Академический Документы
Профессиональный Документы
Культура Документы
VPNs are hot, and for good reason. They promise to help organisations
more economically support sales over the Internet, tie business partners
and suppliers together, link branch orfices with each other, ancl support
telecommuter access to corporate network resourccs.
A virtual private iictworli is ii coinliinatioii ol tuiinclling, encryption, autliciitidioii aiitl ;i(:ccss con1rol weti
to carry traliic o\wr the Intorncl (or a iiimaged 1iitcA
protoc:ol (11) iictwork or a providers Iiacltbonc:).
Simply stated, ii VLN gives 11.
a s~cU1cw a y to al:ccss
corporatc tiet\vorlt rcsour(:cs over tlic Intcriiet or othcr
public or private iirl\vorks.
260
NETWORKS
NETVORKS
mi-cls or tligitiil ccrtilicates. Sharcd secret is fairly easy to
utilise for ii sinall iiuiiilm of endpoints (clieiits mdior
gateways).liikon cards work vory well lor liirgc intrarict
iiiil)lciiientatioiis, 1x11lor ii large extranei im~~lciiietit;itit,n
the easiest iiicthod is io use ti digital cxrtilicate (public
key infrastrllctliro).
Gzla~mztcl?il
seruice
Rccgardless ol how mcll the securii y policics have hccii
dcfiiied, operating ii VIN nwr the lntcrnct is not liiglily
prcctlictal,le I~ecii~isc
tlic Iiiteriiot is not ii guaranteed
trmsport. 1I giixantccd scrvice is not required, thc
Internet provides ;idcquatc VIN transport.
IIowew!r, if guamiitecd scirvicc is mandatory, ii service
k!vel ;1jirccmcnl (SIA) cat1 be
transport nvcr i l managcd Ii tieluk. !In SI,/\ is ii money-back
giixantee that the sei-vice prnvidcr
(SI) will deliver :I specific level ol
service. Tliis iiiirrlit cnver~ lnr
cximple, overall nctworlc availability
of 99.7b, or cncl-to-end latency not
grmtcr than 15Oiiis round-trip, or
local loop availhility of 997k,or a
Ilacltct loss I l l less tlian 1 % overall
throughput. llie agreeinail may also
dictate such terms its, lor inslance, i i
rckiiid ol one months charges if the
SI ;ibrogatcs any o[ the agreed upon service levels.
Le p i h y il($izes aul/zori.sn/ioii re
implcmciit a LKI, you should VI
policy (CI) rcg;irtllcss 01 whether y o u oporatc or
outsourcc your CA.Ihc CI) deline;itcs the requiroincrits
t o i.cceive ii certifiixtc Irom the CA (lor caaniple, ii
certiiicatc must lie rccliicsted in persoti iiiid recluircs twn
loriiis (IC 111, one a piciurc 11)) m l / o r ;I lcvcl o l authority
([or cx;iiiiple, this ccrtilicatc ;~llowssignatwc aiitlioriiy
(or oiic nrillioti dollars).
For iin 11Sec clidpoint, ihc CIdciiiics &it in lnrin;ition must lie siilimi~tcdto thc CA lor ccrtific;itioii.
lMorenver, the CI shnuld
that tlrr CA must iiieet for
,.10
Conclusion
Whether implc~mcntcd;is iiii intranet or iin cxtranct, a
VIN can reduce coiiiinunicatioiis costs Iiy utilising ii
single connection with niic piece o l ccluipment f i x cach
location instead oC what would otlicrr
coiii~nu~iic:;itionlinlts using legacy cq
Cost is usu;illy the dcterrnining iiictor ol whether the
VIN is Iiuilt in-liouso or is contracted out. Cost pcr
coiincc:tioii lor ii scwice is wcighctl against the total
equipment, iraining, maiiitcii;incc, ;ind management
costs spi-ccatlover tlir number of connections rccpii-cd Tor
ii VIW built in-house. Aiiotlirr important considcratioii is
wlin iixiint;iiiis conti.ol o l thc equipmeiit. Some c:nmpanics
do not use coiitl;ict services, rcgartllcss ol cost, bcc;iusc:
thcy ~ w i i i lull
t
control ovvr the VI.
{Jsiiig VINs, compariics (:;in rc1i;ibly aiitl securely
share iiilorni:ition ;icross the Inicrnot or a iiiaiiagccl 11
iictivvoi-It.Todiiy VINs ai-c Iicing used to hclp corporapplicatiotis, tic: I)usincss partners
and suppliers togcthcr, and support the explosion o l
e-cni~i~iici-c~:,
cspccielly in husincss-to-husiiicss applicii1ions.