home
NEWS       BLOGS       FORUMS       NEWSLETTERS       RESEARCH       EVENTS       DIGITAL LIBRARY       CAREERS  
Network Computing Network Computing Powered by InformationWeek Business Technology Network

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers


Infrastructure
W O R K S H O P  
Our Long and Winding Road to VPN

  January 21, 2002
  By Mike Fratto


Printer Print Full Article
Printer Print This Page
Printer Download the PDF
E-Mail E-Mail This URL

For many years Network Computing's Real-World Labs® have been interconnected over fractional T1 lines. With those T1s, we have used frame relay for Layer 2 support. However, the monthly charges for frame relay had been rather high, and we were paying for Internet access. At the time we didn't think the monthly frame relay costs were likely to drop, so we decided to move from frame relay to a VPN (virtual private network). Of course, we have another, less tangible motivation: credibility. We've recommended that you move all your traffic to a VPN and use the Internet as a backbone while we've stuck to frame relay. Well, you can talk out of both sides of your mouth for only so long.



Our WAN contract with our service provider was up, and pricing for the frame relay connections had increased to the point where buying our own equipment and moving to less pricey DSL circuits just made sense, so we decided to move our interlab traffic to a VPN. Although we aren't running what some would consider a critical WAN network, we do use our WAN connections every day, and loss of connectivity means downtime. We've expanded our Real-World Labs® to new locations, and incorporating frame relay into a dynamic environment is tricky. Plus we want more control over our networks and to build in some perimeter security. Finally, we need to support our editors who telecommute or travel for the publication.

We started the migration project in July 2000 with the expectation that the entire changeover would take several months. Like many IT projects, though, ours has taken much longer than expected--primarily because of organizational and not technical issues.

In our frame relay environment (see "Pre-VPN Network"), our interlab traffic passed over the frame, which was fine for most traffic. However, when we started shoving files around the frame, performance suffered. We also had some support issues, especially when we needed to have our ISP-owned routers configured. Some simple configuration changes would cut off one or more of the labs for hours to days at a time. We needed more control over our network.

Our plan was to move to local broadband for all the sites except the Syracuse University and the University of Wisconsin labs--these both use their host networks' existing Internet connections. During the transition, the Syracuse University, University of Wisconsin and the Washington, D.C., labs are connected via a VPN using equipment from NetScreen Technologies. The other labs access internal resources over the Internet. Unfortunately, at one point over the course of our migration, two of our labs were cut off from the Internet when their DSL carriers closed operations, and we had to scramble to replace our broadband connections.

Network Computing's Web site currently is hosted by cerf.net. Editors at our corporate offices use Lotus Notes. But the technical editorial team is distributed across the country, and many of these editors don't use Notes. Therefore, we are focused on supporting these users. Our production servers, such as SMTP, DNS and file stores, are hosted in Syracuse; backup servers are in the Washington lab.

We decided that our goal migration scenario, in which the local provider serves up basic connectivity and bandwidth and we take care of security by placing firewalls at each perimeter, puts us in a much better position for maintaining our own infrastructure. We selected firewalls from the Nokia IP line and software for the VPN and firewalls from Check Point Software Technologies' VPN-1 line, because these products are relatively simple to install. We have tested both sets and are confident they will work well with our network and application needs.

Our goal is simple: Protect our labs from the Internet using a firewall and connect all the labs over the Internet using IPsec VPN. But as with any sites, ours have some special needs.

We want to be able to add and remove new labs from the VPN easily. And, as mentioned, we need to support our remote and mobile editorial staff. Our broadband connections are "business class," meaning that we have a handful of static IP addresses. Lot of good that does us, though, as none of the broadband service providers are willing to advertise our Class C subnets. With these issues in mind, we developed an architecture to fit our current needs and included considerations for future expansion.


   Page: 1 | 2 | 3 | Next Page





Ready to take that job and shove it?

Function:

Keyword(s):

State:
SPONSOR
RECENT JOB POSTINGS
CAREER NEWS
Go beyond Google and get vertical. These specialized search sites will help you find the business information you need -- fast.

Ari Balogh was named to the post of chief technology officer as the companys for a "realignment" of employees.










InformationWeek U.S. IT Salary Survey 2008
Salaries for business technology professionals are falling. Here's what you need to know in order to make good hiring decisions and personal career choices. Download Today
 
ROLLING RIGHT ALONG
Follow key Network Computing Reviews from conception to completion. This Week: Holistic APM.



Network Computing Reports Emerging Enterprise Podcast Series: Secrets to Success








TechSearch


Microsite of the Week


Powerful Information at Your Fingertips



Techweb
IWKBTN
InformationweekInformationweek 500Informationweek 500 ConferenceInformationweek AnalyticsInformationweek Events
Informationweek ReportsInformationweek MagazinebMightyByte and SwitchDark ReadingDigital Library
Intelligent EnterpriseInternet EvolutionNetwork ComputingPlug Into The CloudDr. Dobbs
space
Techweb Events Network
InteropVoiceConWeb 2.0 ExpoWeb 2.0 SummitEnterprise 2.0Mobile Business ExpoSoftware ConferenceNoJitterMobile Connect
Black HatGTECEnergy CampMashup CampStartup CampCloud Connect
space
Light Reading Communications Network
Light ReadingLight Reading EuropeUnstrungCable Digital NewsConstantinopleInternet EvolutionPyramid Research
Heavy ReadingLight Reading LiveLight Reading InsiderEthrnet ExpoOptical ExpoTelco TVTower Technology Summit
space
Financial Technology Network
Advanced TradingBank Systems and TechnologyInsurance and TechnologyWall Street and TechnologyAccelerating WallstreetBST SummitBuyside Trading SummitIT Summit
space
Microsoft Technology Network
MSDNTechNetTotal IT ProTotal Dev Pro
space


App Infrastructure   |   Messaging & Collaboration   |   Network & Systems Mgmt   |   Network Infrastructure   |   Security  |   Storage & Servers   |   Wireless   |   Enterprise Apps
About Us  |  Contact Us  |  Site Map  |  Technology Marketing Solutions  |  Advertising Contacts  |   Briefing Centers
Copyright © 2009  United Business Media LLC  |  Privacy Statement  |  Terms of Service  |  Your California Privacy Rights