Satellite Internet forum
https://www.satsig.net/cgi-bin/yabb/YaBB.pl
Service Providers >> Satellite Connection in Africa >> Inquiry about the VPN over iDirect satellite
https://www.satsig.net/cgi-bin/yabb/YaBB.pl?num=1173884472

Message started by NetvSat_Com. on Mar 14th, 2007 at 3:01pm

Title: Inquiry about the VPN over iDirect satellite
Post by NetvSat_Com. on Mar 14th, 2007 at 3:01pm
If ihave two sites each using an iDirect modem, and i want the two sites, each site with it's local network, to communicate using a VPN connection.

I have been informed that i must use a VPN router for each site, i would like to know the avilable VPN router and recommended VPN routers that works perfectly with idirect 3000 modem.


Also if i want to upgrade the sites no. to 3 sites do i have to buy another VPN router and configure it, or i have to do special arragments.



Title: Re: Inquiry about the VPN
Post by pgannon on Mar 29th, 2007 at 11:37pm
There are a number of issues associated with VPNs, or Virtual Private Networks.  

The first question is, do you absolutely need encryption between these sites?  If you do not need encryption, then you can ask your network operator to configure the two sites on their own VLAN (Virtual LAN).  Their traffic can then be routed at the teleport from one site to any other site(s) in the VLAN.  The iDirect system is inherently quite secure without encryption.  Trying to figure out which remote site is transmitting in which timeslot at any given point in time is quite difficult and will require a signficant reverse engineering effort.  Each iDirect modem has a burned in hardware address and can only receive data  that is directed to it.  

If you require encryption between the two sites, then you will need a VPN appliance or software.  The most popular VPN solutions are IPSec and they are available from many vendors such as Cisco, Juniper, Nortel, 3Com and many others.  There isn't any particular model that will work better with iDirect than any other.  

Another possible option is an SSL-VPN.  Because IPSec (or PPTP from Microsoft) encrypt the TCP headers on each packet, the TCP/HTTP Acceleration features of the iDirect (or any other) modem is disabled.  You already have a significant delay issue to deal with here because your traffic must make a double satellite hop, unless you are using mesh.  SSL-VPNs only encrypt the data, and leave the TCP headers alone so that TCP/HTTP Acceleration continues to operate properly.  

There are pre-acceleration devices such as iDirect's 1100 Network Accelerator, or UDCast or Packeteer/Mentat, that provide TCP/HTTP Acceleration before the data gets encrypted.  These external appliances sit between the LAN and the VPN appliance -but they increase the cost of the solution.  

iDirect has their own encryption option that you can run over the system, however this will require that the network operator support the encryption line card in their hub.  They will surely charge more to use this service.  It's not cost effective for network operators to add this option unless they have enough sites interested in using it.  The advantage of the built-in encryption is that TCP/HTTP Acceleration continues to work.  

I'm afraid that a typical IPSec VPN connection over a double-hop satellite link is going to result in same day service - i.e. very slow!

Hopefully your application doesn't require end-to-end encryption and your network operator can simply configure the sites on a VLAN so they can be routed to each other.  

In response to your question about whether adding additional sites requires additional VPN appliances, the answer is Yes, if you are using IPSec.  You build or configure "tunnels" between the sites that want to communicate with each other. As you add more sites, you have to configure more tunnels.  Most appliances have some limit on the number they support, so this has to be taken into consideration when selecting the right model.  

Hope this helps,

Pat
wxw
Patrick Gannon
Business Satellite Solutions, LLC
www.bsatellite.com


Powered by YaBB 2.5.2!
YaBB Forum Software © 2000-. All Rights Reserved.