Security Infrastructure Overview - VPN Suresh Ramasamy
Agenda What is VPN?What is VPN? Types of VPNTypes of VPN SSL vs IPsecSSL vs IPsec Design ConsiderationsDesign Considerations Questions?Questions?
What is VPN? Virtual Private Network allows security connectivity, either one to one, or one to many.Virtual Private Network allows security connectivity, either one to one, or one to many.
Your Network
Why do you need VPN? Secure access to your officeSecure access to your office Secure tunnelling through public network from one site to anotherSecure tunnelling through public network from one site to another EncryptedEncrypted To reach networks with private IP allocation (RFC1918)To reach networks with private IP allocation (RFC1918)
Types of VPN Remote Access VPNRemote Access VPN Site to Site VPNSite to Site VPN
VPN – the big picture
Remote Access VPN
Site to Site VPN
SSL Based VPN
SSL vs IPsec SSL requires browser with 128bit encryption supportSSL requires browser with 128bit encryption support IPsec requires client (Windows some exceptions)IPsec requires client (Windows some exceptions) Mode of authentication, supports digital certificate and password based authenticationMode of authentication, supports digital certificate and password based authentication Multi factor capable for IPSec (device dependent)Multi factor capable for IPSec (device dependent)
Design Considerations Placement of VPNPlacement of VPN –Inside or outside of firewall? Type of AuthenticationType of Authentication –Password vs. Digital Certs? Factor of AuthenticationFactor of Authentication –Single Factor, Multi Factor, Token Based –One time passwords? (RSA SecurID)
Resources ble.htmlhttp://mia.ece.uic.edu/~papers/volans/ta ble.htmlhttp://mia.ece.uic.edu/~papers/volans/ta ble.htmlhttp://mia.ece.uic.edu/~papers/volans/ta ble.html
Suggestions?