* NEC creates VPN connection to corporate sites without changing firewalls
NEC seems to be dabbling in VPN technology that can create a VPN connection between a remote user and a corporate site without reconfiguring the firewall protecting the corporate site.
The company has demonstrated the technology but says it has no plans to turn it into a product.
Nevertheless, it does point out one of the problems of VPNs, namely how do you get the firewall to let a remote user initiate sessions without weakening firewall defenses?
The system has a VPN agent on the remote machine and a gateway inside the firewall. When remote users want to create sessions, they send the gateway an e-mail making the request. The gateway is an appliance that sits between users’ corporate desktops and the corporate network.
The appliance responds by initiating a session from within the firewall, thereby making it unnecessary to leave extra ports open so the remote machine can do the initiating.
IPSec VPNs call for certain ports to be open to receive requests from the outside, and SSL VPNs use standard Web ports that are generally left open.
When a secure link has been established between the remote user and the desktop, the user has access to the same set of resources that would be available if it were being accessed from the actual desktop directly.
If NEC ever did decide to turn this into a commercial product, it might find itself in competition with vendors that sell remote control products that allow users and help desk workers to take over machines either to gain access to data and applications or to fix machines having problems. But NEC will have to rework the architecture so not every machine being accessed requires its own appliance.




