Home > Ask the Networking Channel Experts > Virtual Private Networks (VPNs) Questions & Answers > IPsec vs. SSL VPNs: Choosing the best virtual private network for your customer
Ask The Networking Channel Expert: Questions & Answers
EMAIL THIS

IPsec vs. SSL VPNs: Choosing the best virtual private network for your customer

EXPERT RESPONSE FROM: Retired Expert - Jon Snader

Pose a Question
Other Networking Channel Categories
Meet all Networking Channel Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 04 October 2006
What are some general guidelines I should consider when determining whether to recommend an SSL or IPsec VPN to a customer?

>
EXPERT RESPONSE

There's a great deal of confusion as to what "SSL VPN" means. One meaning is a traditional VPN that provides network-to-network communication in an application agnostic way. These types of SSL VPNs, exemplified by the open source OpenVPN, are very much like IPsec except that they use the SSL protocol for key negotiation and other administrative tasks. Because they usually operate in user space rather than the kernel, many experts believe that they have a security edge over an in-kernel IPsec implementation. On the other hand, they may suffer some performance degradation due to the need for application scheduling and repeated context switching between the kernel and user space. SANS has a nice white paper that discusses this type of virtual private network.

The other type of SSL VPN is actually an application gateway that uses SSL to encrypt network traffic between a client computer and an enterprise network. These types of virtual private networks are mostly useful for HTML-aware applications and a few other common applications (email, terminal access, etc.) for which the VPN device has built in "application translators." The advantage of these type of VPNs is that they use a standard Web browser and therefore don't require a special client or other software to be loaded on the client computer.

If your client is mostly concerned with allowing secure, remote access to Web-based applications and doesn't want to deal with the administrative headaches of loading additional software on each client machine and schooling employees in its use, then an SSL gateway is a simpler solution, both for the users and network administrators. On the other hand, if the client's users want access to the enterprise network -- so they can connect to their desktop computers, for example -- then IPsec or an SSL VPN like OpenVPN is the preferred solution. Some SSL VPNs perform both functions, but generally not as well as one dedicated to one or the other.


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Virtual Private Networks (VPNs)
Network server loss with a VPN connection
How can I help customers using Windows Server 2003 VPN on Windows XP clients to access the Internet successfully?
Designing an SSL VPN for customers with remote users
Using an indoor wireless mesh for client-network computing
Troubleshooting VPN connection problems for SMBs
VPN bandwidth troubleshooting
VPN tunnel troubles
Access limitation on Cisco 3000 concentrators
Implementing ISA servers
VPN/Vista compatibility

Developing a VPN Architecture
VPN setup guide, part 2: How to configure Windows Vista workstations
Vista VPN setup guide, part 1: How to configure Windows Server 2008
How can VARs determine which kind of VPN is the best fit for each customer's applications?
Infonetics: Ethernet and IP MPLS VPN growth continues
VPN tunnel troubles
Establishing peer-to-peer wireless file transfers over a VPN
How to set up a Windows VPN: A step-by-step guide
VPN fundamentals for VARs and network consultants
Exploring remote access VPN point-to-point tunneling solutions
IPsec VPNs: Identity and authentication options

Choosing a VPN
Vista VPN setup guide, part 1: How to configure Windows Server 2008
Charging and rating requirements for new communications media
VPN fundamentals for VARs and network consultants
Choosing the right VPN for your customer: Four questions to ask
Choosing the right VPN for your customer: VPN options

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice

HomeTopicsITKnowledge ExchangeTipsMultimediaWhite PapersBlogsEvents
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2006 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts