Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
TODAY'S NEWS
iPhone 5 rumor rollup for the week ending Feb. 10
Forget Public Cloud or Private Cloud, It's All About Hyper-Hybrid
Apple passes HP as largest tech company
How to get the IRS' attention: Forge nearly $8 million in tax returns, steal identities
Much of Western U.S. is a 3G wasteland, says FCC
How the Phoenix Suns basketball team takes on social media attacks
Microsoft details Windows 8 for ARM devices
Resume Makeover: How an Information Security Professional Can Target CSO Jobs
Blogger exposes major Google Wallet security flaw
Web app lets enterprise set security, sharing for Google Apps users
Cloudscaling to offer OpenStack private cloud platform
Macs take on the enterprise
Valentine's Day Patch Tuesday: Microsoft to issue 9 patches, 4 critical
Mobile World Congress sneak peek: Quad-core smartphones, Ice Cream Sandwich & more
/

Reviews /

Intel Network Systems
Response to RFP for Abbig Corporation


Requirement summary:

  • Remote access server (RAS) solution for central site of corporate network
  • Fault-tolerant for 99.9% uptime
  • Secure access for authorized users only
  • Centralized management providing full set of usage statistics
  • Remote access connectivity for telecommuters, mobile sales force and executives
  • 1,000 users accessing accessing network at central site
  • 500 users accessing network at each regional office, with 10 regional offices
  • Support for IP and IPX protocols

Assumptions:

  • A key objective is keeping remote access costs low.
  • Solution must be able to integrate with existing network infrastructure and allow for future growth.
  • Remote users are approximately 50% local and 50% long-distance (based on actual customer experience).
  • PSTN and Internet are available to all remote users.
  • User:port ratio is the industry guideline of 10:1.

Recommendation:

A hybrid solution combining direct dial and VPN remote access best meets Abbig Corporation’s need for high availability and security at an economical price point. This is preferable to either a pure remote access server or pure VPN solution (see attached Remote Access Analysis Report).

From a cost perspective, direct dial remote access is cost-effective for local connections, because it doesn’t incur time or distance charges. This complements VPN remote access, which saves money on long-distance users, who can dial a local ISP POP instead of a more expensive 800 number. As a result, the most cost-effective solution is a mix of both direct dial and VPN remote access.

To ensure high availability, an Intel LanRover Access Switch and LanRover VPN solution at each site provides built-in redundancy for all remote users, giving them access over the PSTN or Internet. Typically, local users access the network through the direct dial Access Switch but can also use the LanRover VPN solution as a backup option. The routing capability of the Intel VPN solution establishes an alternate path to the central site over the Internet, and the integrated, ICSA-certified firewall provides redundancy for the regional firewall.

All the LanRover Access Switches and LanRover VPN solutions can be managed from the central site, and the Shiva Access Manager RADIUS server provides centralized authentication, authorization, and accounting for all remote users, regardless of how they access their sites. A secondary RADIUS server ensures redundancy and is accessible over the internal network, PSTN, or Internet. The Shiva Accountant can be used in conjunction with Shiva Access Manager to produce detailed usage reports and charts for capacity planning and individual billback. (see sample chart on page 4)

Equipment cost:

The recommended configuration for each site is based on the industry guideline that 10% of remote access users will be online at any one time. This translates into 50 concurrent users per regional site and 100 concurrent users at the central site. Individual sites are set up with both a direct dial and VPN server, each of which can accommodate the full load of concurrent users independently as backup.

Intel’s solution is designed for future growth, well beyond the initial six-month deployment period. By adding modem cards, network managers can easily scale the LanRover Access Switch to accommodate new users. As VPN remote access usage grows, they can add multiple LanRover Expresses or Gateways, providing greater capacity as well as redundancy, load-balancing and automatic failover. The Shiva Accountant can be used to determine capacity planning, and the Shiva Remote Access Analysis Tool, available for free at www.shiva.com/remote/vpnroi, can assist in determining the right mix of direct dial and VPN remote access for maximum cost savings.

Regional Site
Product # concurrent users Quantity List Price/Unit Total List Price
LanRover VPN Express   1 $3,995 $3,995
VPN 50 client license N/a 1 Included Included
VPN 250 client license N/a 1 $11,000 $11,000
VPN Manager software N/a 1 Included Included
LanRover Access Switch DPS (48-port configuration) 48 analog30 ISDN 1 $28,000 $28,000
Shiva Configurator N/a 1 Included Included
Cost per Regional Site       $42,995

Central site:
Product # concurrent users Quantity List Price/Unit Total List Price
LanRover VPN Gateway Plus 400 1 $9,950 $9,950
VPN 1000 Client license N/a 1 $18,000 $18,000
VPN Manager software N/a 1 Included Included
LanRover Access Switch DPS (48-port configuration) 48 analog30 ISDN 1 $28,000 $28,000
Shiva Configurator N/a 1 Included Included
Shiva Access Manager (Primary RADIUS server) 500 1 $4,250 $4,250
Shiva Access Manager (Secondary RADIUS server) 500 1 $3,185 $3,185
Shiva Access Manager 1000-user license 1000 1 $800 $800
Shiva Accountant Unlimited 1 $1,995 $1,995
Total Central Site Cost       $66,180

LanRover Access Switch DPS is a scalable, parallel-processing remote access concentrator that supports a mix of up to 72 analog and 240 ISDN users. It supports dial-in, dial-out, and LAN-to-LAN communications over multi-protocol connections, features a breadth of security options, and includes a dual power supply for high availability.

LanRover VPN Express is a full-featured VPN solution in an economical, compact system bundled with a 50-client license. It features standards-based IPSec tunneling, ICSA-certified firewall, X.509 digital certificates, 168-bit encryption and automated key management.

LanRover VPN Gateway Plus is a complete VPN solution for up to 1,024 users and features standards-based IPSec tunneling, ICSA-certified firewall, X.509 digital certificates, 168-bit encryption and automated key management. Multiple VPN Gateways provide automatic failover as well as load balancing for reliable and consistent access.

Shiva Access Manager is an authentication, authorization and accounting solution that provides centralized access management for VPN and direct dial users. It interoperates with leading third-party security packages and can manage X.509 digital certificates issued by Shiva Certificate Authority, for integrated VPN and direct dial management.

Shiva Accountant is a stand-alone RADIUS accounting software solution that allows network managers to quickly generate reports to track VPN and direct dial usage for capacity planning and individual billback.

Chart 1:

Sample Shiva Accountant Usage Report

(showing 24-hour usage pattern for direct dial and VPN remote access) Click for Chart 1

Chart 2:

Remote Access Analysis Report: Abbig Corporation

Cost Analysis of Deploying Direct Dial only, VPN only, or Hybrid Solution

chart 2

RFPs from other vendors


NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
Click here to sign up!
New Event - WANs: Optimizing Your Network Now.
Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
Attend FREE
Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.