Ravlin Soft

Secure Access to Corporate Resources Using Public Networks or Dial-Up Lines.

Product Overview

RavlinSoft is a client software tool that provides the same security as a Ravlin hardware unit. With RavlinSoft, remote users such as mobile employees and telecommuters can securely access corporate resources through either public networks or existing corporate dial-up facilities. As with Ravlin units, RavlinSoft provides privacy (56-bit DES, 168-bit Triple DES encryption), user authentication (ISO X.509 v.3 digital certificates), and key management (IKE).

RavlinSoft has all the mandatory components of the Internet Engineering Task Force (IETF) IP Security Standard (IPSec) for enhanced network security. There are two significant benefits to IPSec: enhanced security features and protocol interoperability.

The customer can be certain that IP-based communications conform to the most secure and comprehensive standard for encryption, authentication, key management, and anti-replay services.

Because a Ravlin unit can exchange keys and encrypted communications with any other IPSec-compliant products, customers can use multiple IPSec vendors for multiple scenarios. IPSec protocol interoperability between IPSec-compliant members ensures that two products can negotiate a secure association between them.

The RavlinSoft IPSec network security enforcement features enable strong privacy and user authentication.

Features and Benefits

ESP (Encapsulating Security Payload) Tunnel Mode
ESP Tunnel mode offers protection against intruders who intercept datagrams in transit and use the source or destination IP addresses to gain entry. ESP mode is typically used when the highest level of security is required for gateway- to- gateway and remote-system-to-gateway secure associations (SAs). Consistent with IPSec IPESP standards, this mode uses 56-bit DES or 168-bit Triple DES to encrypt the IP address of the sender, as well as the entire IP payload. The encrypted IP datagram is then encapsulated in a new packet, thus hiding the original source and destination addresses.

ESP (Encapsulating Security Payload) Transport Mode
ESP Transport mode is typically used for host-to-host VPNs or for global Internet users. In this mode, only the data portion of the original IP datagram is encrypted. Like ESP mode, ESP Transport mode uses 56-bit or 168-bit Triple DES.

RavlinSoft also support Authentication Header (AH) Transport mode and Authentication Header (AH) Tunnel mode. These modes use strong authentication to secure IP datagrams without encrypting the data payload. They use IPSec- standard authentication and anti-replay, plus hashing, to ensure that the data stream is not modified.

Encryption-in-Place (EIP) Mode
EIP Mode is a RedCreek proprietary secure VPN technology. Although EIP mode is not part of the IPSec standard, it combines high speed with all levels of encryption.

In EIP mode, only the payloads of IP datagrams are encrypted. Like ESP mode, EIP mode can use 56-bit or 168-bit Triple DES.

EIP Mode is typically used when network speed and performance are the most crucial considerations, as in trusted environments (such as corporate intranets) or where large multimedia development is taking place.

Anti-Replay Service
RavlinSoft uses IPSec anti-replay services to prevent intruders from inserting rogue packets into a data stream. With anti-replay service, each IP datagram passing within the secure association is tagged with a sequence number. On the receiving end, each datagram's sequence number is checked to see if it falls within a specified range. If an IP datagram tag number falls outside of the range, the datagram is blocked.

Event Messaging Support
RavlinSoft also supports Syslog Event Monitoring.

Unlimited Security Profiles
RavlinSoft's profiles feature provides for effectively unlimited client configurations. Simply select any profile and click apply to initiate a new Security Association. RavlinSoft's Security Profile Wizard provides a fast way to configure the client for any secure connection.

Low Cost of Ownership

Standards Based

Support of Unique Digital Certificates
RavlinSoft uses an X.509 certificate for authentication by the Ravlin hardware devices.

Strong User Authentication and Policy Management with X.509 v.3 Digital Certificates
Importing an independent vendor's unique X.509 v.3 digital certificate into the RavlinSoft client allows organizations to add stronger policy enforcement and access privileges to individual users via certificate authorities.

Customer Support/Service
RedCreek Communications, Inc. believes that our customers deserve lasting value and continuous satisfaction with RedCreek products. Because of this belief, RedCreek, in participation with its VARs, offers innovative support programs to assist with installation and configuration of Ravlin products. Please reference RedCreek's Customer Support Center.

home | search | products | services | research | company | partners | downloads | contact
Please contact our Webmaster with any questions or comments.
Copyright 1999, 2000, 2001 I.D.T., Inc.. All rights reserved.