* SSL derivative supports real-time, remote apps
endif; ?>Recently, we’ve been highlighting the fact that in their native forms, both SSL and IPSec have unique advantages and disadvantages. IPSec excels for connecting corporate sites across the WAN, while SSL does a great job in the remote-access world for appropriately Webified applications.
Recently, we’ve been highlighting the fact that in their native forms, both SSL and IPSec have unique advantages and disadvantages. IPSec excels for connecting corporate sites across the WAN, while SSL does a great job in the remote-access world for appropriately Webified applications.
Net6, of San Jose, is attempting to bring the best of these VPN worlds together with its Hybrid-VPN Gateway. By “hybrid,” the company means not a hybrid of both technologies, but a hybrid of SSL and IPSec technology benefits.
The company’s product is based on SSL, but it also adds support for real-time traffic, thereby attempting to give it the advantages of IPSec without the IPSec headaches. Basically, it creates a secure SSL-based TCP tunnel from the client computer to a Net6-based server within the DMZ of the targeted corporate network. The product requires client software, though minimal, which interacts with the computer’s operating system primarily at the application layer, says Brad Peterson, director of operations.
He says that this offers several advantages as compared with either SSL or IPSec. In particular:
* Support for real-time transmissions. Think of the configuration conceptually as supporting UDP over SSL. Through Net6’s proprietary protocol handling, UDP traffic (such as VoIP) is handled via a special TCP stack that eliminates the unacceptable delays of transmitting VoIP over TCP.
* Always-on capabilities/connection persistence. Because the Net6 client operates above the network layers, users can stay connected as they roam from network to network, including moving from wired to wireless networks.
* Operation through NAT and firewalls. Because the software uses industry-standard connection techniques like HTTPS, users should find accessing corporate networks from “foreign” networks to be as simple as establishing a Web session. This method also minimizes the exposure of the corporate network to the remote network, in that not all individual PCs on the shared remote network can gain access to the corporate network.
In fact, the biggest problem that we found with Net6 is its product naming. To us, “Hybrid-VPN” implies that there are both SSL and IPSec components in the product. In reality, what the product does is to attempt to provide the benefits of both SSL and IPSec by running a proprietary, enhanced form of SSL technology only.




