VPN & WAN Over Internet

Solution Overview

Our work environment is turning increasingly mobile. And with this development, demands have become multifaceted: We need more than just the ability to send and receive emails on the move. We need to be able to call up and process all types of information from the company’s Intranet, e.g. need to have the ability to communicate data between two discrete PCs (M2M - machine to machine).


Telecommuters and mobile employees, branch offices and subsidiaries - all need to be integrated into the organization's network. In many cases, business partners and even clients need to be able to access the network to some degree. Data acquisition from stationary and mobile data loggers and the transfer of control and operational data to a centralized data network has become an increasingly important issue for many organizations.

All these scenarios utilize the Internet for data transfer - e.g. public networks, which only offer rudimentary or very little security mechanisms. End-to-end security in these public networks can only be realized on the basis of VPN tunneling technology.

 

Examples for remote access applications:

  • Email download and editing
  • File server access for e.g. editing a Word or PowerPoint file
  • Access to host data, e.g. 3270 emulation
  • Access to Citrix servers
  • SAP data exchange
  • Access to central database
  • Inventory management via barcode readers/ERP (Enterprise Resource Planning) integration
  • Downloading operational and maintenance data
  • Transmission of control data

VPN Solutions & Consulting

  • ACE-VPN solutions can be designed to meet the performance requirements of organizations of any size, including small businesses, and larger enterprises.

  • VPN over Internet can offer secure and cost-effective alternatives to expensive, low-bandwidth dedicated circuits to connect multiple offices across the public Internet.

  • Numerous hardware and software products can be combined to meet your organizations custom connectivity needs.

WatchGuard VPN 

Virtual Private Networking (VPN) enables businesses to deliver secure, encrypted connectivity for traveling employees, remote offices, and telecommuters who require access to critical corporate network resources like e-mail, network drives, and intranet resources. WatchGuard offers two VPN options:

Mobile User VPN (MUVPN) enables telecommuters and traveling employees to access the corporate network while maintaining privacy and security. Remote users remain protected with Firebox X's MUVPN solution integrated with desktop firewall software.

Branch office VPN (BOVPN) enables businesses that require secure communication between geographically separated offices. These communications often contain the types of critical data exchanged inside the corporate firewall. In this scenario, a BOVPN ensures confidential connections between these offices, streamlining communication, reducing the cost of dedicated lines and retaining security at each end.

When you purchase a WatchGuard firewall/VPN appliance, you get:

  • IPSec technology for superior protection and interoperability with other IPSec compliant VPN devices.
  • Intuitive setup wizards for quick remote access deployment for traveling employees.
  • Protection for remote offices and telecommuter sites with Branch Office VPN connections that you can create between any WatchGuard Firebox appliances. 

WatchGuard® appliances include the following Mobile and Branch Office VPN capability:

  Mobile User VPN Branch Office VPN with IPSec
PPTP Client SafeNet® Client
Firebox® X Yes Yes Yes (Optional for Firebox X500)
Firebox® SOHO 6 Yes Optional Optional
Firebox® X Edge   Yes Yes

WatchGuard System Manager
Intuitive, centralized management:

The Firebox X500, X700, X1000 and X2500 include a 4-device management license of WatchGuard System Manager (WSM).
  • Manage the configuration of mobile user and branch office VPN connections through a single centralized interface using 3-step drag-n-drop VPN wizards; save time and lower the complexity of managing your VPN connections.
  • View real-time status of which users and offices are connected and authenticated via VPN; always know what's happening with your network.
  • Log activity and run reports on VPN usage; keep informed about how your VPNs are utilized.
Firebox® X secures your central network while Firebox X Edge models extend that protection to your remote office. Their VPNs integrate to provide centralized management, logging, and historical reporting for securing your telecommuters and remote offices.

VPN Diagram

WatchGuard VPN Specifications
Configuration Easy point-and-click with VPN Manager, or manual configuration
Encryption RSA RC4 standard, DES or 3DES-CBC
Encryption Algorithm MD5-HMAC, SHA1-HMAC, DES-CBC 56-bit encryption, Internet Key Exchange (IKE)
Manual Key Negotiation, Phase I Negotiation
WatchGuard Proprietary Tunnel Encryption RSA 40-bit encryption
RSA RC4-128-bit encryption
Remote User PPTP Tunnel RSA 40-bit encryption
RSA RC4 128-bit encryption
Remote User IPSec Tunnel DES-CBC 168-bit encryption
IPSec passthrough (Firebox SOHO models)
Authentication and Key management WatchGuard Firewall Authentication
User Authentication Remote User VPN: MS-CHAP
Mobile User VPN: MD5 or SHA1
Mobile User VPN Client Microsoft® Windows® 98/2000/XP and Windows NT® 4.0 workstations
Maximum IPSec VPN Tunnels
Firebox® X500 0 Branch Office VPNs
(Upgradeable to 50)
50 Mobile User VPNs
Firebox® X700 100 Branch Office VPNs
100 Mobile User VPNs
Firebox® X1000 500 Branch Office VPNs
1000 Mobile User VPNs
Firebox® X2500 1000 Branch Office VPNs
1000 Mobile User VPNs
Firebox® X5/X5w 2 Branch Office VPNs
11 Mobile User VPNs
Firebox® X15/X15w 15 Branch Office VPNs
25 Mobile User VPNs
Firebox® X50/X50w 25 Branch Office VPNs
50 Mobile User VPNs
Firebox® SOHO 6tc and SOHO 6 SOHO 6tc: 6 Branch Office VPNs
10 Mobile User VPNs (Optional, available in 5-user packs)
SOHO 6: 6 Branch Office VPNs (Available through optional purchase)
10 Mobile User VPNs (Optional, available in 5-user packs)
Firebox® SOHO 6tc Wireless and SOHO 6 Wireless SOHO 6tc Wireless: 6 Branch Office VPNs
11 Mobile User VPNs (1 included, upgradeable in 5-user packs)
SOHO 6 Wireless: 6 Branch Office VPNs (Available through optional purchase)
11 Mobile User VPNs (1 included, upgradeable in 5-user packs)
Firebox® 4500 3000*
Firebox® 2500 2000*
Firebox® 1000 1300*
Firebox® 700 150*
Firebox® 500 50 (Mobile User VPNs only)
The Internet Engineering Task Force (IETF) developed the Internet Protocol Security (IPSec) protocol suite to deliver security services at the network level. IPSec functionality is based on modern cryptographic technologies, providing extremely strong data authentication and privacy. IPSec makes it possible to create a secure communications tunnel over the Internet, and IPSec standards allow interoperability between VPN solutions.

*The total number of Branch Office plus Mobile User VPN tunnels.

 

 

Firewall / VPN Technology

NCP VPN

WatchGuard Technologies