* ICSA Labs prepares second round of testing for SSL VPN gear
Networking certification company ICSA Labs is preparing a second round of testing for SSL VPN gear.
ICSA Labs released results of its first-round tests in May, and the new tests will be tougher, says Brian Monkman, ICSA’s technology programs manager.
The first round included a number of criteria that SSL VPN gear should have, but in the second round, all criteria have been upgraded to must-haves, Monkman says. For instance, session logging was a suggested feature under the first round but will be a mandatory feature in the second.
The new round will also include new requirements, such as checking whether remote machines have anti-virus software running before they are allowed VPN access.
Monkman says making the testing tougher reflects the fact that SSL VPN equipment is becoming more mature. The tests are set up with an awareness of what devices are likely able to do, and so most vendors can pass with minor tweaking of their products.
The ICSA’s position is that the tests and any upgrades performed to enable gear to pass make for better products, Monkman says.
The ICSA tests are drawn up with input from an advisory board of vendors, he says, and the new round will be offered in January.
Recently, the VPN Consortium instituted testing of its own for SSL VPN gear, issuing logos to equipment that could pass both its tests: One tests check that equipment can make secure connections to corporate Internet portals and the other test verifies support for the Outlook Web Access e-mail and messaging application. The group says it will retest equipment that has won logos as vendors upgrade their software.
Like ICSA, VPNC says it also plans to create more extensive tests for SSL VPN products.
Companies that won VPNC logos are Caymas, Check Point, Cisco, F5, Juniper Networks, Nokia, Nortel, SafeNet and Whale Communications.




