tgreene
Executive Editor

Why some VPN vendors are not putting additional functions on their VPN boxes

Opinion
Sep 8, 20053 mins

* Do users want multifunction security boxes?

This newsletter has pointed out in the past that makers of firewall/VPN appliances have started adding other security functions to their boxes – see Multi-function vs. single function devices: Which is more secure? and Cisco follows others down the multi-function security road.

This newsletter has pointed out in the past that makers of firewall/VPN appliances have started adding other security functions to their boxes – see Multi-function vs. single function devices: Which is more secure? and  Cisco follows others down the multi-function security road .

Now a research firm points out that some vendors are purposely not adding other functions to their VPN appliances. Some might say this is because VPN platforms can’t handle the additional load of anti-virus, intrusion detection and content filtering that some vendors are adding to their boxes.

The research firm, Infonetics, suggests another reason – that customers who already have firewall/VPN boxes don’t have to swap them out. “Some vendors are starting to build integrated content security appliances and are intentionally leaving out VPN and firewall functionality so these products can act as a supplement to existing embedded VPN/firewall products,” says Jeff Wilson, research director for Infonetics.

The truth is probably a combination of the two. Customers who have set up VPNs and have them working – a not inconsiderable feat even with the efforts vendors have made to streamline the process – probably don’t want to rip them out and start over. Depending on how old the VPN gear is, it might also not be fully depreciated yet. But it is also true that the performance of multi-function boxes that were designed to be firewall/VPN appliances may suffer compared to platforms designed to support additional security screening. Vendors won’t want to put out a product just to have it shown up by better designed gear.

This leaves potential customers with an opportunity if they can hold out until it is a good time to swap out their existing appliances. They can get more security in a single device that is located at a critical point in remote access networks. And they have the opportunity to evaluate whether they want to switch from SSL to IPSec VPNs or vice versa based on their company needs.

If they do opt to wait for a conversion to multi-function appliances, the wait is also likely to yield better performing equipment at lower prices as competition heats up.