Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
TODAY'S NEWS
Valentine's Day Patch Tuesday: Microsoft to issue 9 patches, 4 critical
Mobile World Congress sneak peek: Quad-core smartphones, Ice Cream Sandwich & more
Microsoft details 'Windows on ARM' program
March debut of 'iPad 3' a sure bet, says analyst
FBI unbolts Steve Jobs 1991 investigation file
Cisco boosted profit, sales in Q2 while cutting costs
Macs take on the enterprise
Four crazy tech ideas from Google's Solve for X project
Obama 2012 campaign playlist revealed courtesy of Spotify
Oracle buying Taleo for US$1.9 billion in direct hit at SAP
Amazon attacks Apple: You get 3 Kindle products for price of iPad 2
Pre-rendered pages highlight latest Google Chrome release
Microsoft exec: Lync-Skype integration a 'compelling opportunity'
The future of hypervisors
/

Reviews /

How we did it: VPNs

Today's breaking news
Send to a friendFeedback

.

We used Bay Networks 350T 10/100 switches to create two private LANs and one public LAN that represented the Internet. We set up three 500 MHz Digital Alpha systems on each of the private LANs to generate traffic, and we watched traffic using AG Group's EtherPeek. A pair of 350 MHz Pentium II systems served as management consoles and also as test units for vendors providing software-only solutions. We used a Cybex Autoboot Commander 4P keyboard/video/mouse switch to monitor our systems.

Most vendors chose to send representatives to install their products. After each one was installed, we started IP Security (IPSec) interoperability testing using a moderately complex tunnel configuration. We required vendors to support two different encryption algorithms: Data Encryption Standard and triple-DES.

Products that did not support IPSec and Internet Key Exchange (IKE) - including Internet Dynamics' Conclave, Microsoft's Windows NT Server 4.0, Routing and Remote Access Software and Novell's BorderManager Firewall Services 3 - were not part of this test phase.

The standards for IP security, which are often thrown together under the IPSec moniker, are long and complex. We found that most products are very similar when it comes to their IPSec implementations, probably because the standards are so comprehensive. Instead, we saw major differences in performance, interoperability and management applications. For this reason, our tests concentrated on these areas.

We tested PKI interoperability with a Windows NT-based product called Entrust/PKI from Entrust and verified whether vendors could really pass keys back and forth.

Finally, we used our test bed to stress-test the performance of all the products using TCP-based data streams. Our tests included a single-stream test, designed to show both throughput and latency of the VPN devices, and a multistream test, intended to show worst-case performance in a typical LAN environment.

We used a BSD-derived TCP/IP stack (Tahoe) and a greedy TCP data stream to send simplex traffic through the virtual private networks. On the receiving side, the same TCP/IP stack simply discarded the data. Because of the TCP stack compression syndrome, as well as the limits of MTU discovery in the stack, the VPNs had relatively dramatic effects on total system throughput. RELATED LINKS Back to the main review


NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
Click here to sign up!
New Event - WANs: Optimizing Your Network Now.
Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
Attend FREE
Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.