VPN Consultants FAQ Security in San Francisco Bay Area

Call Us: (877) 228-4863

rss email us

Contact Us Now:

First Name:
Last Name:
Company:
Phone:
E-Mail:
How can we help you?

VPN Consultants Team in San Francisco Bay Area

We hope that this FAQ compiled by our VPN consultants will help you answer most basic questions. Whatever solution you eventually choose and given the complexity of the issues involved we strongly recommend that you work with VPN consultants or a network security firm, and humbly invite you to contact us for specific VPN questions or for a FREE ON-SITE EVALUATION.

Security Issues#@dlLinkRepPattern@#- VPN FAQ Security Issues10.30318900 1274096742

Are VPNs really secure?
As long as data packets travel on a publicly shared network like Inte .net, they are potential targets for malicious attackers.

VPNs answer that specific problem by multiplying the security mechanisms. The question is "how safe is safe enough?". The most popular VPN protocols have been deemed vulnerable to certain types of attacks. Therefore only VPN solutions that incorporate several mechanisms, from software patches to additional hardware devices and security standards, can make VPNs, if not totally safe, at least safe enough. In this context your main security flaws will be those caused by the VPN users, or VPN consultants, rather than the VPN itself.
Back to FAQ

What are the VPN security standards?
Secure VPNs only apply additional security protocols either to the network "tunnel" or to the data being transmitted in the tunnel. There is currently no universal VPN standard per se. Although the Inte .net Engineering Task Force (IETF) provides an international platform for developers' communities, it can only come up with recommendations more or less implemented, but mostly integrated within proprietary protocols. Among those, popular VPN security protocols such as PPTP, L2TP and IPsec are contending for becoming de-facto standards, each with its strong and weak points, but at this point of time there is no certainty about which will prevail if any.
Back to FAQ

What is strong VPN security?
Technically speaking, VPN security is mainly based on two techniques. Encryption to ensure data integrity and privacy.

Authentication to verify that users have the rights to access the private network and which data they can access. The stronger encryption and authentication mechanisms are, the safer the VPN is. As in real life, often you will have to settle for less freedom and management flexibility when opting for stronger security measures.
Back to FAQ

How do I control VPN user access?
By definition, a VPN generally requires configuration of some sort of access device, either software or hardware-based, to setup a secure channel using private encryption and security parameters. A casual user can't just "use" your VPN, since some knowledge is required to allow the remote user or site access to my network (or even to begin a VPN handshake!). Allowing VPN access only in conjunction with strong authentication also prevents an intruder from successfully authenticating to your network, even if they somehow configured/captured a VPN session.
Back to FAQ

How do I control VPN traffic?
Depending on the VPN solution being implemented, there are a few ways to control the type of traffic sent over a VPN session. Many VPN devices allow you to define a user or group based filter, which can control IP address and protocol/port services allowed through a tunnel. In addition, IPSec-based VPNs allow you to define a list of networks to which traffic can be passed (Security Associations). The first mechanism allows the administrator to limit access to specific networks/machines and applications on her network. The second usually provides fully connectivity to the private network.
Back to FAQ

What is strong encryption? Encryption systems depend on two mechanisms to guarantee data confidentiality. The encryption algorithm provides the mathematical "rules" that convert the plain text message to a random ciphertext message. The algorithm provides steps for convolving the plain text message with an "encryption key," a block of (typically) alphanumeric data that introduces the random element into the ciphertext message. The longer the secret key is, the more time it takes for an attacker to test all possible values of the key - and determine the plain text content of the message. This sort of attack is called a brute force attack. Only strict protocols such as IKE, PKI or ISAKMP can provide enough safety for private data to travel on the Internet. Decrypting one such protected data packet through brute force technique would presumably take a lifetime for an army of computers. But even if that's not the case, it certainly is a must in terms of VPN security.
Back to FAQ

Does encryption affect performance?
The encryption process increases the load on network devices, potentially limiting overall throughput. Since VPN encryption is processed up to 10baseT speeds, on connections like dial-up modems VPN encryption is too fast to even be noticed compared to Inte .net delays. Most performance slowdowns will in fact result from inconsistent Inte .net connections rather than by encryption processing overhead. VPN systems that compress encrypted data before sending them may even slightly
improve connections in specific cases. For noncompressing VPN clients the average decrease in network traffic performance hovers around 20%. For usual applications, such as web browsing and e-mail, this is negligible. But interactive applications, such as virtual terminals may experiment as much as a 60% increase in network latency. Setting aside connection performance problems, a 100Mb/s LAN can experience serious traffic slow-downs, especially if remote users frequently access local applications or transfer large amount of data. In other words, If you put a VPN into your network, be prepared to see quite a bit, and sometimes a lot of bandwidth disappear.
Back to FAQ

What is strong authentication?
Many methods exist to provide user authentication. Usually one is not enough while integrating several of them can prove cumbersome, or simply unfeasible. Also keep in mind that the "weakest link" in the VPN fence remain the users themselves. Most VPN systems include local authentication, which looks up user information in a database stored on the VPN device or VPN management station, but you should probably also provide a gateway to some external authentication database to
avoid creating yet another password for users to forget. In the absence of official standard a consensus has been built around RADIUS (Remote Authentication Dial-In User Service) as the best network-based authentication gateway available. RADIUS servers provide an additional layer of security to Windows-based security policies as well as of other systems using tokens or smart cards, such as SecurID or Cryptocard.
Back to FAQ

ActivSupport delivers consulting and outsourcing services across Microsoft, Linux, and Macintosh networks to small businesses and enterprises alike all over the U.S. For a free consultation call ActivSupport at 1-877-ACTIVNET (1-877-228-4863) or use our online contact form.

 

Case Studies

  • HDD Backup Solution with Remote Storage & Management A recent study discovered that, of companies experiencing a “major loss” of computer records, 43 percent never reopened, 51 percent closed within two years of the loss, and a mere 6 percent survived over the long-term For small and medium-sized businesses (SMB’s) in particular, these statistics suggest the necessity of crafting a Business Continuity Planning (BCP) strategy grounded in a robust data backup and recovery solution. Unlike enterprises, many smaller companies cannot afford optimal in-house strategies and solutions in service of BCP. These companies are consequently at an elevated risk of being put out of business due to any major loss of data. Read the study, and find out more about ActivSupport's answer to this challenge.
  • Information Technology Industry
  • Legal Industry
  • Insurance Industry
  • Financial Industry

Other News

  • ActivSupport Sponsors Collective Roots in Palo Alto
  • ActivSupport joins 1% For The Planet
  • Search Engine Optimization Services
  • Advanced Disaster Recovery Solution ActivSupport is proud to introduce ActiVault, a state of the art data backup and disaster recovery Solution that “bullet proofs” your data, and virtualize your environment for immediate access in the event of servers disaster. ActiVault is available in San Francisco, Los Angeles, New York, and anywhere in the continental U.S. We offer a pricing packaged that is all inclusive of the complete backup and disaster recovery service-with no hidden costs. All your costs are bundled and include the NAS, the Incremental Forever Methodology, file restorations, file integrity checks, secure data transmission and remote storage. Cost is comparable and often less than older tape backup and tape library solutions.
  • VoIP Consulting ActivSupport entered the small business phone systems and now provides VoIP consulting in the San Francisco Bay Area with a comprehensive VOIP offering featuring a select pool of voice and data carriers as well as a suite of telephone systems taylored to the small business needs. ActivSupport is now positioned to provide a range of comprehensive small business phone systems solutions, along with the appropriate connectivity and ongoing support plans thanks to over a decade of experience in the data networking market, addition of voice veterans to our technical staff, and training of our data expert staff.