Skip Links

Network World

  • Social Web 
  • Email 
  • Close

(Comma separation for multiple addresses)
Your Message:

Making IPSec VPNs Enterprise Class

Turning low-cost consumer-grade IPSec VPNs into enterprise class.
Wide Area Networking Alert By Jim Metzler and Steve Taylor , Network World , 09/09/2009
Jim Metzler
Sign up for this newsletter now!

WAN experts Steve Taylor and Jim Metzler analyze and share best practices on WAN issues from optimization to management.

  • Share/Email
  • Tweet This
  • Comment
  • Print

The last newsletter highlighted the fact that the improvements that we have seen over the last 25 years in the price/performance ratio of wide area networking is nothing close to the price/performance improvements that we have seen for other areas of IT such as storage or processing. This newsletter will discuss a technique to turn low cost consumer-grade IPSec VPNs into an enterprise-class IPSec VPN.

Networkings 50 greatest arguments: IPSec VPNs vs. SSL

The last newsletter highlighted the fact that the price/performance of commonly used WAN services in the United States ranges from an average high of $1,200/Mbps/month for MPLS to an average low of $500/Mbps/month. The $500/Mbps/month is for an Internet VPN via a Tier 1 ISP assuming that the IT organization uses a T-1 and not DSL for access.

Some IT organizations, however, are reluctant to use an IPsec VPN because the Internet does not support any form of QoS. As a result, IPsec VPNs don’t always provide acceptable levels of latency, jitter, and packet loss for interactive enterprise applications or real-time applications. Part of the quality issue is due to the fact that packets are routed over the path that the Border Gateway Protocol (BGP) specifies regardless of whether traffic traversing those paths is encountering high levels of congestion resulting in unacceptable levels of latency, packet loss or jitter.

Not all IT organizations use a T-1 or similar facility to access an IPsec VPN. For example, IPsec VPNs can also utilize consumer-grade Internet access using cable and/or xDSL. These access technologies are high speed, and very low cost typically in the range of $3 to $15 per Mbps per month. However, while the reliability is generally regarded as acceptable for consumers, it is often regarded as being too low to meet enterprise quality standards for connectivity of branch offices to one or more central data centers.

However, a key concept in IT is the concept of adding intelligence to a multitude of consumer grade products or services and hence creating a low cost, highly reliable enterprise class product or service. For example, RAID (Redundant Array of Inexpensive Disks) arrays are created by wrapping a layer of intelligence around high volume consumer grade hard disk drives. RAID arrays have become popular because they are inexpensive, highly reliable and highly scalable.

Steve Taylor is president of Distributed Networking Associates and publisher/editor-in-chief of Webtorials. Jim Metzler is vice president of Ashton, Metzler & Associates.

  • Share/Email
  • Tweet This
  • Comment
  • Print
Partner Content

Simplify Your Branch Infrastructure

Learn how to simplify your branch infrastructure while dramatically increasing app performance with Citrix Branch Repeater.

Download the Free Info Kit

Next-Gen Load Balancing

Free Guide: "Next Gen Load Balancing: 8 Things You Need to Handle Today's Network Traffic" shows you the functionality needed in your next load balancer.

Download the Free Guide

Accelerate Your Web Apps by up to 5x

Free Guide: "The Secret to Getting Maximum Speed from your Web Applications."' Learn how you can deliver Web apps up to 5x faster.

Download the Free Guide

Comments (8)
Login
Forgot your account info?

Turning low-cost consumer-grade IPSec VPNs into enterprise classBy Anonymous on September 10, 2009, 8:43 amJim and Steve, Where's the Beef? Next article?

Reply | Read entire comment

re: Where's the Beef?By Anonymous on September 10, 2009, 11:40 amThis is like having a meeting to schedule a meeting. Who's the Pointy-Haired-Boss around here?

Reply | Read entire comment

This is the meta-articleBy Anon on September 10, 2009, 12:35 pmAllow me to summarize: "Last week I wrote an article with some stuff in it and next week I'll write an article about some related stuff"

Reply | Read entire comment

Poor articleBy Anonymous on September 10, 2009, 1:46 pmI second the "where's the beef" comments. The subject of the article is *VERY( interesting. Too bad the author had nothing to say about it.

Reply | Read entire comment

Excellent TopicBy Anonymous on September 10, 2009, 2:28 pmJim and Steve, I am impressed that you would tackle this subject. I commented a few months ago about how we were seeing this broadband IPsec VPN approach catching...

Reply | Read entire comment

Agree-- Excellent Topic!By DrewAllgeier on September 10, 2009, 9:58 pmJim and Steve-- right on and write on! You are hitting on a matter that has broad and deep implications for enterprise and channel partners everywhere. No longer...

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed
Partner Content

Simplify Your Branch Infrastructure

Learn how to simplify your branch infrastructure while dramatically increasing app performance with Citrix Branch Repeater.

Download the Free Info Kit

Next-Gen Load Balancing

Free Guide: "Next Gen Load Balancing: 8 Things You Need to Handle Today's Network Traffic" shows you the functionality needed in your next load balancer.

Download the Free Guide

Accelerate Your Web Apps by up to 5x

Free Guide: "The Secret to Getting Maximum Speed from your Web Applications."' Learn how you can deliver Web apps up to 5x faster.

Download the Free Guide