How expensive are IPsec VPN setup costs?
When setting up a site-to-site VPN using IPsec, what should be expected in terms of costs associated with performance, security, support and maintenance?

    Requires Free Membership to View

    SearchSecurity.com members gain immediate and unlimited access to breaking industry news, virus alerts, new hacker threats, highly focused security newsletters, and more -- all at no cost. Join me on SearchSecurity.com today!

    Michael S. Mimoso, Editorial Director

    By submitting your registration information to SearchSecurity.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchSecurity.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

As with any cost scenario, many of the variables depend upon how you choose to implement the VPN and what equipment you already have on hand. If, for example, you're already operating IPsec-capable firewalls at both sites, and they have enough excess capacity to handle the VPN traffic, you may be able to get by with a negligible investment of additional resources. On the other hand, if you're creating a large number of tunnels, or if you need to purchase additional VPN equipment, the costs can quickly mount.

Consider the case of the Cisco Systems Inc.'s VPN Concentrators. The networking giant's entry-level model, the VPN 3005, can handle 4 Mbps of throughput divided among up to 100 different site-to-site tunnels. You can buy the product for a couple of thousand dollars. As with most networking products, expect to spend about 15-20% of that money on annual support and maintenance.

Regarding staff resources, IPsec VPN tunnels tend to be fairly low maintenance. Technology exists to automatically reestablish broken sessions, and technical support is rarely needed for site-to-site VPNs. I've seen connections remain established for months without a hitch.

More information:

  • Learn why Microsoft Vista and VPNs don't always mix.
  • Do split-tunneling features make a VPN vulnerable? Mike Chapple explains.
  • This was first published in September 2007