Thursday, April 05, 2007

Leave a Comment

Below here, I have summarised differences between SSL VPNs and IPSec VPNs. Third columns lists expected feature.

(following the color coding)

Features IPSEC SSL VPNs EXPECTED

General
Encryption Technique IPSec/IKE SSL SSL
Split Tunneling No Yes Yes
Full tunneling Yes Yes Yes
Reverse Tunneling No May be Yes


Access Modes
Clientless mode No Yes Yes
Access portal No Yes Yes
Network extension Yes May be Yes
Port forwarding client for limited access No May be Yes
Application publishing (java emulators) No May be Yes
Full access client software size Large small Tiny
web deployed client May be Yes Yes
bi-directional access Yes May be Yes

Administration
Client installation on remote user machine Yes May be No
Client configuration on remote user machine No No No
Real time monitoring of user access May be Yes Yes
Centralized access control No Yes Yes
Notify/control users in real time No May be Yes
Remote control of remote users May be May be Yes
Requires firewall configuration Yes No No
Complexity High Simpler Low complexity
Per User administration Yes No NO


Authorization
Network parameter ACL granularity
(src/dest IP address, port, MAC) Yes Yes Yes
Endpoint configuration based No May be Yes
Application level ACL granularity
(file-share file name based, URL based policies) No May be Yes
Select applications that can run on VPN No May be Yes

Endpoint Security No 3rd party software Yes, embedded
Authorization based on End user
machine security settings No Yes Yes
Endpoint Remediation No May be Yes

Performance
Avoid TCP-over-TCP problem NA No Yes
Connection multiplexing No No Yes
Bulk encryption No May be Yes
Avoids TCP slow start No No Yes
Application based compression No May be Yes
Application to Application connection Yes Yes Optional

0 comments: