Thetechnologyused a boatfromwhenusing a hometosortofprotectyourtrafficifyou'reon a hostilenetworkonwhenyouthebusinessworldisthesame, buttheemphasisisslightlydifferent.
I didn't placethesizetothinkabouthowpeopleusetheircomputersandnetworksin a business, andthenwecanextrapolatefromthattheproblemthatweneedtosolvewith a virtualprivatenetworkandthenhowthetechnologyworksfromthat.
So I drew a littlediagram.
I don't haveanycomputerlisting.
Prayforhere, but I havethenextbestthing.
I havemyiPadwithcomputerlistingpaperbyandwe'lldrawonthatandhopefullythescreencapturewillwork.
Thenyouseewhat I'm doing.
Let's have a thinkaboutwhat a typicalcorporatenetworkwouldbe.
Wewouldhavesomecomputersthatpeoplewoulduseon.
Thesewouldsortofbenetworkedtogether.
Let's justhave a couplethatwouldbe a smallofficeandthey'reallconnectedto a singlenetwork.
Forexample, a fileserver, whichcontainedsomesecretinformation, willcallusthefiles, andwemighthave a databasewhichhasgotsomeinformationon a normalcorporatenetwork.
Youmayhavesomecommissionsetup, sotherightpeopleyoucanaccesstherightserviceis, andsobutthesethings, thatnetworkisgonnabeconnectedviasomesortofroutertotheInternetandif I coulddraw a flowerpicturethatwillbetheInternetafterthosemachinescanalsoaccesstotheInternetviatherouterontheRichardConnectas a firewallsothatpeoplecan't getintoitfromtheoutsideandthatallworks.
Answerthatyoufindtheproblemcomesisifwehave a personsittingoutin a cafeorworkingfromhomeisonwhowantstoaccessthosesameresources?
Butofcoursethey'renotinthephysicalpremises, sowecan't justrun a cabletothem.
Sohowdowegetaroundthis?
Well, whatyoucoulddoAtonepointyoucouldbuy a dedicatedconnectionfromtelecomscompany, andtheywouldrun a wirefromyourbusinesspremisestosaytheperson's homeonyouconnectthemdie.
Willyouhave a directcablethatranacrossthewholething?
Theotherthingyoucoulddoisuse a dialupmodemandthepersonwouldringoverthetelephonenetworkandconnectwiththat.
You'd haveremoteaccessbythat, butthatrequiresspecificresources, quite a dialupmodem, quite a dietcollectionbeingputintoplace.
Sothevariousthingsgenerallywouldhavethedatain a packet.
Andthenontopofthat, weput a seriesofheadersthattellusthings.
Sothestandardnetworkthesedaysyouhave a TCPheadoftherethatwouldtellitwiththeorderthatthesepacketsneedtogoinandthenyouhavean I P headedputinfrontofthat, whichwouldtellitwhereit's going, whereit's comefrom.
ThatwholelotwillbeperchedinsideanEthernetpacketsowe'llhaveanEthernetheaderatthetopandthenthatcouldbesenteitherdirectlytothemachinethatwantsitallto a machinethatcanpassitontothemachinethatwantsitoverthecompany's localnetwork.
Sothat's howwesenddataoverthelocalnetwork.
Butwecanactuallydothesamethingifwehave a directconnection, ratherthanhavingthemachineputitdirectlyonthelocalnetwork.
Wehaveanothermachine, whichwasconnectedtothelocalnetworkandconnectedtothedirectconnection, anditwouldgivean I P addresstotheremotemachine.
Remember, thisis a physicaldirectconnection, eitherby a dialupmodemlinkorphysical, atleastlyingfromthetelecomscompany.
WegivetheRamonmachinean I p addressasifitwasonournetwork.
ButratherthansendingthatpacketdirectlytothemachinesovertheInternet, whatitdoesittakesthatwrappedup i p packetanditwrapsthewholewatchupasanotherpacket.
Soithas a UDPheadedhere.
That's anotherwhythingscommunicateovertheInternet, andthere's a reasonwhyhe's UDPTCPmightcoverin a latervideo, andthenthatgetswrappedupasanother I p packet.
Thatgivesusis a privatepartywhenwegetthevirtualpartbecausewe'resendingitovertheInternetovervirtuallywe'vecreatedjustusing a standardInternetconnection.
Youhavetosetupyourcorporatenetworkssothatitknowsthatpacketsgointothisparticular I p addressneedtogooutfor a reversalprivatenetworklinkandsowecansenditoutoverthere.
Andthisiswhatpeopleuseathome, withtheirusing a VPNtoprotecttheirconnectionsothatallyourtrafficissentoverthevirtualprivatenetwork, andthenitappearsasifit's leavingfromthebusinessnetworkwhereit's comingoutwiththeir I P addresses, eventhoughactuallythemachinesin a differentlocation.
Sowherethere's a normalnetworkconnectionthesedays, weconnect a WiFifactoriesthatyouimmediatelyconnectedtothenetwork.
Thatmaybesomeaccesscontrolstheirthiosaywhetheryoucanactuallyuseitinsanethingsandwhoeverthetechnologyimmediatelyconnectsyouwith a virtualprivatenetwork, youhavetosetthatconnectionwhenyousetupthatvirtualconnectionwithserveratthecompany, endontheclimbtotheremoteandskin, figuringthedetailssotheyknowwherethe I P addresseswaytosendthosewrappeduppacketsbackoverthenetwork.
I understandwhat's beingachievedthere, butdoesthisrunintoanyproblemsatall?
ItwillhavelaterCTUconnectionbecauseyougottosend a packettotheVPNserverandthenouttoitsdestinationit, ladlegacy, dependingonhowbadthenetworkis, whereyouare, thatmanshouldbefasterbecauseyourbusinessgot a fasterconnection.
Thatmightbe a moredirectroutethanyougoingdirectly.