SECURE YOUR VPN
Robust security for your private networks, that
grows with your business
Virtual Private Networks (VPNs) allow a company to extend
their local network to connect branch offices, remote
users, business partners and customers via the Internet.
As with all other types of networks, VPNs are also vulnerable
to attack by hackers and cyber-criminals. IPSec (Internet
Protocol Security), an industry standard, enables these
networks to be secured through encryption providing
confidentiality and integrity.
VeriSign Trusted IPSec from NIFTeTRUST strengthens
the security into such VPNs to provide strong authentication
and a scalable solution free of passwords. Trusted
IPSec is a managed digital certification service that
takes our core PKI solution and integrates it into
VPNs such as intranets and extranets, based on the
IPSec industry standards. It gives you the ability
to digitally authenticate every person or network
device (such as firewalls and routers) seeking to
link onlne to your corporate networks and systems,
with the option to scale up from a handful to a million
certificates.
Key Benefits and Features
• Control - you control the
issuance of your digital certificates; we manage the
service for you.
• Easy to deploy - set up quickly
without extensive training and configuration; the
service provides intuitive tools for managing certificates.
• Scalability - as your business
grows, centralised control and reporting, customisable
validity periods, and rapid turnaround make it easy
to issue all the certificates necessary for devices
and clients. You can have from as few as 25 users
or network devices with Trusted IPSec Lite up to a
million with Trusted IPSec Enterprise.
• Low cost of ownership - you
only pay for the size and scale you want.
• Flexibility - adapt certificate
enrolment, renewal, or revocation requirements as
needed.
• Reliability - using industry
standard digital certificates backed by VeriSign,
a market leader in PKI systems, operations are run
from a high-security facility with specially trained,
security-vetted personnel and back-up systems.
• Managed service - we provide
a managed outsourced CA (Certification Authority)
without the need for you to either build the secure
location and infrastructure required nor to implement
and manage the CA yourselves.
What is IPSec
?
IPSec, standing for Internet Protocol Security, is
a framework of open standards for securing private
communications on the Internet. It establishes secure,
encrypted communications at the network level between
firewalls, routers and remote access devices. The
IPSec standard ensures:
• Authentication - validating
the identities of communicating parties;
• Integrity - protecting data
from alteration en route; and
• Privacy - safeguarding information
from interception.
Though IPSec can use either "shared secret keys"
or PKI for initiating a secure communication, shared
secret keys cannot scale beyond a handful of devices.
A PKI (Public Key Infrastructure) solution - Trusted
IPSec - enables your organisation to easily and quickly
issue as many Digital Certificates as your network
demands.
Compatibility
Many vendors have implemented certificate lifecycle
management components into their VPN gateways, firewalls,
routers and desktop clients by employing industry
standard protocols. This allows them to work seamlessly
with VeriSign Trusted IPSec from NIFTeTRUST without
having to incorporate and support proprietary, single
vendor oriented components into their products. The
time to deployment of the highly available infrastructure
of Trusted IPSec can be leveraged by vendors using
the following protocols: CAPI, CRS, CSR, PKCS 7, PKCS10,
PKCS12 and SCEP.
Installation Support
The Trusted IPSec Lite service can be applied for
directly from the NIFTeTRUST Trust Services web site,
through a web-based service enrolment form. The request
would then be authenticated and verified by NIFTeTRUST
Trust Services prior to issue. After configuration
of the service, IPSec digital certificates can be
issued and installed onto network devices such as
routers, firewalls and gateways.
Due to the complex nature of network devices, it
is strongly recommended that the application and installation
of the service and IPSec certificates must be carried
out by a qualified engineer, well-versed in the technology.
If required, additional support for installing IPSec
certificates onto devices can be obtained from the
device vendor.