Technology Industry
Industry: Email Alert RSS FeedA pretty interface is not enough: integrated firewall and VPN security just make sense - Cover Story
Communications News, Sept, 2002 by Mark Alexander
When divine Inc. acquire the assets of MarchFirst-three central sites in the Chicago area and 19 throughout the United States-Chuck Horvat, a founding member of Chicago-based divine and its director of network services, wondered how to securely integrate these 22 new networks into the existing corporate network. He had no desire to buy firewalls for each. So, Horvat and his engineers looked into security solutions, and found one that made sense--an integrated firewall/virtual private network (VPN) appliance.
Most RecentTechnology Articles
Shortly after the acquisition, MarchFirst filed Chapter 7 bankruptcy. The divine network services team had only six weeks to integrate the company and build a secure wide area network from scratch. Complicating matters was the nature of the acquisition: divine did not inherit ally established network circuits or commitments. MarchFirst's sites were geographically dispersed, with their own circuits and with some leased equipment.
Prior to the acquisition and under its original business model, divine's entry-level boxes supported only 1,000 concurrent TCP/ IP sessions and 10 VPN tunnels. "We decided to try using one NetScreen 5 from NetScreen Technologies of Sunnyvale, CA, for the initial test of isolating our mail infrastructure, which obviously in a session count wasn't appropriate, but we thought, "what the heck," says Chad Knupp, senior network engineer. "We had a tunnel up and running within an hour. We pumped almost 6 Mbps of DES (data encryption standard) through it, which is pretty impressive performance for an inexpensive appliance that fits in the palm of your hand."
FULL RANGE OF SECURITY FUNCTIONS
Early in 2001, based on the success of that trial, divine bought its first firewall/VPN system-level product. Horvat and his team settled on the NetScreen 1000 platform, which offered virtual local area network trunking of security with multiple security functions integrated into a single device. The purpose-built security appliances included VPN, firewall, denial-of-service (DoS) protection and authentication. While the product was easy to deploy and has an intuitive GUI, application-based security integration proved to be a key differentiator.
"We like to keep up to date," says Horvat. "For years, I had been begging for features and integration that we now have in this appliance-based box for under $500.
"I like appliances that are targeted for specific purposes," he says. "With security solutions, I believe in having a custom operating system, and hardware with no moving parts. Why have a hard drive for a firewall when you don't need it? Why have unnecessary points of physical failure? An appliance-based approach makes sense to me."
Using a custom operating system and application-specific integrated circuit (ASIC) technology to accelerate firewall/ VPN security and optimize network performance, the appliances eliminate traditional performance choke points experienced by software-based security solutions running on general-purpose PCs.
A COMPLETE SECURITY CHANGEOVER
"It would be a nightmare to manage multiple flavors of firewalls and expect to have reliable connectivity among those firewalls," says Horvat. "We were moving so aggressively that we didn't have time to deal with those kinds of reliability issues. NetScreen had a security solution that was just the right size for each one of the new facilities."
divine, which provides enterprises with content management, managed hosting, customer relationship management and consulting services, installed one NetScreen 1000 for the Chicago hub. The appliance provides 2-Gbps throughput and up to 25,000 VPN tunnels. Its performance impressed the engineers, as did its stability and manageability. With only a handful of engineers at divine, manageability is crucial.
The company also installed two NetScreen 204s in Burlington, and NetScreen 10s and 25s for the remaining sites. According to Horvat, the systems offer good overall cost-performance and no complex licensing schemes--charges were not based on the number of IP addresses. Most NetScreen products support an unlimited number of users.
"The cost for a new box was less than simply renewing the maintenance for the previous vendor used by MarchFirst," says Horvat. "By moving from that frame relay network to NetScreen VPNs and the Internet, we eliminated about $41,000 in monthly costs."
Having a full range of products from which to choose under one vendor simplifies everything, says Horvat. In addition, the Web interface has been getting more flexible and the command line getting more features. Code issues also get immediate attention. "When some of our offices fell victim to the Code Red virus," says Horvat. "the infected internal systems were performing a DoS within our network. NetScreen turned around some code revisions that dealt with the problem quickly."
SOLUTION PROVES ITS STABILITY
When divine first deployed the infrastructure, once the 25 units came up online, they stayed up. "They just don't crash," says Knupp. "They are unusually stable, extremely reliable." Occasionally, Knupp admits he has to do a configuration tweak, but the debugging tools facilitate finding the problem and solving the issue. Knupp also likes the fact that when he is doing an I-IKE (Internet key exchange) tunnel between the VPN appliance and a third-party product, he can accept any proposal dynamically. Despite different terminology among firewall vendors, he can get a tunnel up with any setting proposed by the other firewall and then see exactly what configuration is needed to lock it down.
CXO UnpluggedSmart Business interviews on BNET
Brought to you by CBS MoneyWatch.com
- Best- and Worst-Paid College Degrees
- 6 Things You Should Never Do on Twitter or Facebook
- How Much Sleep Do You Really Need?
- 6 Big Myths about Gas Mileage
- 5 Rules for Immediate Annuities
- Death in the Family: 12 Things to Do Now
- Dumbest Things You Do With Your Money
- 6 Online Networking Mistakes to Avoid
- 401(k) Mistakes to Avoid
- 5 Economic Scenarios to Keep You Up at Night
- The Real ‘Best Places to Retire’
- Best Credit Cards for You
- 12 Tough Questions to Ask Your Parents
- The Real ‘Best Colleges’
- Home Buyer Tax Credit: How to Cash In
- Why You Shouldn't Bash Cash
- 8 Phony 'Bargains' and Better Alternatives
- Danger: 3 Debit Card Scams to Avoid
- 6 Myths About Gas Mileage
- 29 Fees We Hate Most
- Quick and Easy Ways to Boost Returns
- Best Stocks to Buy Now
- Lower Your Taxes: 10 Moves to Make Now
- New Jobs: 8 Lessons from Real-Life Career Switchers
- The New Job Market: Who Wins and Who Loses?
- Health Care Reform's Public Option: Everything You Need to Know
- Volunteer Work When Unemployed: Should You Work for Free?
- Whose Recovery Is This?
- Long-Term-Care Insurance: 4 Biggest Risks to Avoid
Content provided in partnership with
Most Recent Technology Articles
Most Recent Technology Publications
Most Popular Technology Articles
- BizRate to monitor in-store customer satisfaction for Office Depot stores - Market Intelligence
- Speed control of separately excited DC motor
- Effects of creative, educational drama activities on developing oral skills in primary school children
- Political stability and economic growth in Asia
- Failed businesses in Japan: a study of how different companies have failed, and tips on how to succeed, in the Japanese market



