|
Provider
|
VPN
Platform(s)
|
Tunnel Protocols & Encryption
|
VPN User Authentication
|
VPN User
Access Controls
|
VPN Features &
Add-Ons
|
Additional Comments
|
|
Altoria
RA VPN Solutions
|
Cisco, Aventail,
Juniper, Nortel CPE Gateways
Persistent,
Temporary, or No VPN Client
|
IPsec / IKEv1
& v2, SSLv3 & TLSv1, PPTP
encrypted
with AES, 3DES, RC4
|
PSKs, Certificates,
Passwords, RSA Tokens
using MSSP
or Customer AAA / Database
|
ACLs can
refer to Network / Subnet, Ports / Services, URLs / Data Objects,
Endpoint Device ID, Endpoint Scan.
|
Included:
5
Optional:
1 2 3 4 6 7 8
|
Depending
on platform chosen, may use full VPN client, Java/ActiveX client,
or only web browser. Client can be obtained from portal; all Windows
devices supported.
For password
auth, customer creates users directly on their live domain. For
hosted RSA strong auth, customer creates users via web form, activated
within 24 hrs.
Monitoring
as described under S2S VPN.
|
|
AT&T
Global
Network Client
|
NW-based
Persistent
VPN Client
|
IPsec / IKEv1,
SSLv3, PPTP, L2TP over IPsec
encrypted
with AES, 3DES, DES
|
Passwords,
RSA Tokens
using MSSP's
AAA / Database
|
ACLs can
refer to Network / Subnet, Ports / Services, URLs / Data Objects,
Endpoint Scan.
|
Included:
5 6 7
Optional:
1 4 8
|
Must
be purchased with S2S VPN or Business Internet Service. Available
with Wi-Fi, Ethernet, Dial, or Bring Your Own Broadband.
MSSP's
connection manager client provides integrated access, including
multi-carrier cellular & global Wi-Fi options.
|
|
FiberLink
Managed IPsec VPN
|
Cisco, Nortel,
Juniper CPE Gateways
Persistent,
Temporary, or No VPN Client
|
IPsec / IKEv1,
SSLv3
encrypted
with AES, 3DES
|
Passwords,
Tokens
using MSSP
or Customer AAA / Database
|
ACLs can
refer to Endpoint Device ID.
|
Included:
1 2 5 7 8
Optional:
3 4
6
|
Client can
be bundled or downloaded depending on customer needs. Compatible
with Win32 laptops & basic WinCE PDAs, supported by 24/7 helpdesk.
Portal provided
to hosted database, or customer can use own RADIUS / AD for user
auth & access rights.
|
|
Getronics
Managed Firewall/VPN
|
Cisco, Juniper,
Checkpoint, SonicWALL CPE Gateways
Persistent
or No VPN Client
|
IPsec / IKEv1
& v2, SSLv3, PPTP, L2TP over IPsec
encrypted
with AES, 3DES, RC4
|
Certificates,
Passwords, RSA Tokens, Fingerprint Readers
using MSSP's
AAA or ActiveDirectory .
|
ACLs can
refer to Network / Subnet, Ports / Services, URLs / Data Objects,
Endpoint Device ID, Endpoint Scan.
|
Included:
Optional:
1 2 3 4 5 6 7
|
RA VPN service
is bundled with Managed Firewall Service. Windows IPsec client
is available for download. Web-based SSL client is platform non-specific.
User account change process is based on service level, ranging
from simple account reset to complex validation.
|
|
Globix
Managed Firewall Managed VPN access option
|
Checkpoint,
Cisco Hosted CPE
Persistent
VPN Client
|
IPsec / IKEv1,
PPTP
encrypted
with 3DES
|
PSKs, Passwords
using MSSP
or Customer AAA / Database
|
ACLs can
refer to Network / Subnet, Ports / Services, URLs / Data Objects.
|
Included:
Optional:
2 5
|
RA VPN service
is bundled with Managed Firewall Service. Cisco & Checkpoint Windows
clients are provided to customer. User management specified by
customer.
|
|
Provider
|
VPN
Platform(s)
|
Tunnel Protocols & Encryption
|
VPN User Authentication
|
VPN User
Access Controls
|
VPN Features &
Add-Ons
|
Additional Comments
|
|
IBM
ISS
Managed VPN Concentrator
|
Checkpoint,
Cisco, Fortinet, Juniper, ISS Proventia M CPE Gateways
Persistent
or Temporary VPN Client
|
IPsec / IKEv1
& v2, SSLv3
encrypted
with AES, 3DES, RC4
|
PSKs, Certificates,
Passwords
using Customer's
AAA / Database
|
ACLs can
refer to Network / Subnet, Ports / Services, URLs / Data Objects.
|
Included:
2 3
Optional:
6
|
CPE hosted
by customer or MSSP. Standalone service or Managed Firewall feature.
Customer obtains VPN client from vendor.
MSSP trains
up to 3 customer user admins. SLAs include change ack (within
2 hrs) & implementation (within 2/8/24 hrs), outage notification,
portal availability, emergency rsp.
|
|
MegaPath
Mobility
|
NW-based or
Cisco, Aventail CPE Gateways
Persistent,
Temporary, or No VPN Client
|
IPsec / IKEv1,
SSLv3 & TLSv1
encrypted
with AES, 3DES
|
PSKs, Certificates,
Passwords, Tokens, Biometrics
using MSSP
or Customer AAA / Database
|
ACLs can
refer to Network / Subnet, Ports / Services, URLs / Data Objects,
Endpoint Device ID, Endpoint Scan.
|
Included:
Optional:
1 2 3 4 5 6 7 8
|
CPE hosted
by customer or MSSP. Cisco for IPsec; Aventail for SSL. Both available
with MSSP advanced client which allows connection only by protected
endpoints & includes dialer, firewall, IPS, anti-spyware, AV.
Or customer can use iPass client w/ dial, EV-DO, Wi-Fi, & hotel
broadband access services.
Software
& adds/changes/drops via portal.
|
|
Perimeter
VPN
|
Fortinet, Nortel
CPE Gateways
Persistent
VPN Client
|
IPsec / IKEv1,
L2TP over IPsec
encrypted
with AES, 3DES
|
Passwords
using MSSP's
AAA / Database
|
ACLs can
refer to Endpoint Device ID, Endpoint Scan.
|
Included:
1 2 4
Optional:
|
CPE hosted
by customer or MSSP. Windows client downloaded via URL. To disable
user account, customer informs MSSP.
|
|
Secure
Designs
Firelan
Managed Mobile VPN
|
SonicWALL,
Cisco, Watchguard, Juniper CPE Gateways
Persistent,
Temporary, or No VPN Client
|
IPsec / IKEv1
& v2, SSLv3, PPTP, L2TP over IPsec
encrypted
with AES, 3DES
|
PSKs, Certificates,
Passwords, RSA / Vasco Tokens
using Customer's
AAA / Database
|
ACLs can
refer to Network / Subnet, Ports / Services, URLs / Data Objects.
|
|
RA VPN service
is bundled with Managed Firewall Service. Uses vendor supplied
Win32 IPsec clients, embedded Win PPTP client, or any SSL-capable
browser. Software
& setup docs supplied via portal.
Auth based
on MSSP-managed user list on appliance or customer's Windows Domain,
RADIUS, or AD server.
|
|
SecureWorks
Managed
Firewall
|
iSensor, Checkpoint,
Juniper, Cisco CPE Gateways
Persistent,
Temporary, or No VPN Client
|
IPsec / IKEv1
& v2, SSLv3 & TLSv1, PPTP, L2TP over IPsec
encrypted
with AES, 3DES, DES, RC4
|
PSKs, Certificates,
Passwords, Tokens, Biometrics
using MSSP
or Customer AAA / Database
|
ACLs can
refer to Network / Subnet, Ports / Services, URLs / Data Objects,
Endpoint Device ID, Endpoint Scan.
|
Included:
5
Optional:
1 2 3 4 6 7 8
|
RA
VPN service is bundled with Managed Firewall Service. VPN client
software, protocols, algorithms, & auth methods all depend on
type of firewall.
User add/drop/change
thru tickets submitted via portal or phone.
|
|
Provider
|
VPN
Platform(s)
|
Tunnel Protocols & Encryption
|
VPN User Authentication
|
VPN User
Access Controls
|
VPN Features &
Add-Ons
|
Additional Comments
|
|
Solutionary
ActiveGuard Monitored and Managed RA VPN
|
Cisco, Checkpoint,
Juniper CPE Gateways
Persistent
or Temporary VPN Client
|
IPsec / IKEv1
& v2, SSLv3 & TLSv1, PPTP, L2TP over IPsec
encrypted
with AES, 3DES, RC4
|
PSKs, Certificates,
Passwords, Tokens
using Provider's
AAA / Database
|
ACLs can
refer to Network / Subnet, Ports / Services, URLs / Data Objects.
|
Included:
Optional:
2 3 6
|
Can
use any vendor-supported VPN client.
Add/drop/change
requests submitted via e-mail form or portal.
Monitoring
as described under S2S VPN.
|
|
Symantec
Monitored and Managed Firewall/VPN
|
Checkpoint,
Cisco, Juniper CPE Gateways
Persistent
VPN Client
|
Depends on
firewall vendor technology.
[ No further
details supplied ]
|
PSKs, Certificates,
Passwords, Tokens, Biometrics
using MSSP
or Customer AAA / Database
|
ACLs can
refer to Network / Subnet, Ports / Services, URLs / Data Objects,
Endpoint Device ID, Endpoint Scan.
|
Included:
Optional:
1 2 3 4 5 6 7 8
|
RA VPN service
is bundled with Managed Firewall Service. Customer manages VPN
client distribution & administration.
For user
adds/changes/drops, see firewall mgmt change control process.
|
|
Unisys
Secure VPN Remote Access
|
Cisco, Checkpoint,
Juniper, Nortel CPE Gateways
Persistent
or Temporary VPN Client
|
IPsec / IKEv1
& v2, SSLv3
encrypted
with AES, 3DES, RC4
|
Certificates,
Passwords, Tokens
using MSSP
or Customer AAA / Database
|
ACLs can
refer to Network / Subnet, Ports / Services, URLs / Data Objects,
Endpoint Device ID.
|
Included:
Optional:
1 2 3 5 6 7
|
CPE hosted
by customer or MSSP. Persistent IPsec client for Cisco, Nortel,
Checkpoint, & iPass. Browser-based Java/ActiveX download for SSL
VPNs.
Supports
customer or MSSP-driven user admin via Managed Service Desk add/drop/change
process.
|
|
Verizon
Business
IP VPN Remote AccessSSL
|
Aventail CPE
Gateway
Persistent,
Temporary, or No VPN Client
|
IPsec / IKEv1,
SSLv3
encrypted
with AES, 3DES, RC4, DES
|
PSKs, Certificates,
Passwords, RSA, Tokens
using MSSP
or Customer AAA / Database
|
ACLs can
refer to Network / Subnet, Ports / Services, URLs / Data Objects.
|
Included:
1 2 3 4 5 6
Optional:
7 8
|
3
client options: clientless browser access to web & file apps,
auto-downloaded Aventail OnDemand Java agent for client/server
apps, or installed Aventail Connect Windows client for full network
access.
Service
Management Console used by customers to define access policies.
|
|
Verizon
Business
IP
VPN Remote AccessIPSec
|
Nortel, Cisco
CPE Gateways
Persistent
VPN Client
|
IPsec / IKEv1
& v2, L2TP over IPsec
encrypted
with AES, 3DES
|
PSKs, Certificates,
Passwords, RSA Tokens
using MSSP
or Customer AAA / Database
|
ACLs can
refer to Network / Subnet, Ports / Services.
|
Included:
3 5 7
Optional:
1 2 4 6 8
|
Standalone
or bundled with Verizon Business Access Manager for RA connectivity
& desktop mgmt.
ESM
web site used to download Nortel or Cisco Windows VPN clients
& manage user accounts, group policy, products, & reports.
|
|
Virtela
Remote Access VPN
|
NW-based or
CPE Gateways (F5,
Juniper)
Persistent
or No VPN Client
|
IPsec / IKEv1,
SSLv3
encrypted
with 3DES
|
PSKs, Passwords,
RSA Tokens
using MSSP
or Customer AAA / Database
|
ACLs can
refer to Endpoint Scan.
|
Included:
Optional:
1 2 3 4 7 8
|
CPE hosted
by customer or MSSP. SSL preferred; IPsec clients also available.
If authentication is through a proxy, customer maintains user
control.
VPN provides
access to entire network unless ACLs applied by a managed router/firewall
service.
|
|
Provider
|
VPN
Platform(s)
|
Tunnel Protocols & Encryption
|
VPN User Authentication
|
VPN User
Access Controls
|
VPN Features &
Add-Ons
|
Additional Comments
|