SSi Service Strategies Inc.

IPSec VPN

Home
Up
VPN Client
Contact SSi
Site Contents
Glossary of Terms
Request Information
Site Search
Notices

 

SSi

IPSec VPN Network Security Feature

IPSec VPN Security Feature The IPSec VPN feature provides secure, encrypted communication to business partners and remote offices at a fraction of the cost of dedicated leased lines. Using the SonicWALL's intuitive Web Management Interface, you can quickly create a VPN security association to a remote site. Whenever data is intended for the remote site, the SonicWALL automatically encrypts the data and sends it over the Internet to the remote site, where it is decrypted and forwarded to the intended destination.

IPSec VPN Applications

bullet

Linking Two or More Networks Together
SonicWALL VPN is the perfect way for you to connect to your branch offices and business partners over the Internet. SonicWALL VPN offers an affordable, high-performance alternative to leased site-to-site lines. If NAT is enabled, SonicWALL VPN also provides access to remote devices that have been assigned private IP addresses.
 

bullet

Remotely Managing the SonicWALL
The SonicWALL PRO 330, the SonicWALL GX Series and the SonicWALL VPN Upgrade include a free VPN client for remote administration. The SonicWALL VPN client, installed on Windows 95, 98, NT, and 2000, allows you securely manage the SonicWALL over the Internet.
 

bullet

Accessing Network Resources from a VPN Client
VPN client remote access allows your employees to connect to your network from any location. The VPN client remote access solution is easy to deploy and supports hundreds of remote users. The SonicWALL PRO 330 includes 50 VPN client licenses for remote access.

 

VPN Diagram

 

IPSec VPN Features and Benefits

Interoperable IPSec VPN Implementation.
SonicWALL VPN is based on the IPSec standard for VPN, so it's compatible with other VPN products with the same IPSec implementation, such as Check Point Firewall-1, Cisco PIX, Nortel Contivity and Axent Raptor.

Seamless Support of Windows Networking.
VPN tunnels between two appliances can pass Windows Networking broadcasts, which support Windows Network Neighborhood. Users can then view both local and remote network resources in the same Windows Network Neighborhood.

VPN Client for Secure Dial-Up Access.
The SonicWALL Global VPN Client allows your organization to include dial-up Internet users into the VPN. The Client supports Windows 95, 98, NT and 2000. The SonicWALL group VPN tunnel feature simplifies deployment of VPN clients by allowing distribution of a common VPN client configuration to remote users.

3rd Party Digital Certificate Support
A digital certificate is an electronic means to verify identity by a trusted third party known as a Certificate Authority (CA). SonicWALL now supports third party certificates in addition to the existing Authentication Service. The difference between third party certificates and the SonicWALL Authentication Service is the ability to select the source for your CA certificate.

DHCP Over VPN
In some network deployments, it is desirable to have all VPN networks on one logical IP subnet, and create the appearance of all VPN networks residing in one IP subnet address space. This facilitates IP address administration for the networks using VPN tunnels. DHCP over VPN is a feature that allows a Host (DHCP Client) behind a SonicWALL to obtain an IP address lease from a DHCP server at the other end of a VPN tunnel.

VPN Bandwidth Management
A VPN Security Associations can be allocated bandwidth if bandwidth management is enabled for the SA.

NAT Traversal Support
VPN NAT Traversal is a feature designed to overcome problems faced when IPSec traffic is intended to pass through a NAT device. NAT Traversal addresses the problem by wrapping an IPSec packet inside a UDP packet when a NAT or NAPT (Network Address Port Translator) device is detected between peers.

Single-Arm Mode
Enables the SonicWALL security appliance to connect via the WAN interface onto a subnet with an existing firewall and process all VPN traffic, removing the burden of encryption/decryption from the Internet access firewall. A dedicated SonicWALL VPN solution easily integrates with existing firewalls, increases security policy enforcement through VPN tunnels, and delivers flexible VPN options to customers of all sizes.

RIP Advertising
RIP Advertising dynamically advertises updated VPN and static routing information to the internal network, reducing the risk of misroutes and ensuring reliable connectivity to critical resources. Supports both RIPv1 and RIPv2.

AES Support
Support for Advanced Encryption Standard (AES) encryption algorithm, the next-generation encryption standard, and underlines SonicWALL’s commitment to next-generation open security standards.

User Level Authentication
User Level Authentication (ULA) controls VPN access at the user level, giving businesses more control of VPN access by remote employees, contractors and partners

SonicWALL Global Management System (GMS).
Large, distributed enterprises and service providers can centrally manage and monitor hundreds of SonicWALL VPN deployments using SonicWALL GMS

To learn more about SonicWALL's VPN capabilities, please visit our web site dedicated to VPN by clicking here.

If you would like to request additional information on a network security product or service, please click on the button below.

Certified SonicWALL Sales Experts

Service Strategies Inc.

2392 Mount Vernon Rd

Dunwoody, GA 30338-3092

678-441-0020   800-662-1615

assist@ssimail.com

Copyright © 1998 - 2008 Service Strategies Inc. All rights reserved.
Revised: February 01, 2008.