Doughnut-maker’s Web portal was key to the company intranet, extranet.
Krispy Kreme, the doughnut people, had a problem: The maker of their Web portal was going to upgrade its software, and the portal would no longer be compatible with Krispy Kreme’s SSL VPN gear.
Following research and trials of several other VPN gateways, the company found Whale Communication’s e-Gap , which supports the portal and also gives remote users the same view of the portal they would get if they connected to it via the LAN. This benefited the company because it could continue to use the portal without having to retrain the 1,000 or so end users that connect through it to reach centrally located applications, says Sam Gray, director of technical services for the doughnut franchiser.
Krispy Kreme was using CoreSecure SSL gateway software on Windows servers to protect Internet connections between remote users and the Krispy Kreme data center in Winston-Salem, N.C. Users connected through the company portal supported by CorePort, later bought by OpenText.
Gray tried Nortel’s Alteon switches, and Juniper’s and Aventail’s SSL gear. “With all of them we were able to get to a certain point but were not really able to get all of the various applications that sit behind our portal to work properly in that environment,” Gray says.
The company was trying to grant users access to the portal and to use the portal as they always had to reach the applications they needed, he says. The problem was that with most of the vendors, users had to first go through the SSL vendor’s interface before reaching the portal. Once in the portal, they may have to re-access it via the SSL vendor’s interface to reach a separate application.
The portal for Krispy Kreme is a master Web page for the company intranet and extranet, a launching place for other applications such as e-mail and its supply chain system. “Just having an SSL appliance that gets you to the portal page and it looks right – that’s one thing. But once you drill down into all the various applications that this portal is a front end for, everything behind it has to work, as well,” he says.
In SSL gear trials, no vendor gave Krispy Kreme exactly what it wanted, he says. “Nobody was ever able to pull off a 100% successful pilot. They’d maybe get 50% to 90%, but there were always some applications or some systems that just didn’t function properly,” he says.
Even Whale wasn’t ideal.
“It’s not plug and play. It’s not like you pull it out of the box and assign a couple of IP addresses to it and it just magically works. There was a lot of upfront work from their engineering staff to get all of our stuff set up behind their box and get it working,” he says. Whale says the work it did to give Krispy Kreme what it needed is now part of Whale’s e-Gap platform so users with similar requirements to Krispy Kreme can configure the boxes themselves.
The company was looking for an SSL gateway appliance as opposed to CoreSecure, which ran on a Windows server. “It gets away from managing the [operating system] and hardware environment from one side and the application from another. We’d rather have it all in one pocket,” he says.
Upgrades and management were also a problem, especially after CoreSecure was bought by a Swedish company, PortWise. “The time zone differences and the language differences made it difficult to get support,” he says. “A lot of times your only option was to leave a message and wait for a return call.”
Krispy Kreme chose SSL because the portal is an extranet access point, Gray says. The company didn’t want to use technology that required a remote client. “We don’t really own or have control of a huge portion of the end user PCs that have to connect, so we want to make sure whatever components have to be installed on that remote PC are easy to install and easy to support.”




