{"id":6265,"date":"2021-01-29T14:26:22","date_gmt":"2021-01-29T12:26:22","guid":{"rendered":"https:\/\/tekmart.co.za\/t-blog\/?p=6265"},"modified":"2021-01-29T14:26:23","modified_gmt":"2021-01-29T12:26:23","slug":"what-does-a-vpn-concentrator-do","status":"publish","type":"post","link":"https:\/\/tekmart.co.za\/t-blog\/what-does-a-vpn-concentrator-do\/","title":{"rendered":"What does a VPN concentrator do?"},"content":{"rendered":"<span class=\"span-reading-time rt-reading-time\" style=\"display: block;\"><span class=\"rt-label rt-prefix\">Reading Time-approximately:<\/span> <span class=\"rt-time\"> 3<\/span> <span class=\"rt-label rt-postfix\">minutes<\/span><\/span>\n<h2 class=\"wp-block-heading\"><strong>As more employees work remotely and VPN use rises, VPN concentrators have become trendy. But what does a VPN concentrator do exactly, and how do you deploy one?<\/strong><\/h2>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/cdn.ttgtmedia.com\/rms\/onlineImages\/slattery_terry.jpg\" alt=\"Terry Slattery\"\/><\/figure>\n\n\n\n<p>By <a href=\"https:\/\/www.techtarget.com\/contributor\/Terry-Slattery\">Terry Slattery<\/a><\/p>\n\n\n\n<p>Virtual private networks are encrypted tunnels that protect network communications from unauthorized access when the communications must cross untrusted networks, like the internet. <\/p>\n\n\n\n<figure class=\"wp-block-pullquote\"><blockquote><p>VPN concentrators are one component that can enhance VPN connections and remote access. But what does a VPN concentrator do, and what type does your organization need?<\/p><\/blockquote><\/figure>\n\n\n\n<p>VPN concentrators are used to connect many remote networks and clients to a central corporate network. They are used to protect the communications between remote branches or remote clients &#8212; such as workstations, tablets, phones and IoT devices &#8212; to corporate networks. You can think of it as extending the corporate network&#8217;s security boundary out to remote branches or remote computers.<\/p>\n\n\n\n<p>VPN clients, VPN routers and VPN concentrators at each end of the connection perform key negotiation, authentication, encryption and decryption. Encryption has two modes. The first, called\u00a0<em>transport mode<\/em>, encrypts only the data\u00a0payload, leaving the original packet headers intact. <\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>The second method, called\u00a0<em>tunnel mode<\/em>, encrypts the entire packet and encapsulates it in a new IP datagram. Therefore, your VPN security design must start with understanding the\u00a0transport vs. tunnel modes.<\/p><\/blockquote>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>VPN concentrator benefits and costs<\/strong><\/h3>\n\n\n\n<p>VPN concentrators are deployed at the corporate network edge, either just inside the border firewall using a single interface or in parallel with the firewall configured in passthrough mode with an inside and outside interface. Your design details, including\u00a0network address translation\u00a0and vendor recommendations, will provide direction in selecting the preferred topology.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/cdn.ttgtmedia.com\/rms\/onlineimages\/networking-vpn_concentrator-f.png\" alt=\"\"\/><figcaption><strong>This diagram shows a VPN concentrator in the corporate headquarters internet edge demilitarized zone (DMZ).<\/strong><\/figcaption><\/figure>\n\n\n\n<p>You should include a VPN if your organization needs to protect communications between sites or with remote users. Dedicated VPN concentrators become more attractive as the number of VPN connections increases or the aggregate bandwidth grows.<\/p>\n\n\n\n<p>Vendors offer VPN concentrators at a variety of price-performance points. Smaller models may be software-based VMs or container implementations, while the larger models with dedicated encryption hardware can support thousands of VPN tunnels. Your design should incorporate other requirements, like redundancy and load balancing, which will determine how many concentrators are needed, their capacity and their feature sets.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Types of VPN concentrators<\/strong><\/h3>\n\n\n\n<p>Most VPN concentrators are based on a dedicated hardware appliance that is sized for a specified number of VPN connections. You can also find appliances that include dedicated hardware for performing encryption and decryption of large numbers of VPN tunnels.<\/p>\n\n\n\n<figure class=\"wp-block-pullquote\"><blockquote><p>Configurating large numbers of site-to-site IPsec VPNs is tedious and complex but is simplified by using <strong>dynamic multipoint VPN (DMVPN)<\/strong>, a mechanism pioneered by Cisco. Cloud deployments are supported by software-only VPN concentrators that run within VM or container environments.<\/p><\/blockquote><\/figure>\n\n\n\n<p>Organizations with especially tight budgets, multiple remote offices and a motivated staff can take advantage of an open source project to assemble their own VPN concentrator. Some examples include OpenVPN, pfSense, native Linux implementations and VyOS, which includes DMVPN support.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Which VPN protocol is best?<\/strong><\/h3>\n\n\n\n<p>Two primary protocols are used for VPNs: IPsec and Secure Sockets Layer\/Transport Layer Security (SSL\/TLS). Secure Shell (SSH) tunneling is also used &#8212; but rarely. IPsec relies on an OS extension to create the VPN tunnel. It is the preferred mechanism to connect networks between branches and corporate networks.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p>SSL\/TLS is incorporated into the web browser, providing wider availability across more devices than IPsec. It is often preferred for connecting a single host to a corporate network.<\/p><\/blockquote>\n\n\n\n<p>You should understand the\u00a0protocol differences\u00a0and the\u00a0speed, security risks and technology\u00a0when choosing among protocols. Avoid the security mistake of using\u00a0split tunneling\u00a0unless additional protection measures are taken.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>Maintaining good security<\/strong><\/h3>\n\n\n\n<p>A good network security system is constructed from many components &#8212; and VPNs are just one component in the\u00a0overall system. With the prevalence of malware and data loss, such as credit card theft or intellectual property disclosure, you should consider a periodic review of your organization&#8217;s security systems. New security threats emerge on a regular basis, and only good diligence protects your critical assets.<\/p>\n\n\n\n<p>When was the last time you had a security assessment?<\/p>\n","protected":false},"excerpt":{"rendered":"<p><span class=\"span-reading-time rt-reading-time\" style=\"display: block;\"><span class=\"rt-label rt-prefix\">Reading Time-approximately:<\/span> <span class=\"rt-time\"> 3<\/span> <span class=\"rt-label rt-postfix\">minutes<\/span><\/span>As more employees work remotely and VPN use rises, VPN concentrators have become trendy. But what does a VPN concentrator do exactly, and how do you deploy one? By Terry Slattery Virtual private networks are encrypted tunnels that protect network communications from unauthorized access when the communications must cross untrusted networks, like the internet. VPN concentrators are one component that<\/p>\n<p><a class=\"more-link\" href=\"https:\/\/tekmart.co.za\/t-blog\/what-does-a-vpn-concentrator-do\/\">Read More<\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[155,4,30,3,116,195],"tags":[],"class_list":["post-6265","post","type-post","status-publish","format-standard","hentry","category-batting-for-tech-in-the-covid-19-times","category-datacenter-news","category-expert-advise-and-opinion","category-industry-news-and-expert-advise","category-network-security","category-network-visibility"],"_links":{"self":[{"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/posts\/6265","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/comments?post=6265"}],"version-history":[{"count":1,"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/posts\/6265\/revisions"}],"predecessor-version":[{"id":6266,"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/posts\/6265\/revisions\/6266"}],"wp:attachment":[{"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/media?parent=6265"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/categories?post=6265"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/tekmart.co.za\/t-blog\/wp-json\/wp\/v2\/tags?post=6265"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}