Even though your TUNIX/Firewall protects your internal network by forming a
strong barrier between the outside world there is still the need to provide
access to data within your organization for selected partners. In order to do
this securely, the authenticity of both sender and receiver and the integrity of
the data needs to be verified. This calls for a solution using strong
authentication and authorization, and data exchange through an encrypted tunnel
between the endpoints. Depending on the nature of your organization and the kind
of data that you need to offer access to, there may be even legal requirements
to deploy exchange of sensitive data in a secure fashion.
There are of course many ways to secure your data, each with its own pros and
cons. Deciding on the optimal way to deploy encryption for secure data exchange
with another organization in a secure fashion depends on a few parameters:
-
Between how many people do you need to exchange data?
-
How often do you need to exchange data?
-
What kind of data do you need to exchange?
Depending on these parameters, your optimal solution for secure data exchange
may range from encrypting small amounts of data individually, using VPN software
or setting up encrypted tunnels between locations.
In order to exchange small amounts of data securely, TUNIX provides a digital
vault facility on http://www.webttp.nl where you can store documents. To give
other parties access to these documents, you provide them with the virtual key
to the vault. Both storage and retrieval actions are protected by strong SSL
encryption. Because documents can only be retrieved from the vault once,
interception is readily detected, making sure that the document is sent only to
the rightful recipient. You are cordially invited to try this new facility.
E-mail messages can be secured using S/MIME, which not only provides strong
encryption, but also authentication of the originator, because it relies on
certificates. Many modern mailclients --including Outlook and Outlook Express--
are S/MIME capable, so setup requires minimal effort. TUNIX can supply
the certificates needed for this purpose. Similar encryption and authentication
capabilities are offered by PGP. Incidentally, the ZIP encryption algorithm is
considered weak, and should be avoided as a means for secure data exchange.
Secure remote access to corporate applications and data can also be provided
using VPN tunnels. TUNIX offers its own low-cost, easy install VPN solution
``TUNIX/VPN for Windows'', which offers strong authentication and can be
tailored to allow minimal access to the internal network. In addition, TUNIX
now offers secure SSL-based remote access using
F5 FirePass (TM) appliances
With optional hardware-based SSL
acceleration and clustering, these devices can accomodate anywhere between 25
and 20000 concurrent employees working remotely. To ensure authorized access
to your internal network, the TUNIX/Firewall offers a choice of authentication
systems for VPN access, including an internal database, Active Directory, LDAP
or RADIUS. Support for two-factor authentication (such as Ikey, SecurID and
SafeWord) is also provided and endpoint systems can be checked for security
compliance before access is granted.
For data exchange at the enterprise level, between remote offices for instance,
the TUNIX/Firewall fully supports IPSec connectivity (both pass-through and
endpoint) to many VPN devices of other vendors. Even though IPSec allows two
endpoints to be fully connected, the TUNIX/Firewall still allows fine-grained
control to your internal servers and applications.
Please contact your account manager for expert advice on the deployment of a
framework for secure data exchange.