Reviews - Channel Insider
Empowering the next generation Channel
 

Sponsored Links
  • Get up and running in as quickly as 30 days with BI. Learn how today.
  • FREE Securing Smartphones & Tablets for Dummies Book from Sophos
  • 5 New Technologies That Will Change Enterprise ITAdvertisement
  • Build an IT Infrastructure That Delivers the Future

  •  

    VOIP Versus Net Security

    in Reviews



    Article Rating:starstarstarstarstar / 0
    Article Views: 2058

    Review: Tests show that SSL VPNs can coexist with voice over IP.

    Rate This Article:
    Add This Article To:

    There are no two ways about it: Network security complicates voice-over-IP implementations.

    But in tests at eWEEK Labs, we have seen that it is possible for VOIP to coexist at least with Secure Sockets Layer VPN security technology.

    Typically, SSL VPN products enable an encrypted, user-initiated connection to a network resource, such as a file share or an e-mail server.

    Using the nearly ubiquitous SSL tunneling capability included in almost every Web browser, users can make secure connections without the installation of any additional software on the client.

    However, SSL VPNs that support VOIP usually do so with either a client shim, in the form of an ActiveX or a Java-based component, or a piece of client software provided by the SSL VPN vendor.

    A good example of this is Aventail's network tunnel service, which uses either an installed client (usually deployed like any other piece of corporate software, as part of an image) or an on-demand shim that is downloaded by the browser when a session is initiated.

    Group Dynamics

    To ensure a successful implementation of VOIP that will traverse SSL VPNs, one of the most important things to keep in mind is access policy creation and maintenance.

    The best policy tools for VOIP govern groups rather than individual users.

    We recommend looking for SSL VPN tools that can dynamically assign users to groups based on attributes that are determined by administrators during initial registration. Also look for tools that allow changes to be made at a group level.

    For example, only members of the group called "sales" are allowed to make outgoing long-distance calls, or members of the group called "public lobby" are allowed to call only internal phone numbers.

    We got a dose of what it means to be thorough in access-policy creation during our recent tests of SSL VPNs from Aventail and F5 Networks, when we evaluated the products' ability to work with VOIP.

    Click here to read more about SSL VPNs.

    During one test, we were able to use a softphone to ring in through Digium's Asterisk-based Trixbox system.

    However, we could hear only one end of the conversation because we had failed to create a policy that allowed the other end to travel over our network.)

    Also making VOIP over SSL VPNs tricky are the security deficiencies in the VOIP protocol itself.

    An SSL VPN implementation can overcome some of these security weaknesses, however, by encrypting communication among clients and between clients and the server.

    This security covers the data portion of the voice packet, preventing exploits that sniff a message as it passes along the public network.

    In addition, by using an SSL VPN to facilitate an authenticated and allowed connection to protected VOIP network resources, some client registration hijack attacks can be prevented.

    It's clear from eWEEK Labs' initial testing that all of the aforementioned configuration concerns can be overcome with current technology.

    Network managers should leverage policy settings in SSL VPN tools, along with other proxy devices and firewalls that support the bidirectional session initiation required by VOIP technology.

    Technical Director Cameron Sturdevant can be reached at cameron_sturdevant@ziffdavis.com.

    Check out eWEEK.com's for the latest news, views and analysis on voice over IP and telephony.




    comments dic


     
     
    >>> More Reviews Articles          >>> More By Channel Insider Staff
     


     



    channel chatter


    HTML PLAIN TEXT

    Keep on top of news for VARs and Resellers with CI's Weekly Newsletter and Alerts.


    [ci] feeds
    XML
    Add Channel News, Product Reviews, Trends and Analysis to your RSS newsreader or My Yahoo!


     


    CHANNEL SPONSORED RESOURCE CENTER
     
     
     
    Start the New Year with business intelligence—it’s a smart move
    Join us on February 1 for an encore rebroadcast at either 5 am or 12 noon EST and discover how business intelligence (BI) supports companies in uncertain business and economic climates. Get expert advice on how to create a strategy that fits your organization's needs and budget and see how quickly it can pay for itself.
    Click Here
     
    Security and Availability Essentials for Running Your Business in the Cloud
    Are you moving to the cloud? Find out what every IT professional should know about security and availability before moving to the cloud. Hear what a security provider’s own CSO has to say.
    Watch Video
    A new algorithm automatically identifies relationships between variables to help reduce researcher prejudice.
    Click HereAdvertisement