MPKI Portfolio - Trusted IPSec
 

Back to home page

Robust security for your private networks, that grows with your business

Virtual Private Networks (VPNs) allow a company to extend their local network to connect branch offices, remote users, business partners and customers via the Internet. As with all other types of networks, VPNs are also vulnerable to attack by hackers and cyber-criminals. IPSec (Internet Protocol Security), an industry standard, enables these networks to be secured through encryption providing confidentiality and integrity.

VeriSign Trusted IPSec from BT strengthens the security into such VPNs to provide strong authentication and a scalable solution free of passwords.  Trusted IPSec is a managed digital certification service which takes our core PKI solution and integrates it into VPNs such as intranets and extranets, based on the IPSec industry standards. It gives you the ability to digitally authenticate every person or network device (such as firewalls and routers) seeking to link onlne to your corporate networks and systems, with the option to scale up from a handful to a million certificates.

Key Benefits and Features

  • Control - you control the issuance of your digital certificates; we manage the service for you.
  • Easy to deploy - set up quickly without extensive training and configuration; the service provides intuitive tools for managing certificates.
  • Scalability - as your business grows, centralised control and reporting, customisable validity periods, and rapid turnaround make it easy to issue all the certificates necessary for devices and clients. You can have from as few as 25 users or network devices with Trusted IPSec Lite up to a million with Trusted IPSec Enterprise.
  • Low cost of ownership - you only pay for the size and scale you want.
  • Flexibility - adapt certificate enrolment, renewal, or revocation requirements as needed.
  • Reliability - using industry standard digital certificates backed by VeriSign, a market leader in PKI systems, operations are run from a high-security facility with specially trained, security-vetted personnel and back-up systems.
  • Managed service - we provide a managed outsourced CA (Certification Authority) without the need for you to either build the secure location and infrastructure required nor to implement and manage the CA yourselves.

What is IPSec ?
IPSec, standing for Internet Protocol Security, is a framework of open standards for securing private communications on the Internet. It establishes secure, encrypted communications at the network level between firewalls, routers and remote access devices. The IPSec standard ensures :

  • authentication - validating the identities of communicating parties;
  • integrity - protecting data from alteration en route; and
  • privacy - safeguarding information from interception.

Though IPSec can use either "shared secret keys" or PKI for initiating a secure communication, shared secret keys cannot scale beyond a handful of devices. A PKI (Public Key Infrastructure) solution - Trusted IPSec - enables your organisation to easily and quickly issue as many Digital Certificates as your network demands.

Compatibility
Many vendors have implemented certificate lifecycle management components into their VPN gateways, firewalls, routers and desktop clients by employing industry standard protocols. This allows them to work seamlessly with VeriSign Trusted IPSec from BT without having to incorporate and support proprietary, single vendor oriented components into their products. The time to deployment of the highly available infrastructure of Trusted IPSec can be leveraged by vendors using the following protocols : CAPI, CRS, CSR, PKCS 7, PKCS10, PKCS12 and SCEP.

Installation Support
The Trusted IPSec Lite service can be applied for directly from the BT Trust Services web site, through a web-based service enrolment form. The request would then be authenticated and verified by BT Trust Services prior to issue. After configuration of the service, IPSec digital certificates can be issued and installed onto network devices such as routers, firewalls and gateways.

Due to the complex nature of network devices, it is strongly recommended that application and installation of the service, as well as IPSec certificates, be carried out by a qualified engineer who is well versed in the technology. If required, additional support for installing IPSec certificates onto devices can be obtained from the device vendor.

 
Back to top
 
Print a print-friendly version of this page

Helpline

Syntegra

tScheme

Verisign_trust_network