Internet.com ISP-Planet
Search ISP-Planet


Search internet.com
internet.com

IT
Developer
Internet News
Small Business
Personal Technology
International

Search internet.com
Advertise
Corporate Info
Newsletters
Tech Jobs
E-mail Offers

internet.commerce
Partner With Us














ISP Technology

VPN

VPN RFP Lab Eval: Final Thoughts —continued

by Lisa Phifer
VP Core Competence, Inc.
[January 4, 2002]
Email a colleague

Installation and Provisioning
Many ISPs resell equipment to customers in return for a small piece of the pie. Offering managed security services has far greater potential to generate recurring revenue and differentiate an ISP's offerings. According to the Yankee Group, the managed security market will reach nearly $1.7 billion by 2005. But providers in this fast-changing market will tell you: cost-effective administration is essential if you hope to turn a profit. Let's start with the device-level interfaces to install and provision individual appliances:

Device-Level Admin:
NetScreen
RapidStream
SonicWALL
Command Line Interface
Serial Port, Telnet
Serial Port, Telnet
Serial Port Only (12/2001)
CLI Capabilities
Provisioning
Diagnostics
Provisioning
Diagnostics
Basic
Graphical User Interface
WebUI
RapidStream Manager
SonicWALL GUI
GUI/CLI Security
SSH, HTTPS, VPN, Set Management IPs,
Read-Only Accounts
SSH, HTTPS, VPN, Set Management Ports, View/Clear-Only Accounts
VPN, Enable/Disable Remote,
Single Account
Install Aids
QuickStart (NS5 only)
Device Discovery,
Install Wizard
Install Wizard

To reduce the cost of provisioning, IPRVnet could drop-ship any of these units to a customer. SonicWALL's Install Wizard excels at "hand holding" newbies. RapidStream's Install Wizard requires more network know-how, but has a great discovery tool to avoid PC renumbering. By comparison, NetScreen's QuickStart is rather limited.

ISPs offering managed security services usually take responsibility for configuring firewall and VPN policies. Many even configure initial or "bootstrap" policies before units are supplied to customers. After the appliance is activated, secure remote management interfaces are essential for provisioning, monitoring, and installing upgrades.

NetScreen and RapidStream are easy to manage securely, supporting Telnet/SSH and HTTP/SSL from the LAN or WAN. SonicWALL's GUI is less secure: it is always listening for cleartext HTTP on the LAN, protected by a single admin login.

These appliances can all be administered securely over a VPN tunnel. Of course, you'll need to configure that VPN tunnel first—and avoid breaking it with later updates. We found NetScreen's and SonicWALL's checkboxes to enable admin over VPN more fumble-proof than RapidStream's explicit policy method.

When all else fails, serial ports come in handy to undo the damage. Using a serial port to access SonicWALL's CLI, one can do little more than import a previously-saved config. NetScreen and RapidStream CLIs are more full-featured; either can be used to tweak the existing config and view diagnostic logs.

Device-Level Monitoring
No matter how sophisticated your back-office surveillance system, remote monitoring depends on device-level interfaces. These appliances support the usual suspects—and a few unique features:

Device-Level Monitoring:
NetScreen
RapidStream
SonicWALL
SNMP
MIB-II, VPN Monitoring MIB, Standard and Enterprise Traps
MIB-II, VPN Topo and Monitoring MIBs, Standard and Enterprise Traps, Custom Traps
MIB-II,
Standard Traps
Remote Logging

SYSLOG Server,
WebTrends,
NetScreen-Global PRO

SYSLOG Server
or RSM/CPM Query
SYSLOG Server
or SGMS/ViewPoint
E-mail Notifications
Built-In Alerts,
VPN and Traffic Alerts with or without Log
Built-In Alarms,
Custom Alarms

Built-In Alerts,
Logs

NTP Support
Yes
No
Yes
From Device GUI
Traffic Graphs,
Counter Graphs,
System Logs,
Per-Policy Logs
Device Status, Device Alarms, VPN Logs,
Traffic Logs, Real-Time Monitors, VPN Tunnel / User Status
Device Log,
Web Use Report,
Service Use Report,
Node Use Report,
VPN Tunnel Status

Beware of hidden gotchas when forwarding logs. For example, appending cleartext logs to e-mail can be a security risk. NetScreen can forward logs to multiple destinations; the others send to just one SYSLOG server. With RapidStream, sending to a SYSLOG prevents querying logs from the CLI or GUI. On the other hand, RSSA-2000 device logs persistent after reboot—most appliance logs do not.

In comparison, SonicWALL SNMP traps and e-mail notifications are basic. NetScreen and RapidStream support more extensive VPN monitoring MIBs, traps, and alerts that signal changes in tunnel status and traffic level. At the device level, RapidStream offers more customizable alarms—for example, each alarm type can be sent to a different destination. RapidStream offers the most detailed VPN tunnel and user status. NetScreen has the edge when it comes to CLI-level debugging.

3. Installation and Device Level Monitoring

 

ISP Glossary
Find an ISP Term

Newsletters!
ISP-Planet Weekly

Best of ISP-Planet