Internet.com ISP-Planet
Search ISP-Planet


Search internet.com
internet.com

IT
Developer
Internet News
Small Business
Personal Technology
International

Search internet.com
Advertise
Corporate Info
Newsletters
Tech Jobs
E-mail Offers

internet.commerce
Partner With Us














ISP Technology

ISPPlanet eTunnels VPN-on-Demand

Speeding Deployment from the Center:
eTunnels VPN-on-Demand

by Lisa Phifer
VP Core Competence, Inc.
[December 11, 2000]

In September, eTunnels launched VPN-On-Demand, a unique "instant VPN" service. According to CEO Dimitri Sirota, VPN-On-Demand was designed to meet the top challenges involved in high volume service deployment. "The principals who formed this company worked with carriers that used CheckPoint FireWall-1 and Cisco PIX to build VPNs," said Sirota. "These CPE solutions were complex to deploy and didn't support Extranet very well. They were also hard to budget. This is the origin of VPN-On-Demand."

VPN-On-Demand 1.0 is aimed at providers who want to offer remote access VPN services to the SME market. The fundamental premise: keep VPN simple by making the network smart. eTunnels centralizes enrollment, provisioning, and policy enforcement to speed delivery and reduce cost. The upcoming 2.0 release (now in beta) adds centrally-managed CPE for site-to-site and Extranet VPN services.

VPN-On-Demand 1.0
Example Price: $1,500/month for 100-user VPN
eTunnels Inc.
Seattle, Wash.
http://www.etunnels.com

etunnels logo

Intrigued by this pitch, we took VPN-On-Demand 1.0 for a test drive. We found that this service lived up to its name: with an on-line wizard and software, we created a 3-member PC-to-PC VPN in about an hour. While this service is very simple to use and deploy, there are also limitations. Here's what we found.

The Foundation: eNS
As with other IPsec-based services, customer networks created by VPN-On-Demand provide encrypted communication between authenticated members. In release 1.0, IPsec ESP DES or 3DES tunnels carry traffic between client and server PCs. Release 2.0 adds software and hardware IPsec gateways—devices that terminate WAN tunnels, providing secure access to entire LANs.

But VPN-On-Demand places unusual emphasis on centralized, automated provisioning. Tunnel endpoints don't have to be individually configured with security policies, as in many VPNs today. Configuration and software updates flow from a central source: the eNS (eTunnels Network Server). "eNS operates as a service—like DNS, but for security," explained Sirota.

The eNS tracks VPN membership, state, security parameters, network topology, and resource locations. "Some customers want a worker visiting a customer site to be able to connect into their home network using the customer's network—sort of a hybrid of remote access and Extranet," said Sirota. "In this case, the client may be behind DHCP and a firewall, and eNS needs to understand network topology to make this all work."

The eNS is also a policy enforcer—a traffic cop. Each member of the VPN—client, server, or gateway—initiates an SSL connection to the eNS. The eNS authenticates the member, generates session keys, and orchestrates tunnel setup. An IPsec tunnel is established between the new member and every other active member (a fully-meshed VPN). There are no filters for specific protocols or source/destination pairs—every member is granted full access to the entire VPN. The eNS tracks element status and works to keep this fully-meshed network afloat at all times.

After setup, traffic is tunneled directly between VPN elements, using a point-to-point rather than hub-and-spoke tunnel topology. "This gets us out of the call, and lets us avoid the trust and latency issues that have impacted some other Extranets, like ANX," said Sirota. "If the eNS should go down, tunnels would not be impacted."

Nonetheless, placing so much control and real-time processing at the network center does raise reliability and scalability concerns. Naturally, the eNS is not just one monolithic server. It is a set of servers, hosted at multiple data centers for geographic redundancy. eNS servers are front-ended by L4 switches and back-ended by an Oracle 8 database. With VPN-On-Demand's centralized architecture, eTunnels must clearly do everything possible to prevent the eNS from becoming a single-point-of-failure—and to protect this juicy target from being hacked.

Pt. 1: Introduction / The Foundation
Pt. 4: ISP Opportunity / Bottom Line

 

ISP News
IDC: Microsoft's Yahoo Deal Could be a Big Hit
Ballmer Fills in 'Software-Plus-Services' Plan
Report: Enterprise Search Will Top $1 Billion by 2010

More >


ISP Glossary
Find an ISP Term

Newsletters!
ISP-Planet Weekly


Best of ISP-Planet

 

Feedback


Advertising inquiry? Click here!

ISP-Planet's RSS feed



JupiterOnlineMedia

internet.comearthweb.comDevx.commediabistro.comGraphics.com

Search:

Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

Jupitermedia Corporate Info


Legal Notices, Licensing, Reprints, & Permissions, Privacy Policy.

Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers

Solutions
Whitepapers and eBooks
Intel PDF: Virtualization Delivers Data Center Efficiency
Intel eBook: Managing the Evolving Data Center
Microsoft Article: BitLocker Brings Encryption to Windows Server 2008
Symantec eBook: The Guide to E-Mail Archiving and Management
Microsoft Article: RODCs Transform Branch Office Security
Go Parallel Article: James Reinders on the Intel Parallel Studio Beta Program
Avaya Article: Advancing the State of the Art in Customer Service
Adobe Acrobat Connect Pro: Web Conferencing and eLearning Whitepapers
Avaya Article: Avaya AE Services Provide Rapid Telephony Integration with Facebook
Go Parallel Article: Getting Started with TBB on Windows
HP eBook: Storage Networking , Part 1
MORE WHITEPAPERS, EBOOKS, AND ARTICLES
Webcasts
Intel Seminar: Efficiencies in Hardware/Software Virtualization
HP Webcast: Disaster Recovery Planning
Go Parallel Video: Performance and Threading Tools for Game Developers
HP Video: StorageWorks EVA4400 and Oracle
HP Webcast: Storage Is Changing Fast - Be Ready or Be Left Behind
MORE WEBCASTS, PODCASTS, AND VIDEOS
Downloads and eKits
IBM TCO eKIT: Your IT Budget is Under Attack, Get in Control
IBM Energy Efficiency eKIT: Learn How to Reduce Costs
30-Day Trial: SPAMfighter Exchange Module
Red Gate Download: SQL Toolbelt and free High-Performance SQL Code eBook
Iron Speed Designer Application Generator
MORE DOWNLOADS, EKITS, AND FREE TRIALS
Tutorials and Demos
Microsoft Article: Silverlight Streaming--Free Video Hosting for All
Featured Algorithm: Intel Threading Building Blocks - parallel_reduce
HP Demo: StorageWorks EVA4400
MORE TUTORIALS, DEMOS AND STEP-BY-STEP GUIDES