tgreene
Executive Editor

Sabre flies with SSL

News
Aug 29, 20055 mins

Travel services giant Sabre wanted to give customers access to its data center without having to provision, install, manage and maintain remote access gear, and it found the answer in SSL VPNs.

Travel services giant Sabre wanted to give customers access to its data center without having to provision, install, manage and maintain remote access gear, and it found the answer in SSL VPNs .

Using standard desktop browsers and an Internet connection, customers can reach Sabre’s portal and transact business as if they had site-to-site network layer connection to the data center via an IPSec VPN. The difference is that an IPSec VPN requires separate VPN appliances at each of Sabre’s more than 10,000 customer sites, while the SSL VPN requires gear only at the data center. Sabre currently supports 2,000 users on the SSL VPN; when the project is completed it will support 70,000, the company says.

Sabre wouldn’t say how much it is saving by transitioning to Nortel SSL VPN technology, but it eliminates the capital cost of devices at customer sites and the ongoing cost of keeping them up and running. “The economies were very attractive,” says Lindsay Miller, Sabre’s senior principal for end-to-end engineering.

Saving money

The project came about as part of an overriding plan to cut back on ongoing maintenance of customer connectivity, says Andrew Teel, the company’s senior principal in charge of strategic architecture. “We’re trying to pull away from giving customers physical equipment and network connections,” he says. Historically, Sabre would connect its travel agent customers to its data center and take responsibility for the link from site to site.

To keep the IPSec VPN running, Sabre needed a vendor that handled maintenance and repairs, warehouse space to keep spares, license fees and central servers – all of which ran up the cost. “It’s almost like a PC you’re maintaining out at the customer site. With the SSL VPN it’s really just the capital cost of the equipment and then the license fee on a user basis,” Miller says.

The company shifted the bulk of these connections to IPSec VPNs about 10 years ago and is now in the midst of a shift to SSL VPNs. “We’re trying for a zero footprint,” Teel says.

Sabre enlisted the aid of network consultant EDS to help decide which SSL vendor to choose. Besides Nortel, Sabre considered Aventail, Cisco, F5 and NetScaler. Nortel had a leg up because Sabre uses Nortel Contivity gear for its IPSec access, but Nortel also was able to integrate its gear with Sabre’s customer-portal software called MySabre. It was also able to scale to support the 70,000 users Sabre wants to transition to the SSL technology, Teel says.

Nortel did well against the competitors in benchmarking tests performed by EDS, he says. Those results, in conjunction with cost and Nortel’s ability to integrate the SSL VPN with the IPSec VPN gear that would remain in the network, carried the day for Nortel.

IPSec doesn’t go away

Some Sabre customer sites will remain connected by IPSec because managing a single IPSec device at a large location requires less work than managing a large number of users with SSL, he says. Sabre is considering a site with at least 30 users to be a candidate for IPSec for this reason.

In an effort to make the SSL VPN invisible to end users, Sabre wanted a single sign-on that would authenticate users to the VPN, as well as MySabre. That meant customizing the interface among Netegrity SiteMinder authentication platform, the VPN and MySabre.

MySabre requires a three-factor sign-on – user name, password and a pseudo-city code – but off the shelf. SiteMinder can handle only two. Customizing code and reconfiguring the Nortel 3050 VPN gateways enabled SiteMinder to take user credentials once, use them to turn up the VPN and then connect to the portal by passing on the credentials to MySabre, Miller says.

The result was that customers had to choose “virtual private network” as the method they wanted to use to connect to Sabre; otherwise use of Sabre services was unchanged between the IPSec VPN and the SSL VPN, Teel says. And the selection of the VPN is a one-time preference. After the first time, the system defaults to the SSL VPN.

Sabre’s SSL transition coincided with an upgrade of MySabre software, so customers were prepared for a bit of an education, Miller says.

The SSL VPN brought another benefit. Before using SSL, the company had been using HTTPS to connect remote users to Sabre 56K bit/sec via dial-up Internet connections. Tunneling the Sabre-specific protocol used to connect to Sabre’s servers through SSL improved performance these users experienced, Miller says. “Imagine that most of their day is sitting in front of the terminal emulation [screen] trying to be efficient. The agents are sitting on the phone with their customers, so response time and performance are key to them,” he says.

Overall, the switch to SSL VPN technology has served Sabre well. “This enables our business to extend to our customers, give them an integrated view of our network without too much work for us to do at the desktop level,” Teel says.