Virtual
Private Networks
What do ISP Customers Expect from a VPN
Service? continued
Security Options
Every VPN service spotted in my search included access
control, authentication, and encryption,
and a growing number touted support for IPsec standards. It now takes
something extra to make your security features stand out from the crowd.
AT&T CERFnet EQ-VPN is the only outsourced VPN service I've seen that
supports IPsec in transport mode (particularly applicable for financial
applications).
Troubled by lack of public key infrastructure?
GTE's Advantage VPNSM includes provisioning of GTE CyberTrust digital
certificates, and management features that allow customers to issue and
revoke certificates.
To protect against receiving infected email or files
from VPN partners, Pilot's CPN includes Trend Micro's Viruswall as an
option. Savvis' ProSecureSM incorporates ISS RealSecure for attack
recognition and response. These expanded security features indicate
growing customer awareness of network vulnerabilities.
QoS Issues
Managed VPN services differentiate themselves in two dimensions: quality
of service and level of support. Providers like GTE and MCI WorldCom offer
Service Level Agreements (SLAs) with proactive
monitoring and money-back guarantees. Consider this GTE SLA: 99.8 percent
availability and 125 ms or less round-trip latency site-to-site, 97 percent
busy-free remote access. Secure on-line access to real-time and historical
usage data is an essential complement to SLAs. For finer granularity,
the Xedia QVPNs used by MCI provide per-application bandwidth prioritization
features and will add class-based queueing later this year.
Outsourcing Support Advantage
Support is one area where outsourced VPN services can offer customers
a clear edge over roll-your-own VPNs, but 24x7 NOC support by VPN-savvy
staff is only the starting point. GTE differentiates itself by offering
superior web-based customer configuration, including the ability to remotely
add/delete users and update security policies. MCI offers local language
support and uses CPE modems for out-of-band trouble shooting. Pilot's
Heuristic Defense Infrastructure provides ongoing upgrades to address
previously detected attacks. ISPs must demonstrate their ability to run
customer VPNs more reliably, more responsively, and at a lower cost than
in-house IT staff.
The Cost Factor
Finally, don't forget the bottom line: Customers expect to save money
by deploying outsourced VPN services. The number and placement of local
Internet access points is key for remote access VPNs, while the global
reach of an ISP's high-speed backbone is more important for site-to-site
VPNs with stringent QoS demands.
End
back to the top of the article
|