Author Topic: Where are all the small FIPS certified IPSEC VPNs going?  (Read 5502 times)

mtnbkr

  • friend
  • Senior Member
  • ***
  • Posts: 15,388
Where are all the small FIPS certified IPSEC VPNs going?
« on: January 29, 2009, 11:56:48 AM »
Nortel is dropping theirs, it looks like Cisco is doing the same.  Juniper nickels and dimes you to death if you want one of theirs.  Alcatel is gone, as are many other players.

All I want is a sub-$2000 device that will deliver 20+ tunnels at 10-20Mbps with AES encrypted IPSEC and is also FIPS 140-2 certified.  We buy 5-10 of these a year from Nortel (their Contivity 600 model).

Chris

41magsnub

  • friend
  • Senior Member
  • ***
  • Posts: 7,579
  • Don't make me assume my ultimate form!
Re: Where are all the small FIPS certified IPSEC VPNs going?
« Reply #1 on: January 29, 2009, 01:34:01 PM »
Sonicwall will do it, there is a FIPS check box to lock it down to those standards.  The smallest one, the TZ-150, is not but everything larger is.

An SW NSA 240 Box might be what you are looking for, well under $2K, exceeds all the numbers you mentioned, and is FIPS compliant.
« Last Edit: January 29, 2009, 01:39:20 PM by 41magsnub »

mtnbkr

  • friend
  • Senior Member
  • ***
  • Posts: 15,388
Re: Where are all the small FIPS certified IPSEC VPNs going?
« Reply #2 on: January 29, 2009, 02:10:00 PM »
Will check it out.  Thanks!

Chris

AJ Dual

  • friends
  • Senior Member
  • ***
  • Posts: 16,162
  • Shoe Ballistics Inc.
Re: Where are all the small FIPS certified IPSEC VPNs going?
« Reply #3 on: January 29, 2009, 02:11:56 PM »
Yes.

Sonicwall seems to be moving into the small/medium end of the market the others are vacating. It's what we have too.
I promise not to duck.

RevDisk

  • friend
  • Senior Member
  • ***
  • Posts: 12,633
    • RevDisk.net
Re: Where are all the small FIPS certified IPSEC VPNs going?
« Reply #4 on: January 29, 2009, 03:15:36 PM »
Nortel is dropping theirs, it looks like Cisco is doing the same.  Juniper nickels and dimes you to death if you want one of theirs.  Alcatel is gone, as are many other players.

All I want is a sub-$2000 device that will deliver 20+ tunnels at 10-20Mbps with AES encrypted IPSEC and is also FIPS 140-2 certified.  We buy 5-10 of these a year from Nortel (their Contivity 600 model).

Chris

Shoot, there's usually half a dozen such devices in "Signal" magazine that's geared towards military commo gear.   I'll find ya a bunch once I get home.  Uh, you don't mind your boxes coming in OD, ACU grey, etc, right? 
"Rev, your picture is in my King James Bible, where Paul talks about "inventors of evil."  Yes, I know you'll take that as a compliment."  - Fistful, possibly highest compliment I've ever received.

mtnbkr

  • friend
  • Senior Member
  • ***
  • Posts: 15,388
Re: Where are all the small FIPS certified IPSEC VPNs going?
« Reply #5 on: January 29, 2009, 03:23:28 PM »
Pink is fine as long as it meets our needs. :)

Chris

RevDisk

  • friend
  • Senior Member
  • ***
  • Posts: 12,633
    • RevDisk.net
Re: Where are all the small FIPS certified IPSEC VPNs going?
« Reply #6 on: January 29, 2009, 04:20:46 PM »
Pink is fine as long as it meets our needs. :)

Chris

I shall inquire into the availability of that as well, then.
"Rev, your picture is in my King James Bible, where Paul talks about "inventors of evil."  Yes, I know you'll take that as a compliment."  - Fistful, possibly highest compliment I've ever received.

mtnbkr

  • friend
  • Senior Member
  • ***
  • Posts: 15,388
Re: Where are all the small FIPS certified IPSEC VPNs going?
« Reply #7 on: January 29, 2009, 04:24:41 PM »
If you find a pink one that meets our needs, then I shall lobby for it's adoption simply because...

Chris

41magsnub

  • friend
  • Senior Member
  • ***
  • Posts: 7,579
  • Don't make me assume my ultimate form!
Re: Where are all the small FIPS certified IPSEC VPNs going?
« Reply #8 on: January 29, 2009, 04:36:41 PM »
If you find a pink one that meets our needs, then I shall lobby for it's adoption simply because...

Chris

There is always Krylon...

RevDisk

  • friend
  • Senior Member
  • ***
  • Posts: 12,633
    • RevDisk.net
Re: Where are all the small FIPS certified IPSEC VPNs going?
« Reply #9 on: January 30, 2009, 12:09:50 AM »
 =|

Sorry man, everyone uses repackaged Cisco or Nortel usual suspects.

Your only options for something name brand are a Netscreen off eBay, or a SSG 140.  Juniper is probably going to be your only bet if you want FIPS, brand name and new from OEM. 

You can try looking at Allied Telesis AT-AR750S, but I don't think it's FIPS.  Work looking into, tho.
http://www.alliedtelesyn.com/products/type.aspx?cid=10

There's other stuff, but probably not what you want.  SonicWall, TrendNet TW100-BRV324, etc etc.
"Rev, your picture is in my King James Bible, where Paul talks about "inventors of evil."  Yes, I know you'll take that as a compliment."  - Fistful, possibly highest compliment I've ever received.

S. Williamson

  • formerly Dionysusigma
  • friends
  • Senior Member
  • ***
  • Posts: 3,034
  • It's not the years, it's the mileage.
Re: Where are all the small FIPS certified IPSEC VPNs going?
« Reply #10 on: January 30, 2009, 02:02:33 AM »
0_0

ihavenoideawhatyouretalkingabout

0_0
Quote
"The chances of finding out what's really going on are so remote, the only thing to do is hang the sense of it and keep yourself occupied. I'd far rather be happy than right any day."
"And are you?"
"No, that's where it all falls apart I'm afraid. Pity, it sounds like quite a nice lifestyle otherwise."
-Douglas Adams

RevDisk

  • friend
  • Senior Member
  • ***
  • Posts: 12,633
    • RevDisk.net
Re: Where are all the small FIPS certified IPSEC VPNs going?
« Reply #11 on: January 30, 2009, 08:34:27 AM »
ihavenoideawhatyouretalkingabout

We're making up words to confuse you.  I would have thought that was obvious.   =D
"Rev, your picture is in my King James Bible, where Paul talks about "inventors of evil."  Yes, I know you'll take that as a compliment."  - Fistful, possibly highest compliment I've ever received.

mtnbkr

  • friend
  • Senior Member
  • ***
  • Posts: 15,388
Re: Where are all the small FIPS certified IPSEC VPNs going?
« Reply #12 on: January 30, 2009, 09:06:46 AM »
Juniper is probably going to be your only bet if you want FIPS, brand name and new from OEM. 

You can try looking at Allied Telesis AT-AR750S, but I don't think it's FIPS.  Work looking into, tho.
http://www.alliedtelesyn.com/products/type.aspx?cid=10

Thanks.  I'll check into the AT unit.  Juniper isn't a bad choice if we can get what we need for the price we're paying for a Nortel 600. FIPS is an absolute requirement though, which is what makes this so damn annoying.  Lots of non-FIPS choices out there...

Chris

Firethorn

  • friend
  • Senior Member
  • ***
  • Posts: 5,789
  • Where'd my explosive space modulator go?
Re: Where are all the small FIPS certified IPSEC VPNs going?
« Reply #13 on: January 30, 2009, 04:46:07 PM »
Quote
FIPS is an absolute requirement though, which is what makes this so damn annoying.

You want fun?  I have people trying to find FIPS 140-2 compliant wireless keyboards...   :lol:   =D

When it gets annoying is when they try to get ME to find them.

Nitrogen

  • friends
  • Senior Member
  • ***
  • Posts: 1,755
  • Who could it be?
    • @c0t0d0s2 / Twitter.
Re: Where are all the small FIPS certified IPSEC VPNs going?
« Reply #14 on: January 30, 2009, 05:46:43 PM »
Sonicwall or possibly Checkpoint.
יזכר לא עד פעם
Remember. Never Again.
What does it mean to be an American?  Have you forgotten? | http://youtu.be/0w03tJ3IkrM

mtnbkr

  • friend
  • Senior Member
  • ***
  • Posts: 15,388
Re: Where are all the small FIPS certified IPSEC VPNs going?
« Reply #15 on: January 31, 2009, 12:06:19 AM »
You want fun?  I have people trying to find FIPS 140-2 compliant wireless keyboards...   :lol:   =D

Why?  If you need security in a keyboard, use a wired model. 

Chris

AJ Dual

  • friends
  • Senior Member
  • ***
  • Posts: 16,162
  • Shoe Ballistics Inc.
Re: Where are all the small FIPS certified IPSEC VPNs going?
« Reply #16 on: January 31, 2009, 09:43:39 AM »
0_0

ihavenoideawhatyouretalkingabout

0_0

It's really pretty simple. IEEE 4521.x standards dictate that any proposed device has bitstream conduits that deviate from the OSI seven-layer concept less than .005% of all cross-partnered packets. And that they all have have a factored checksum that falls within a Fibonacci sequence.

Many inexpensive devices do this, however, the expense is really in the certification. Although if you want one that can multipath sessions with indexed authentication using disposable one-time pads, now that'll cost you.
I promise not to duck.

mtnbkr

  • friend
  • Senior Member
  • ***
  • Posts: 15,388
Re: Where are all the small FIPS certified IPSEC VPNs going?
« Reply #17 on: January 31, 2009, 09:54:58 AM »
It's really pretty simple. IEEE 4521.x standards dictate that any proposed device has bitstream conduits that deviate from the OSI seven-layer concept less than .005% of all cross-partnered packets. And that they all have have a factored checksum that falls within a Fibonacci sequence.

Many inexpensive devices do this, however, the expense is really in the certification. Although if you want one that can multipath sessions with indexed authentication using disposable one-time pads, now that'll cost you.

AJ, I'm not familiar with IEEE 4521.x.  I also can't find anything referring to it.  What exactly is it?

More about FIPS 140-1 (what I'm referring to when I merely say "FIPS"): http://en.wikipedia.org/wiki/FIPS_140-2

Chris

AJ Dual

  • friends
  • Senior Member
  • ***
  • Posts: 16,162
  • Shoe Ballistics Inc.
Re: Where are all the small FIPS certified IPSEC VPNs going?
« Reply #18 on: January 31, 2009, 10:23:57 AM »
AJ, I'm not familiar with IEEE 4521.x.  I also can't find anything referring to it.  What exactly is it?

More about FIPS 140-1 (what I'm referring to when I merely say "FIPS"): http://en.wikipedia.org/wiki/FIPS_140-2

Chris

IEEE 4521.x supplanted IEEE 4521.w sometime around 2003, IIRC. Mainly because RAMDAC's capable of less than a .00001% error rate with packet formulation have only cost pennies since the 90's. They also upped the session retry timeout for non-optical transmission, (copper pair etc.) for when there's solar storm activity etc.

You do, uh.. know I'm just making up completely random stuff as I go along, right?  =)
I promise not to duck.

mtnbkr

  • friend
  • Senior Member
  • ***
  • Posts: 15,388
Re: Where are all the small FIPS certified IPSEC VPNs going?
« Reply #19 on: January 31, 2009, 11:10:54 AM »
You do, uh.. know I'm just making up completely random stuff as I go along, right?  =)

Who are you, Gene Roddenberry? ;)

Chris

RevDisk

  • friend
  • Senior Member
  • ***
  • Posts: 12,633
    • RevDisk.net
Re: Where are all the small FIPS certified IPSEC VPNs going?
« Reply #20 on: January 31, 2009, 12:14:11 PM »
Many inexpensive devices do this, however, the expense is really in the certification. Although if you want one that can multipath sessions with indexed authentication using disposable one-time pads, now that'll cost you.


Dude, I swear to the Gods I was laughing so hard, my lady friend thought I was in danger of dying.  I was seeing spots and now my sides hurt. 

 =D
"Rev, your picture is in my King James Bible, where Paul talks about "inventors of evil."  Yes, I know you'll take that as a compliment."  - Fistful, possibly highest compliment I've ever received.

Firethorn

  • friend
  • Senior Member
  • ***
  • Posts: 5,789
  • Where'd my explosive space modulator go?
Re: Where are all the small FIPS certified IPSEC VPNs going?
« Reply #21 on: January 31, 2009, 02:43:43 PM »
Why?  If you need security in a keyboard, use a wired model. 

That's what I tell them.  But by regulation there is no direct ban, so when I get full birds asking I need the 4-Star regs to override them.

RevDisk

  • friend
  • Senior Member
  • ***
  • Posts: 12,633
    • RevDisk.net
Re: Where are all the small FIPS certified IPSEC VPNs going?
« Reply #22 on: January 31, 2009, 03:01:33 PM »
That's what I tell them.  But by regulation there is no direct ban, so when I get full birds asking I need the 4-Star regs to override them.

Don't you have a facility security officer handy?   FSO's are supposed to be able to explain security regs exactly like this situation.
"Rev, your picture is in my King James Bible, where Paul talks about "inventors of evil."  Yes, I know you'll take that as a compliment."  - Fistful, possibly highest compliment I've ever received.

Firethorn

  • friend
  • Senior Member
  • ***
  • Posts: 5,789
  • Where'd my explosive space modulator go?
Re: Where are all the small FIPS certified IPSEC VPNs going?
« Reply #23 on: January 31, 2009, 05:10:56 PM »
Don't you have a facility security officer handy?   FSO's are supposed to be able to explain security regs exactly like this situation.

My official title is a bit different, but that's basically what I am.