CertCities.com -- The Ultimate Site for Certified IT Professionals
Free CertCities.com Newsletter via E-mail Share share | bookmark | e-mail
  Microsoft®
  Cisco®
  Security
  Oracle®
  A+/Network+"
  Linux/Unix
  More Certs
  Newsletters
  Salary Surveys
  Forums
  News
  Exam Reviews
  Tips
  Columns
  Features
  PopQuiz
  RSS Feeds
  Press Releases
  Contributors
  About Us
  Search
 

Advanced Search
  Free Newsletter
  Sign-up for the #1 Weekly IT
Certification News
and Advice.
Subscribe to CertCities.com Free Weekly E-mail Newsletter
CertCities.com

See What's New on
Redmondmag.com!

Cover Story: IE8: Behind the 8 Ball

Tech-Ed: Let's (Third) Party!

A Secure Leap into the Cloud

Windows Mobile's New Moves

SQL Speed Secrets


CertCities.com
Let us know what you
think! E-mail us at:



 
 
...Home ... Editorial ... News ..News Story Monday: December 27, 2010


Cisco's SSL VPN Mixed Bag


2/21/2006 -- It was at last year's RSA security confab that Cisco Systems Inc. kicked off its extreme security makeover. There, you'll remember, Cisco chief John Chambers outlined an ambitious new security strategy during his keynote, and Cisco itself announced 10 new security-related products, enhancements and services.

At this year's RSA Conference 2006 event, Cisco once again made headlines -- this time for revamping its SSL VPN portfolio, tweaking SSL VPN licensing, and augmenting its SSL VPN stack with new Anti-X capabilities.

For the record, Cisco announced a new Content Security and Control security services module (CSC-SSM) for its Cisco Adaptive Security Appliance (ASA) 5500 Series. The CSC-SSM provides Anti-X services (anti-virus, anti-spyware, anti-spam, anti-phishing, content, file and URL blocking and filtering) and was developed in tandem with anti-virus specialist Trend Micro Inc.

The new SSL VPN services (available on the ASA 5500 and on Cisco's IOS routers) are available for a single concurrent user license fee. The SSL VPN features are licensed in 10-, 25- and 100-user increments for $30 per user.

Analysts say Cisco's SSL VPN refresh is something of a mixed bag. "[T]hese new features are critical for Cisco to be competitive in the evolving market for remote access and unified threat defense," writes Joel Conover, a principal analyst for enterprise infrastructure with consultancy Current Analysis.

For one thing, Conover notes, the new SSL VPN features help Cisco make good on its promise to bring full SSL VPN functionality to the ASA-5500 platform; what's more, they expand on this promise by delivering a subset of SSL VPN functionality on IOS-based routing platforms from Cisco's 800 series through the 7200 series. "The new SSL VPN functionality also comes with a price. SSL VPN is no longer a free feature on Cisco platforms; instead, it is now a licensed feature. Cisco also introduced Anti-X services for the ASA-5500 platform via a new content security module on the ASA platform. However, this functionality is mutually exclusive of Cisco's advanced IDS support, diminishing the competitive impact in the highly competitive UTM market," Conover writes.

Cisco's SSL about-face also contradicts its own long-standing position, Conover notes. "Cisco spent a great deal of time educating the market [that] SSL was just another form of transport for remote access, and that it should be a ‘free' feature of remote access platforms. Its recent change in product licensing for SSL VPNs is a 180-degree shift from that messaging, and gives competitors an open license to attack Cisco's tactics," he points out.

Finally, changes Cisco has made to the licensing of its SSL VPNs could negatively impact some existing ASA owners, Conover concludes. "While the SSL VPN feature set is now complete on the ASA, a small subset of that functionality was already available on the ASA platform, and that existing functionality was available for use at no charge."  -Stephen Swoyer



There are 1966 CertCities.com user Comments for “Cisco's SSL VPN Mixed Bag”
Page 1 of 197
3/26/06: Anonymous says: Those that purchased a ASA on or before March 31, 2006, can apply for a "grandfather" license. This license will transfer their prior "free" SSL license to the new "pay" model at no charge.
2/20/07: Anonymous says: I actually have used the new AnyConnect VPN client from Cisco and it is pretty nice. There is a new low latency TLS protocol in it which is really really fast.
4/12/07: Jim Wilson from Ny says: Can you tell more about the low latency protocol. Is AnyConnect available today?
10/11/09: adipex p no perscrip from New York says: It is the coolest site, keep so!
10/11/09: pet tramadol hydroch from New York says: Perfect site, i like it!
10/11/09: tramadol non prescri from New York says: Great. Now i can say thank you!
10/11/09: instructions for cia from New York says: If you have to do it, you might as well do it right.
10/12/09: buy cheap phentermin from New York says: Perfect work!
10/12/09: percription free phe from New York says: I want to say - thank you for this!
10/12/09: adipex p vs adipex from New York says: Perfect work!
First Page   Next Page   Last Page
Your comment about: “Cisco's SSL VPN Mixed Bag”
Name: (optional)
Location: (optional)
E-mail Address: (optional)
Comment:
   

-- advertisement (story continued below) --

top