* Beware of claims that SSL vendors can duplicate IPSec VPN network layer access, analyst says
endif; ?>PUBLISHER’S NOTE: Please note that, as of 9/29/03, all of your valued Network World Fusion newsletters will be delivered to you from nwfnews.com. If you use filters to manage your newsletters based on domain name, please adjust accordingly.
Claims by Secure Sockets Layer vendors that their gear can provide network-layer remote access are being met with warnings by one industry analyst.
The vendors’ claims that they can duplicate IPSec VPN network layer access are confusing and misleading to customers, according to Joel Conover, an analyst with Current Analysis.
His argument goes that SSL remote access is designed to make remote access available from just about any PC connected to the Internet, whether it is issued by a company or is rented for an hour at an Internet kiosk. That convenience can also be a liability, he says.
Machines outside the control of a corporation’s security policies might be connected to the Internet without benefit of firewalls and anti-virus software, making it possible for them to become contaminated with Trojans, viruses, worms and whatnot. Giving such machines network-layer access is just asking to be infected, he says.
SSL vendors have acknowledged the problem and are scrambling around to offer software that makes sure remote machines have appropriate firewalls and anti-virus software and other security measures in place before they are allowed to gain access via SSL devices.
That fixes the problem but it does so at the expense of complexity, and if you want complexity, you might just as well use IPSec remote access gear for network layer access. It’s tried and true and readily available.
One of the attractions of SSL remote access technology is that it is simple to set up and use and can give the vast majority of users access to what they need without installing client software on remote machines. It also gives only application-layer access, making it more restrictive of what remote users are able to access. This makes the gear ideal for in-house remote access and extranets to allow business partners restricted access.
It makes sense for SSL vendors to offer network layer access; it lets them grab customers that would otherwise be attracted to IPSec remote access equipment.
And it makes sense for customers to consider the SSL network-layer equipment as a viable option. But they should not be fooled into thinking it will be as simple and elegant as SSL application layer access to Web-based applications.




