Cybernetica's response to RFP
for Powell Electrical Manufacturing Co / NWW VPN Survey 1999
1999-04-27
Executive summary
Cybernetica's remote access solution is based on switching over to Internet connectivity and using Secure Sockets Agent (SSA) - a software package allowing to add strong cryptographic security to any TCP-based client/server applications. Both key requirements for your new RAS solution - fault tolerance and communication security - shall be met. The cost of our solution is $1,019 in software license fees plus Internet connection charges less eliminated costs for maintenance of the dial-in system less eliminated long-distance call fees plus the cost of a firewall if necessary.Reliability issues
We suggest switching from an in-house dial-in service to using the services of your favorite Internet Service provider. While there are costs related to leasing a T1 line, the advantages of it - significantly smaller maintenance expenses, ability to use Internet resources as well as relief from the need to pay for long-distance phone calls for modem access outside your area - are likely to pay off in quite short time. I would like to stress the issue of maintenance expenses: each company should do what they do best. So let the data communication companies keep up your network connections. They can do it.Security issues - communication security
Secure Sockets Agent consists of a pair of proxies to be installed on the server computer and on the client computer and implements the industry standard SSL protocol between each proxy. The actual client program will be configured to connect to the SSA Client on localhost, and the server program will be allowed to accept connections from the SSA Server only. All communication between SSA Client and SSA Server will be encrypted using strong cryptographic algorithms and encryption keys of unlimited length. All communication between the existing client and the SSA client (or application server and SSA server, respectively) will continue to be plain text, so there will be no need to modify the original application. Besides just encrypting the communication, the SSA also features strong authentication of both the client and the server. SSA's authentication is based on public-key cryptography and X.509 certificates; the package also includes a Certification Authority (SSA User Manager). Thanks to its authentication features, the SSA Server shall only communicate with clients who present a valid certificate.Security issues - network security
In case of Internet connectivity, the corporate network should definitely be separated from the public network. Should you not require the Internet functionality, you may ask your ISP to configure your router to pass all inbound packets to the SSA Server, thus effectively separating your intranet from the Internet. Otherwise, you would require a firewall (either Cybernetica's Barricade or any other brand). We strongly suggest to choose a firewall that comes with on-site support and includes free software updates for at least 12 months after its installation.Meeting the other requirements
Central manageability is assured thanks to the bundled Certificate Authority. Usage statistics for the SSA Server are available via Event Viewer (on Windows NT) or from syslog (on Unix).Further advantages
As Cybernetica is an European company, we are not bound by export limitations and may therefore provide your overseas business partners and/or subsidiaries with strong cryptographic software that they'll need in order to access your network. SSA supports virtually all TCP-based application protocols including numerous protocols with dynamic IP port allocation. During the transition period, or if necessary, even later, you may continue to use Winframe through the SSA. The SSA is available for Win32 and a number of UNIX brands. Should you want to run SSA on a server that is not currently listed, we will compile the necessary binaries upon request. You can find more information on the SSA web site. You may download the binaries (executables) as well as end-user documentation free of charge or pay a small fee for a distribution on CD-ROM.Low cost, strong security
SSA Commercial Server License for 100 users costs $1,019 including free upgrades and free support via e-mail or phone for the period of one year from your purchase.Future perspectives
In the future, you might be willing to consider linking the HQ network and those of your subsidiaries into a single wide-area private network sharing a common private address space and communicating securely over any public networks. In case you also need strictly centralized management of the network and its security policy, you will want to check out the Privador SVPN System. Please direct your further requests to: Mr. Peeter P. MõtskülaInternational Sales Manager Cybernetica
http://www.cyber.ee
peeter.motskula@cyber.ee
tel +372 51 22 551
fax +372 639 7992 RELATED LINKS
Additional responses
Plus the original RFP and a sample RFP from The Gartner Group.
Review: VPNs
We test 15 products. Network World, 5/10/99.
Interactive VPN buyer's guide
Find a VPN that best matches your critieria.
