tgreene
Executive Editor

Getting around the problem of granting VPN access to your staff when they’re at client sites

Opinion
Aug 24, 20062 mins

* Why one consulting firm uses both SSL and IPSec gateways

The IT director at a consulting firm that uses VPNs for its staff to connect back to headquarters recently noted that it uses both SSL and IPSec VPN gateways.

The company may well be transitioning to SSL, but whether it does is coming up from the grassroots level rather than being determined from the top down.

The firm initially invested in IPSec because it needed a secure way to link the consultants to the corporate network from within its clients’ firewalls. The VPN worked fine, and it wasn’t that complicated to configure once the firm reached the right IT person at the client firm.

The problem was that the full network connection that IPSec supports violated security policies at most of the client firms. Opening up their networks to another network that had unknown security vulnerabilities was forbidden, end of story. However, some clients did allow the IPSec VPN.

When SSL VPNs came out, the consulting firm added an SSL gateway to its IPSec gateway. Most of the consultants now use that instead, even though they all have IPSec clients installed on their laptops and can use either SSL or IPSec as they choose.

SSL seems to be gaining in popularity because it can generally get through firewalls at client sites because most companies leave SSL ports open. It can also be reached via Web browser, which eliminates having to boot up an IPSec client.

IPSec will likely remain around for a while at the consulting firm because it is the only method of access the firm grants to consultants who need to access its network. The company has multiple IPSec gateways, each of which protects a limited set of corporate assets, so the consultants can be corralled into just the subnet they need to access where they can’t wander to where they don’t belong.