Home > Midmarket CIO Tips > Data centers and infrastructure for the midmarket > Virtual private networks offer secure, simple remote access
CIO Midmarket Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

DATA CENTERS AND INFRASTRUCTURE FOR THE MIDMARKET

Virtual private networks offer secure, simple remote access


Mike Rothman, Contributor
04.16.2007
Rating: -4.08- (out of 5)


Technology news and tips for midmarket CIOs
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


If you are connecting to your small or medium-sized business's internal network from a remote location, you should be using a virtual private network (VPN) -- period.

VPNs encrypt your sensitive traffic and require strong authentication, providing safe remote access. VPNs are also easy to aquire and use. The technology is mature, it's integrated into your firewall or unified threat management (UTM) platform and it works relatively hassle-free.

SSL VPNs preferred

Over the past few years, there has been a migration from IP Security VPNs to Secure Sockets Layer (SSL) VPNs because SSL VPNs don't require a specific client on the end device. That makes deployment a bit easier, but the user experience (once configured) is roughly the same. More organizations are using VPN technology to connect their remote sites and using inexpensive Internet bandwidth. This allows small and medium-sized businesses (SMBs) to adopt the technology more readily.

But remote access and site-to-site connections are not all that VPN technology has to offer. VPNs can be used for other reasons in an organization:

  • Visitor and/or guest access
    When consultants, auditors and other foreign bodies show up and want to connect to your network, all of the network jacks in conference rooms should be put on a closed network and directed into a VPN concentrator. This allows you to require strong authentication to get onto the network, ensuring that only authorized users can access internal network resources.

    Another benefit of encrypting the connection for guests is if your physical network is compromised, a hacker cannot detect any authentication information by sniffing the network.

  • Wireless networks within your building
    I've seen a trend toward turning off the wired ports in most conf

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


    RELATED CONTENT
    Data centers and infrastructure for the midmarket
    Pricing out Windows Server 2008 for virtualization cost efficiency
    Data center strategy starts with the business
    Desktop and application virtualization: Lessons learned
    FAQ: What is unified communications, and why would I want it?
    Virtualization technology creates hosts of problems for midmarket IT shops
    Virtual servers key to consolidated data center
    Fixed-mobile convergence saves firms costly mobile phone charges
    Virtualization the center of county's 'disaster avoidance' plan
    Five tips that could change your data center
    Converged networks a risky business

    Mobile technology for the midmarket
    ITSM and corporate performance management: CIO Decisions Ezine
    Midmarket data center management guides: Tips and best practices
    2008 top 10 technology articles: Social media, Vista, IT salaries
    FAQ: What is unified communications, and why would I want it?
    Mobile unified communications options for the midmarket
    Top five technology trends -- and why you should give thanks
    Information technology management e-book downloads for midmarket CIOs
    Arts center's network infrastructure hits right note with Wi-Fi, FMC
    When Microsoft shuts you down and other IT horror stories
    CIOs, unified communications and the lost art of conversation

    Remote connectivity for the midmarket
    9 steps to business continuity strategy: Remote access solutions, more
    Midmarket data center management guides: Tips and best practices
    How to build a remote-site disaster recovery plan -- a CIO's advice
    Arts center's network infrastructure hits right note with Wi-Fi, FMC
    Unified communications plans should tap CIO
    Forrester: IT industry demands better collaborative, integrated data
    Broadband Wi-Fi access a community dream
    Augusta latest city to try out municipal Wi-Fi
    Consumer smartphones pushing midmarket CIOs to adopt (news podcast)
    IPhone: CIOs ponder personal tech toys in the office

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    USB  (SearchCIO-Midmarket.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary


    erence rooms and requiring use of the wireless. This ensures that misconfigured network ports don't allow a free pass onto the internal network.

    The deployment model is similar to guest access in that all traffic on the wireless network is run through the VPN concentrator. Many UTM vendors are starting to provide integrated Wi-Fi access points in their platform. This makes a lot of sense because by definition all traffic would be routed through a VPN, providing encryption and authentication.

    Points of caution

    So what's the catch? Aside from the cost of installing a few more boxes depending on traffic volumes, there isn't one. And with the price of access points and VPN concentrators continuing to come down, this is becoming less of an issue.

    There is one area of caution that bears mention. I don't recommend organizations encrypt traffic on their internal networks. Not even between sensitive applications. Why? Encrypted data cannot be scanned and monitored for private data leakage or virus/worm proliferation.

    Given the increasing scrutiny of regulations, even for SMBs, an organization must be able to inspect data as it travels through the network -- before it is ultimately sent out into the harsh world -- to ensure compliance.

    But for providing access to your internal networks from outside your facility, conference rooms or over public wireless networks, you can't beat the security and convenience of VPN technology.

    Mike Rothman is president and principal analyst of Security Incite, an industry analyst firm in Atlanta, and the author of The Pragmatic CSO: 12 Steps to Being a Security Master. Get more information about The Pragmatic CSO at www.pragmaticcso.com, read his blog at http://blog.securityincite.com, or reach him via email at mike.rothman (at) securityincite (dot) com.


    Rate this Tip
    To rate tips, you must be a member of SearchCIO-Midmarket.com.
    Register now to start rating these tips. Log in if you are already a member.




    DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



  • Mid-market CIO Business Solutions on Data Integrity, Unified Communications, and Virtualization
    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2007 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts