Secure site-to-site connectivity traditionally implies frame relay, leased line and IPSec deployments. While frame relay and leased line connections are very secure, they are also very expensive – hence the explosion in IPSec deployments, which leverage encryption and the ubiquity of the Internet to create cost-effective and secure multi-site virtual private networks.
For all of its advantages, IPSec retains distinct disadvantages; the most notable being that it provides only an encrypted connection. In common deployments, two or more sites must be connected to allow key applications to communicate, to provide business partners access to a select set of resources, or to allow collaboration for given business units. With IPSec, this can be achieved, but at the expense of exposing the entire network on both ends of the connection.
To address this security gap, administrators must configure extensive ACLs and security policies to ensure only authorized users access authorized resources. With IPSec, this process is time-consuming, error-prone and often disregarded – at great risk to an organization’s well being.
Array Site-to-Site SSL VPN
- Encryption plus granular access control
- Dramatically reduced administration and IT overhead
- Remote access and site-to-site connectivity on a single platform
Array site-to-site SSL VPN access solutions provide all the benefits of traditional IPSec site-to-site connectivity and go above and beyond, introducing granular access control and the ability to connect sites at the network, host, and application level.

Application and Host Level Access
With site-to-site SSL VPN, organizations requiring site-to-site connectivity to enable communication between business critical applications can establish permanent connections that enable only key applications or host servers to communicate – eliminating the need for complex ACLs and eliminating unwanted network exposure and associated security risks.
Network Level Access
At the network level, Array site-to-site SSL VPN provides all the performance and functionality of traditional IPSec connectivity, but with distinct advantages. SSL VPN network separation and NAT capability enables administrators to connect subnets within networks, such that engineering at headquarters is restricted to communicating with engineering at a remote site. No additional ACLs or security policies are required to prevent user communities from viewing or accessing resources or networks for which they are not unauthorized.
Secure Access Consolidation
An added benefit of site-to-site SSL VPN is the ability to consolidate both remote access and site-to-site access on a single platform. SSL VPN is the technology of choice for remote access, due to its clientless browser-based architecture, end-point security, and granular access control. With Array’s site-to-site SSL VPN, administrators no longer need to maintain a separate IPSec system to provide site-to-site connectivity, all secure access can be consolidated on the Array platform to increase security and dramatically reduce IT overhead.
|
|
Site-to-Site SSL VPN
|
IPSec VPN
|
|
Technology
|
Export resources to external party with controlled application access through secure SSL tunnel
|
Provide site-to-site tunnel to connect internal networks
|
|
Ease of Deployment
|
Automated software only option downloads for fast and easy deployment to any location and/or party
|
Pre-install VPN client or hardware box with IT infrastructure coordination
|
|
Hide Internal Network
|
No impact to internal networks; no issue with IP conflicts
|
IP address or subnet centric; explicit NAT is required for IP conflicts
|
|
Fine Grain Access Control
|
Export resources base on access privilege with local or centralized AAA integration
|
Open up entire subnets or require multiple FW or security protection
|
|
Encryption
|
Typically stream oriented ciphers – simpler protocol, VPN is proprietary
|
Usually block oriented ciphers –standardized VPN protocol, but more complex – AH, ESP, Transport mode, tunnel mode
|
|
Performance
|
Array performance equal or better than IPSec
|
Good
|
|
End-Point Validation Schemes
|
SSL Client certificates / PKI , IP address or network address, machine scan, machine login
|
Client certificates, IKE, IP / network address, machine login
|
- APV Series Datasheet
Application Delivery Controllers
(PDF – 1.28MB)

- DesktopDirect Datasheet
Remote Desktop Access
(PDF - 404 KB)

- SPX Series Datasheet
Universal Access Controllers
(PDF - 789KB)
- Toll Free in US:
1.866.MY ARRAY
1.866.692 7729 - Outside the US:
1.408.240.8700 - Email Sales

