internet.com Corp. ISP-Planet
Search ISP-Planet


Search internet.com
internet.com

IT
Developer
Internet News
Small Business
Personal Technology
International

Search internet.com
Advertise
Corporate Info
Newsletters
Tech Jobs
E-mail Offers

internet.commerce
Partner With Us














ISP Technology

VPN

Multi-Vendor VPNs:
The Quest for Interoperability

Should your ISP stick with a single vendor solution to deploy VPN services or do multi-vendor systems deliver a better return on investment? Learn how to build a VPN offering around your ISPs short and long-term goals.

by Lisa Phifer
Core Competence, Inc.
[June 20, 2001]
Email a colleague

Those who deploy Virtual Private Networks (VPNs) for Internet-based remote access, Intranets, and Extranets often begin with a single-vendor solution. Focusing on a single vendor product line can reduce capital equipment, training, and support costs. Initial deployment is often faster and simpler because there are fewer interoperability issues to overcome.

Why go multi-vendor?
Over the long-haul, many larger enterprises, service providers, and carriers end up pursuing multi-vendor VPNs:

  • Do you need to deal with firewall and routers already deployed in the target network—an embedded base that won’t disappear overnight?
  • Is that single vendor product line really the loosely-integrated sum of several acquisitions?
  • Does your target market go beyond the range covered by one vendor, requiring you to look elsewhere for cost-effective solutions at the low or high end?
  • Do you stick with vendor A even when vendor B introduces newer, better, faster products?
  • Is your account big enough that pitting one vendor against another can reduce your cost or speed feature enhancements?

Harmonic shape and form
When business drivers lead you to consider a multi-vendor VPN, what are the consequences? Multi-vendor VPNs raise concerns about interoperability because IPsec and IKE standards offer many options for protocols, modes, authentication methods, key exchanges, encryption algorithms, and message hash algorithms. Even when the complementary options are supported, these specifications are complex and can be interpreted differently.

Because mix and match problems are inevitable, most VPN vendors perform conformance and interoperability testing to mreasure their own gear against rival's equipment. Self-testing starts behind closed doors, in the safety of one's own laboratory.

Most vendors also attend VPN bakeoffs—industry events held every year. The last bakeoff was in September in San Diego. The next is slated for Finland in August, 2001. VPN bakeoffs are not held to publish test results—they are intended to enable self-testing and debugging in a relatively safe setting. If you purchase products from vendors that participate in VPN bakeoffs, your odds of multi-vendor success are greatly improved.

Next, there is the Virtual Private Network Consortium (VPNC), a trade association for VPN vendors. VPNC exists to promote member products and augment interoperability by showing where member products conform to IPsec and IKE standards.

A product that passes the VPNC Basic conformance test has successfully initiated an IPsec tunnel to open-source gateways from OpenBSD and KAME. This test verifies product support for IKE authentication with preshared secret, and ESP with 3DES and SHA-1. A product that passes the Rekey test has also demonstrated that it can automatically rekey IPsec tunnels with these gateways.

A list of member products awarded the VPNC logo and associated test results are available online. But there is one caveat, VPNC tests for conformance—not interoperability. Products sporting the VPNC logo won't necessarily interoperate with each other.

ICSA Labs, now a division of TruSecure, runs an IPsec Product Certification program intended to promote multi-vendor interoperability. Version 1.0B verifies that certified products support baseline IPsec—ESP with 3DES and SHA-1, and IKE—preshared secret, Diffie-Helman Group 2. In addition, ICSA tests for proper implementation of cryptographic algorithms. Version 1.1 certified products will also be required to demonstrate baseline digital certificate support.

Unlike VPNC, ICSA continuously re-tests products to verify interoperability with all other certified products. Their website states, "Interoperability testing is not a one-time event, but rather requires ongoing testing with present and future peers. Having been awarded the certification is not an end to the process." A table of certified products and test results can be found here. If you're building a multi-vendor VPN, consult the ICSA's Lab Notes to read about pairwise anomalies.


Go to page 2: One Example >

ISP News
IDC: Microsoft's Yahoo Deal Could be a Big Hit
Ballmer Fills in 'Software-Plus-Services' Plan
Report: Enterprise Search Will Top $1 Billion by 2010

More >


ISP Glossary
Find an ISP Term

Newsletters!
ISP-Planet Weekly


Best of ISP-Planet

 

Feedback


Advertising inquiry? Click here!

ISP-Planet's RSS feed



JupiterOnlineMedia

internet.comearthweb.comDevx.commediabistro.comGraphics.com

Search:

Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

Jupitermedia Corporate Info


Legal Notices, Licensing, Reprints, & Permissions, Privacy Policy.

Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers

Solutions
Whitepapers and eBooks
Intel Article: Using Power & Display Context in the Intel Mobile Platform SDK
Internet.com eBook: Real Life Rails
IBM SCA Center Article: Simplifying Composite Applications with Service Component Architecture
Intel PDF: Quad-Core Impacts More Than the Data Center
Internet.com eBook: The Pros and Cons of Outsourcing
Go Parallel Article: Scalable Parallelism with Intel(R) Threading Building Blocks
Intel PDF: Analysis of Early Testing of Intel vPro in Large IT Departments
Internet.com eBook: Best Practices for Developing a Web Site
Intel PDF: IT Agility through Automated, Policy-based Virtual Infrastructure
IBM CIO Whitepaper: The New Information Agenda. Do You Have One?
Microsoft Article: BitLocker Brings Encryption to Windows Server 2008
Microsoft Article: RODCs Transform Branch Office Security
Go Parallel Article: James Reinders on the Intel Parallel Studio Beta Program
Avaya Article: Advancing the State of the Art in Customer Service
IBM Whitepaper: How are other CIOs driving growth?
Adobe Acrobat Connect Pro: Web Conferencing and eLearning Whitepapers
Avaya Article: Avaya AE Services Provide Rapid Telephony Integration with Facebook
Go Parallel Article: Getting Started with TBB on Windows
HP eBook: Storage Networking , Part 1
MORE WHITEPAPERS, EBOOKS, AND ARTICLES
Webcasts
Go Parallel Video: Intel(R) Threading Building Blocks: A New Method for Threading in C++
HP Video: Is Your Data Center Ready for a Real World Disaster?
HP On Demand Webcast: Virtualization in Action
Go Parallel Video: Performance and Threading Tools for Game Developers
Rackspace Hosting Center: Customer Videos
Intel vPro Developer Virtual Bootcamp
HP Disaster-Proof Solutions eSeminar
HP On Demand Webcast: Discover the Benefits of Virtualization
MORE WEBCASTS, PODCASTS, AND VIDEOS
Downloads and eKits
Actuate Download: Free Visual Report Development Tool
Red Gate Download: SQL Backup Pro
Microsoft Download: Silverlight 2 Software Development Kit Beta 2
30-Day Trial: SPAMfighter Exchange Module
Red Gate Download: SQL Toolbelt
IBM SCA Download: Start Building SCA Applications Today
Iron Speed Designer Application Generator
Microsoft Download: Silverlight 2 Beta 2 Runtime
MORE DOWNLOADS, EKITS, AND FREE TRIALS
Tutorials and Demos
IBM IT Innovation Article: Green Servers Provide a Competitive Advantage
Microsoft Article: Expression Web 2 for PHP Developers--Simplify Your PHP Applications
Featured Algorithm: Intel Threading Building Blocks - parallel_reduce
MORE TUTORIALS, DEMOS AND STEP-BY-STEP GUIDES