Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
TODAY'S NEWS
FBI warns of holiday cyber scams
U.S. Open used Web filtering to prevent online gambling
Google Earth used by terrorists in India attacks
Mumbai terrorist attacks don't deter technology companies
Google layoffs: 10,000 jobs being cut, report claims
Experts to Feds: Sign the DNS root ASAP
Cisco shutting down between holidays
Sprint completes Clearwire WiMAX deal
Mobile sales to beat economic gloom, forecasts Ovum
Start-ups starting to feel economic pain
Spam levels fluctuate as crooks try to revive botnets
Mozilla eyes extra beta for Firefox 3.1
Grim forecast for holiday e-commerce sales
Talking Web, memory assistants and solar-powered cell phones headed mainstream, IBM says
Massive botnet returns from the dead, starts spamming
SMB Networks / Security /

Out of sight, out of mind

Four companies share the tools and strategies they use to secure home offices.

Related linksToday's breaking news
Send to a friendFeedback


Axcelerant's CTO Jeff Christy likes to say, "We treat ourselves like customers." While the managed VPN services provider counts 35 Fortune 1000 companies as customers, it also provides remote access to its 70-plus employees. As such, Axcelerant knows from both angles the challenges network executives face when securing remote offices.

Axcelerant's service includes sophisticated broadband provisioning and security management software combined with a VPN/firewall appliance from NetScreen or SonicWall, or if a software VPN is in place, a firewall device from ZyXel.

"We can architect a secure solution, but the issue comes down to that architecture staying in place and making sure the home users aren't doing something that directly compromises security," Christy says.

Advertisement:

Typical misbehavior includes unplugging or plugging around the VPN appliance, or plugging the system directly into a broadband modem. Teleworkers often try to improve productivity, by sharing a printer between their family machines and their work machine. But Christy has seen numerous situations in which home users want to do things they don't want the company to see.

Educating firms of the dangers is a challenge, too. "Enterprises will tell us, remote users can shut down the VPN as long as they're not connected to the corporate network," he says. "The trouble is, that remote system is a corporate asset, which logs onto specific servers and intranet pages, and Windows caches all those passwords. Once you disable the VPN, all that information is now accessible to hackers."

Two networks in one

SonicWall's new Tele3 Trusted Zone (TZ) addresses this two-network problem, and makes it easier for teleworkers to safely share peripherals and files on a home network. The device includes two physical ports, WorkPort and HomePort. Typically, you attach all the peripherals to HomePort, and only the corporate PC to WorkPort. Then you create a firewall policy between the two interfaces that lets the corporate PC access specific home devices on HomePort, but doesn't let HomePort devices access anything on WorkPort.

Peter Silvo, corporate services manager at storage network company Network Appliance, in Sunnyvale, Calif., relies on Axcelerant's managed VPN service to connect 900 employees' home offices, and recently launched a small pilot program of the Tele3 TZ.

"A lot of people share the connection with a spouse or a roommate, who sometimes works for a competitor. But with the TZ, the work machine is protected. If somebody's kid downloads a virus, only the systems on the HomePort get infected."

Silvo's strategy is to educate and trust his users, and he shores things up so if something happens he can catch it right away.

Double-edged sword

The network director of a large software company in Silicon Valley (who requested anonymity) credits much of his company's success on its ability to hire talent from all over the world. While he, too, contracted with Axcelerant to manage his company's VPN, he still found managing remote workers troublesome.

Although out of sight, remote users were always on his mind. "If an employee and his spouse are hooking their computers together, we could be hooking ourselves up with a competitor and we don't have a lot of control over that. Even though we wrote policies and tried to educate people, we just don't have a lot of control over that kind of behavior."

This network director detected a lot of deviant behavior by watching network traffic, spam and e-mail from unknown sources, but the job was difficult and time-consuming. So when Axcelerant finished the beta-test cycle of its new remote security policy-monitoring program, Scout, his company began a large pilot program.

The Scout agent sits on the remote user's PC and sends an alert to the network if that machine deviates from its security policy. Scout can send the administrator an e-mail or Axcelerant can disable the VPN tunnel.

"My security team's given it the thumbs up," the network director says. "Anyone logging in remotely will have SecureID and the Scout agent running on the system."

Oil and water

For many companies, the combination of Axcelerant's managed VPN service, SonicWall Tele3 TZ and Scout Agent might seem sufficient, even overkill for some. But Schlumberger Network & Infrastructure Solutions, a 75-year old multinational information services firm, has taken a different approach. Because much of the company's work is in oil field services, 5,000 employees are nomads, working for long stretches on oil rigs in remote places.

"By 1982, we'd mapped 80% of the world's well sites, proprietary data we've kept secure for our customers. We've done it with our road warriors, whom we've had to keep linked to our [research and development] groups in metropolitan areas," says Kosta Gioukaris, business development manager for Schlumberger.

The challenge for Schlumberger was how to grant road warriors access to e-mail, applications and time sheets while on oil rigs or traveling. The company developed its own connectivity products, the DeXa Suite of Services. Today, Schlumberger nomads use a variety of remote access technologies, including the company's DeXa.Net VPN services, DeXa.Badge smart card certificate authentication product, and Check Point Software's VPN-1 SecureClient. Some remote workers access server-based applications using products from Neoteris, Tarantella or i-Planet.

Schlumberger's security is based on three policies: All applications are kept on the corporate servers; mandatory use of smart cards to access all PCs, buildings and floors; and certificate authentication challenges at 15-minute intervals.

Gioukaris has little concern for home office security. "The moment you pull the smart card from the reader, the PC no longer has any access to company services. Then employees can use the broadband connection for anything they want," he says.

While workers are generally accepting of the policies, Gioukaris says they've asked to store their password onto a PC so they wouldn't have to type in their username and password so frequently. "But we've enforced it rather stringently," he says.

A Schlumberger employee adds, "It can be distracting at first, but one gets used to it."

Tools of the trade
Particulars on the products and services these firms rely on to secure corporate home offices.
Product Description Benefit
Axcelerant Managed VPN Service Offers broadband provisioning and VPN management for remote corporate networks. Scales well for large telework rollouts. Remote network policy monitoring available.
Check Point VPN-1 SecureClient Software-based VPN. Lets mobile and part-time teleworkers connect to the network from various locations.
Schlumberger DeXa Suite of Services Products and services for securing remote and mobile connections, VPNs, extranets and smart cards. Smart card authentication technology provides system and building security.
SonicWall Tele3 Trusted Zone Security appliance with two physical ports — one for the corporate PC and one for thehome network. Segregates corporate PC from PCs on the home network, yet lets corporate machines access home network resources safely.

RELATED LINKS

Axcelerant

SonicWall

Network Appliance

Schlumberger Network & Infrastructure Solutions

Researchers find problems with RFID passport cards 10/23/2008
EFF, ACLU slam carrier immunity law 10/17/2008
Corporate security and the climate crisis 10/2/2008
Powered by Inform

NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
Click here to sign up!
New Event - WANs: Optimizing Your Network Now.
Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
Attend FREE
Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.
* HOME    * RESEARCH CENTERS     * NEWS     * EVENTS

Contact us | Terms of Service/Privacy | How to Advertise
Reprints and links | Partnerships | Subscribe to NW
About Network World, Inc.

Copyright, 1994-2006 Network World, Inc. All rights reserved.