Integrated VPN / Firewall

Today’s VPN product solutions generally fall into two main categories:

1) stand-alone VPN gateways
2) integrated VPN/firewall solutions

Of these two, only integrated VPN/firewall solutions are designed to deliver complete Internet security. By contrast, VPN gateways deployed separately from the firewall burden network administrators with many needless complexities of security and management. In addition, with stand-alone VPNs, the placement of the VPN gateway with respect to the firewall becomes critical since firewalls cannot enforce access control of encrypted traffic.


Integrated VPN/firewall solutions meet all of the critical requirements for a sound VPN deployment by delivering:

Protection from Internet Threats. With integrated VPN/firewall solutions, the VPN gateway, and therefore VPN connectivity, receives protection from the firewall. Common denial of service attacks that could compromise a stand-alone VPN gateway are detected and dealt with by the integrated firewall.

Access Control for all Traffic. Placement of the VPN gateway within the access control device allows more granular security to be applied to VPN traffic. Since the firewall and VPN gateway share user information, individuals and pre-defined groups can use the resources and services to which they are entitled access and all VPN traffic is decrypted and inspected to ensure that only appropriate content is allowed through the firewall.

Centralized Management. Integrated VPN implementations greatly simplify the administration of a security policy, particularly in environments where multiple firewalls and VPN gateways are required. Database updates and security policy changes can be simultaneously applied to all VPN/firewalls, minimizing the possibility of configuration errors.

In addition, integrated VPN solutions allow critical user information to be shared among multiple network applications, including firewalls and VPN gateways, throughout the enterprise. In this way network managers do not have to maintain redundant user information across multiple proprietary user data stores.

Consolidated Logging. It is only with integrated solutions that network, object, user, service and administrator data shared by the VPN gateway and firewall can be leveraged. This way, all of the auditing information, which is critical to network administrators, is available in unified log files.

Scalable Architecture. In order to extend the geography of networks to branch offices and customers, enterprises require VPN solutions that will scale. VPN/firewall solutions can be introduced into VPN networks seamlessly with virtually no disruption to network operations. This benefit becomes particularly compelling when considering environments with high availability requirements where the number of enforcement points to be deployed is doubled.

Simplified Routing. As data travels through network devices, each possible path is reflected as a routing table entry. When resources are added to a network, routing tables must be augmented to direct traffic to the firewall and VPN gateway. Integrating the VPN and the firewall greatly simplifies this task by eliminating the need to maintain separate routes to these devices.