(as published in Itworldcanada.ca)
http://www.itworldcanada.com/blog/the-demise-of-excess-access-a-eulogy-for-traditional-vpn/96655
Once upon a time, in a world where mobile meant "laptop" or "remote home PC", Corporate network connectivity came in two flavours: 1) Dial-up modem, with it's clunky protocols and achingly slow speeds, and 2) Corporate VPN client over Internet.
Internet VPN seemed like a godsend in comparison to Dial-up. Basically it's purpose was to provide a secure network connection between your remote PC/Laptop (the entire device) and your Corporate network. Whether old-school IPSec or the more recent SSL encapulation, the transport was secured. Username/password, and optionally a One Time password or Security Token would be used to provide Two Factor Authentication (2fa).
Seems secure? Right? I mean, authentication and transport security are covered.. what else is there?
Dynamic Access Policies were then created to define a set of rules, similar to firewall rules, that describe what applications (port/protocol) on the remote users PC could talk to what servers/services in the data center.
In general, this worked fine if there were less than a hundred employees in the company, you had no third party users, no application was ever upgraded, and nobody changed roles.
In practice, policies are defined loosely to allow for Convenience rather than Security. Realistically, large numbers of PC's have unfettered access to the corporate network, as if they were sitting at their desk. (We'll get into THAT issue in a future blog.)
Well then we started worrying about Viruses, worms, trojans... basically Malware residing on the remote PC. What stops them from propagating into the corporate network? How do we know the end user has applied all the appropriate patches, and is running the most current AntiMalware (And that it's signatures are up to date!)?
Network Access Control was added to the VPN client to assess the endpoint (laptop or PC) and determine it's "security posture" based on patch status and running AntiMalware applications.
But this wasn't enough to satisfy the Audit or Risk departments, so you had to install Intrusion prevention appliances and network anti-malware inside the network to remediate anything that was missed on the endpoint...
AND... we still have all those remote endpoints, with pretty much open access to our entire corporate network...
In the meantime...
As a result of the explosion of Tablets and smart phones, alternate solutions arose for many of the very services we require daily as part of our VPN dependency. An entire industry arose to service BYOD or Bring Your Own Device. Tablets and Smart phones are managed through various means, but typically now applications running on those devices are segregated or "sandboxed" from one another to reduce the risk of eavesdropping and data capture.
The Future of Enterprise Remote Connectivity:
Today, there is absolutely NO REASON to use VPN for your Corporate Email service. All enterprise grade email clients utilize strong local authentication, integrate with industry standard Single Sign On, and use strong transport encryption. Whether you are an Exchange/Outlook or Domino/Notes user, for this use case, VPN is merely a hindrance to productivity, and a complexity that costs your company both in Capex and Opex.
Similarly, there is absolutely NO REASON to use VPN for your Corporate VOIP or Instant messaging. These services also integrate cleanly into Enterprise Single Sign On, and provide for secured, encrypted transport.
If you NEED, and I stress NEED, a corporate desktop, then there are many highly secure NON VPN solutions available, such as Microsoft's Remote Desktop Gateway, Citrix Access Gateway, or VDI via VMWare's Horizon View. Some Legacy Applications may still require this model for a few years to come.
Are you using Cloud Services through VPN? If you are using VPN to get to your corporate Cloud applications like SalesForce, SAP, Concur,ServiceNow, Microsoft Office 365, or Taleo, you are simply adding an extra network loop to an already secured connection. These services already use Enterprise Single Sign On, and provide for secured, encrypted transport.
Containerization technologies like Bromium will transform application development for the laptop environment, and allow Laptops to join the realm of Managed Devices in a Mobile Device Strategy. Soon your Enterprise Mobile Application Management suite will package and manage apps for Windows and OSX as well as iOS, Blackberry and Android.
Write Once, Run Anywhere has been a mantra used by vendors such as Oracle for well over a decade. It is finally approaching a maturity level that will see it in action everywhere. Most large applications today are being developed using frameworks that abstract the presentation layer, and allow the designers to write various "front ends" specific to the device, while the rest of the application is identical across platforms.
So aren't you just replacing one remote access solution with several niche appliances?
In a quick answer, sort of... Service specific appliances, such as SIP gateways provide a much more robust and secure means on managing this specific traffic, and many companies already have them in place for internal branch to branch connectivity.
I'm not suggesting that the future of remote connectivity is free and unfettered access to your Corporate Network. Quite the opposite in fact. I'm suggesting that 2/3 of what employees access today via traditional VPN, already has BETTER and MORE SECURE means of connectivity through their native infrastructure, and that the remaining 1/3 is on track to be replaced with technologies that will allow the remote applications to be secured on any device from phone to tablet to laptop.
In today's world of high profile Data Breaches, Zero Day Attacks, and Significant Operating System vulnerabilities, we cannot allow the Excess Access that traditional VPN affords.
References:
WindowsSecurity.com: Death of VPN
VPN Clients are Dead in the Cloud
The Evolution …. and Death of the VPN
The Death of the VPN
Microsoft Technet: Overview of Remote Desktop Gateway
App Wrapping is A Form of Containerization
Forrester: Containerization Vs. App Wrapping - The Tale Of The Tape
Thanks for the link to my blog: http://andrewjprokop.wordpress.com
ReplyDeleteNo prob. You've got some great stuff there.
Deleteyou can lean about vpn by visit this site.
ReplyDeletewhat is a vpn
VPN is surely the internet mainstream entity nowadays, to unblock netflix and other channels or to get full privacy from NSA and other govt survelleince.
ReplyDeletei`m using citizen vpn, http://www.bestvpnservice.com/citizenvpn/
Very interesting article about VPN.
ReplyDeletetop10-bestvpn.com
Excellent article.Cool info about VPN.
ReplyDelete10webhostingservice