Latest technologies and news that improve your WAN

International links now viable in a Private Network

Until recently, we considered IPSec VPN as the most affordable solution for international links since Internet was so much cheaper. While this is often still the case, the same considerations that we have been discussing, latency, QoS, oversubscription & contention, apply to international links.


    • Since international links and traffic cost carriers and ISPs more, there is a greater tendency to oversubscribe the Internet link giving more variable performance on an IPSec VPN.

    • Voice and interactive traffic such as Citrix and terminal services tend to suffer even more on international VPN links. The driving forces behind one of our customers choosing a global managed MPLS network are Citrix and voice.

    • And if our customers choose to have an international MPLS network with us, there is just the one point of contact, Netforce. You just deal with our help desk, not with a dozen different international carriers with different procedures. The cost of international private links has come down, so consider performing a cost-benefit analysis to see where true savings can be made.

Email us to explore the options with you in context with your specific needs.

Costs

There is a perception that Private networks have higher ongoing costs than IPSec Networks; however, this all depends on the service provider and your situation. Netforce have agreements with a number of providers and we can quote based on different budgets. We can perform a cost benefit analysis to see where true savings can be made. Email us to explore the options with you in context with your specific needs.

Internal Threats in a Private Network

For example, suppose a compromised laptop is brought into a company's branch office, the network becomes infected with a blended threat, it could flood the MPLS link and saturate the connection. Furthermore, the worm could spread to other sites through the WAN causing untold damage across the organisation. In light of these potential threats, the only solution for companies using MPLS technology is to protect the network by isolating traffic before it gets onto the WAN, by deploying a multi-purpose security device at each connection point to the MPLS network.

The necessary protection can be achieved through deploying a security appliance that uses a Unified Threat Management (UTM) approach, which combines multiple security features including firewalling, anti-virus, VPN and intrusion detection and prevention, onto a single hardware platform.

Choices

There are any number of service providers out there in the market. When deciding between service providers (MPLS or IPSec), You need to ask yourself these questions:

The level of network reach and service-level targets
What Class of Service standards are offered
Latency statistics
Packet loss statistics
Jitter for voice and video conferencing. (Ideally, for voice, the jitter should be below 10 ms. For video, it should be below 100 ms. )
Are services such as end-to-end traffic management offered?
How easy is it to increase bandwidth?

Contractual requirements

It used to be more practical to opt for IPSec VPN if you needed temporary network access like a construction site. However, there are new arrangements that make it feasible for you to enter into short term contracts for either MPLS or IPsec VPN.


Summary

In summary, there is no right or wrong choice between MPLS and IPSec VPNs. The choice of whether or not to use an MPLS or IPSec VPN is dependent upon your business needs. Managing risks, controlling costs and providing flexibility and scalability are significant factors when deciding which way you should go.

Best practices indicate companies can meet their site-to-site VPN business requirements with a combination of MPLS & IPSec VPN - e.g., the core network is on MPLS, and the WAN connection points are firewalled with an UTM appliance that also serves as an IPSec gateway for roaming and remote users.
Gartner recommends that businesses should evaluate the opportunity to reduce WAN costs and create a more redundant network by using a hybrid combination of Multiprotocol Label Switching and Internet IP VPNs.

Technology and providers are changing...call us now to perform a cost benefit analysis to see where true savings can be made. We can build a network that incorporates terminations of various last-mile technologies including WiMAX, 3G, ATM, Ethernet, Frame Relay, DSL, fibre, etc into one quality, managed network - either MPLS or IPSec.