecture, Web Service Management, Data Warehousing  
    

Enterprise Applications

Application Integration, Application Performance Management, Best Practices, Business Activity Monitoring, Business Analytics, Business Integration, Business Intelligence, Business Management, Business Metrics, Business Process Automation, Business Process Management, Call Center Management, Call Center Software, Change Management, Corporate Governance, Customer Interaction Service, Customer Relationship Management, Customer Satisfaction, Customer Service, EBusiness, Enterprise Resource Planning, Enterprise Software, EProcurement, Extranets, Groupware Workflow, HIPAA Compliance, IP Faxing, IT Spending, Marketing Automation, Performance Testing, Product Lifecycle Management, Project Management, Return On Investment, Risk Management, Sales & Marketing Software, Sales Automation, Server Virtualization, Simulation Software, Supply Chain Management, System Management Software, Total Cost of Ownership, Video Conferencing, Voice Recognition, Voice Over IP, Workforce Management, Incentive Compensation, Spend Management, Manufacturing Execution Systems, International Computing  

Human Resource Technology

Human Resources Services, Payroll Software, Time and Attendance Software, Workforce Management Software, Financial Management, Employee Monitoring Software, Employee Training Software, Recruiting Software/Services, Employee Performance Management, ELearning, Benefits Management, Expense Management  
    

IT Career Advancement

Cisco Certification, Microsoft Certification, Linux Certification, Network Security Certification, Software Development Certification  

IT Management

Employee Performance, ITIL, Productivity, Project Management, Software Compliance, Sarbanes Oxley Compliance, Service Management, Desktop Management  
    

Knowledge Management

Collaboration, Collaborative Commerce, Contact Management, Content Delivery, Content Integration, Content Management System, Corporate Portals, Customer Experience Management, Document Management, Information Management, Intranets, Messaging, Records Management, Search And Retrieval, Search Engines, Secure Content Management, SLA  

Networking

Active Directory, Bandwidth Management, Convergence, Distributed Computing, Ethernet Networking, Fibre Channel, Gigabit Networking, Governance, Grid Computing, Infrastructure, Internetworking Hardware, Interoperability, IP Networks, IP Telephony, Local Area Networking, Load Balancing, Migration, Monitoring, Network Architecture, Network Management, Network Performance, Network Performance Management, Network Provisioning, Network Security, OLAP, Optical Networking, Quality Of Service, Remote Access, Remote Network Management, Server Hardware, Servers, Small Business Networks, TCP/IP Protocol, Test And Measurement, Traffic Management, Tunneling, Utility Computing, VPN, Wide Area Networks, Green Computing, Cloud Computing, Power and Cooling, Data Center Design and Management, Colocation and Web Hosting  
    

Platforms

AS/400, Domino, Linux, Microsoft Exchange, Oracle, PeopleSoft, SAP, Siebel, Solaris, Tivoli, Unix, Web Sphere, Windows, Windows Server  

Security

Access Control, Anti Spam, Anti Spyware, Anti Virus, Application Security, Auditing, Authentication, Biometrics, Business Continuity, Compliance, DDoS, Disaster Recovery, Email Security, Encryption, Firewalls, Hacker Detection, High Availability, Identity Management, Internet Security, Intrusion Detection, Intrusion Prevention, IPSec, Network Security Appliance, Password Management, Patch Management, Phishing, PKI, Policy Based Management, Security Management, Security Policies, Single Sign On, SSL, Secure Instant Messaging, Web Service Security, PCI Compliance, Vulnerability Management  
    

Software Development

.NET, C++, Database Development, Java, Middleware, Open Source, Software Outsourcing, Quality Assurance, Scripting, SOAP, Software Testing, Visual Basic, Web Development, Web Services, Web Service Security, XML  

Storage

Backup And Recovery, Blade Servers, Clustering, IP Storage, ISCSI, Network Attached Storage, RAID, Storage Area Networks, Storage Management, Storage Virtualization, Email Archiving, Data Deduplication  
    

Wireless

802.11, Bluetooth, CDMA, GPS, Mobile Computing, Mobile Data Systems, Mobile Workers, PDA, RFID, Smart Phones, WiFi, Wireless Application Software, Wireless Communications, Wireless Hardware, Wireless Infrastructure, Wireless Messaging, Wireless Phones, Wireless Security, Wireless Service Providers, WLAN  
Search