Secure site-to-site connectivity traditionally implies frame relay, leased line and IPSec deployments. While frame relay and leased line connections are very secure, they are also very expensive – hence the explosion in IPSec deployments, which leverage encryption and the ubiquity of the Internet to create cost-effective and secure multi-site virtual private networks.

For all of its advantages, IPSec retains distinct disadvantages; the most notable being that it provides only an encrypted connection. In common deployments, two or more sites must be connected to allow key applications to communicate, to provide business partners access to a select set of resources, or to allow collaboration for given business units. With IPSec, this can be achieved, but at the expense of exposing the entire network on both ends of the connection.

To address this security gap, administrators must configure extensive ACLs and security policies to ensure only authorized users access authorized resources. With IPSec, this process is time-consuming, error-prone and often disregarded – at great risk to an organization’s well being.

Array Site-to-Site SSL VPN

  • Encryption plus granular access control
  • Dramatically reduced administration and IT overhead
  • Remote access and site-to-site connectivity on a single platform  

Array site-to-site SSL VPN access solutions provide all the benefits of traditional IPSec site-to-site connectivity and go above and beyond, introducing granular access control and the ability to connect sites at the network, host, and application level.

Application and Host Level Access

With site-to-site SSL VPN, organizations requiring site-to-site connectivity to enable communication between business critical applications can establish permanent connections that enable only key applications or host servers to communicate – eliminating the need for complex ACLs and eliminating unwanted network exposure and associated security risks.

Network Level Access

At the network level, Array site-to-site SSL VPN provides all the performance and functionality of traditional IPSec connectivity, but with distinct advantages. SSL VPN network separation and NAT capability enables administrators to connect subnets within networks, such that engineering at headquarters is restricted to communicating with engineering at a remote site. No additional ACLs or security policies are required to prevent user communities from viewing or accessing resources or networks for which they are not unauthorized.

Secure Access Consolidation

An added benefit of site-to-site SSL VPN is the ability to consolidate both remote access and site-to-site access on a single platform. SSL VPN is the technology of choice for remote access, due to its clientless browser-based architecture, end-point security, and granular access control. With Array’s site-to-site SSL VPN, administrators no longer need to maintain a separate IPSec system to provide site-to-site connectivity, all secure access can be consolidated on the Array platform to increase security and dramatically reduce IT overhead.

 
Site-to-Site SSL VPN
IPSec VPN
Technology
Export resources to external party with controlled application access through secure SSL tunnel
Provide site-to-site tunnel to connect internal networks
Ease of Deployment
Automated software only option downloads for fast and easy deployment to any location and/or party
Pre-install VPN client or hardware box with IT infrastructure coordination
 
Hide Internal Network
No impact to internal networks; no issue with IP conflicts
IP address or subnet centric; explicit NAT is required for IP conflicts
Fine Grain Access Control
Export resources base on access privilege with local or centralized AAA integration
Open up entire subnets or require multiple FW or security protection
Encryption
Typically stream oriented ciphers – simpler protocol, VPN is proprietary
Usually block oriented ciphers –standardized VPN protocol, but more complex – AH, ESP, Transport mode, tunnel mode
Performance
Array performance equal or better than IPSec
Good
End-Point Validation Schemes
SSL Client certificates / PKI , IP address or network address, machine scan, machine login
Client certificates, IKE, IP / network address, machine login
  • Learn more about site-to-site SSL VPN; download Array’s SiteDirect site-to-site SSL VPN datasheet.
  • For more information, or to request a product demo, contact Array today!
  • View Array’s range of SSL VPN Access Gateway products.