- Cool Yule Tools: 2008 Holiday Gift Guide
- 10 kitchen gadgets for the geek gourmet
- Google admits to violating iPhone development terms
- Smartphone smackdown: Storm vs. iPhone
- Google layoffs: 10,000 jobs being cut
Application-layer VPNs are generating lots of attention these days. Proponents cite the technology's ability to provide secure remote access to a broad spectrum of applications and network resources. But what exactly are application-layer VPNs, and how do they differ from traditional VPNs?
Unlike traditional IP Security (IPSec)-based VPNs, which operate at Layer 3 (the network layer) of the Open Systems Interconnection model, application-layer VPNs operate at Layer 7 (the application layer). Operating at Layer 7 provides visibility into application data, giving network administrators new opportunities to enforce security policy for remote application access.
The central element of an application-layer VPN is the application-layer proxy, typically provided in the form of a dedicated network appliance. The proxy offers a single point of administration while acting as a sentinel to the private network behind the firewall.
An application-layer VPN acts as an intermediary between remote client requests and server-based applications. It terminates incoming connections from remote users at the application layer, processes the data and then translates the data to the appropriate application protocol. During this termination gap, the VPN analyzes application information, applies security policy and serves as a gatekeeper between the Internet and the private network.
An application-layer VPN runs client and server versions of an application on a single server, eliminating the need for a client on the remote PC. For Windows applications, client and server versions are installed on a Windows Terminal Server, which uses Microsoft Remote Desktop Protocol (RDP) to negotiate the remote user's input with the application's responses.
Partner Content
Brilliantly simple security and control solutions for email, web and endpoint
www.sophos.com
Stopping data leakage
Learn how to exploit your current security investment to control the information that flows into, through and out of your network.
Download the white paper.
Why detection rates aren't enough
Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.
Download the white paper.
Applications: taking back control
Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.
Learn more today.
Comment