<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Strategies for Software-as-a-Service (SaaS), Governance Risk and Compliance (GRC), Open Source&#124; PrudentCloud &#187; spoofing</title>
	<atom:link href="http://www.prudentcloud.com/tag/spoofing/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.prudentcloud.com</link>
	<description>Software-as-a-Service (SaaS), Governance Risk and Compliance, Cleantech are becoming critical decision points  in companies. PrudentCloud will help you make some of these strategic decisions.</description>
	<lastBuildDate>Thu, 29 Jul 2010 20:44:12 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Tavve: Zone Ranger</title>
		<link>http://www.prudentcloud.com/solutions/security/tavve-zone-ranger-28052009/</link>
		<comments>http://www.prudentcloud.com/solutions/security/tavve-zone-ranger-28052009/#comments</comments>
		<pubDate>Thu, 28 May 2009 21:11:27 +0000</pubDate>
		<dc:creator>Subraya Mallya</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Configuration Management]]></category>
		<category><![CDATA[DMZ]]></category>
		<category><![CDATA[HP Open View]]></category>
		<category><![CDATA[Network Management]]></category>
		<category><![CDATA[PCI-DSS]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[Proxy firewall]]></category>
		<category><![CDATA[Security Zones]]></category>
		<category><![CDATA[spoofing]]></category>

		<guid isPermaLink="false">http://www.prudentcloud.com/?p=1047</guid>
		<description><![CDATA[IT Management has become a critical need in companies that leverage extensive technologies to meet their business demands. Change Governance, Security, Automation and Service Delivery are the key focus areas for IT organizations. With global networks, companies have to contend with securing the network to protect their intellectual property, data and corporate assets.
As security has [...]]]></description>
			<content:encoded><![CDATA[<p>IT Management has become a critical need in companies that leverage extensive technologies to meet their business demands. Change Governance, Security, Automation and Service Delivery are the key focus areas for IT organizations. With global networks, companies have to contend with securing the network to protect their intellectual property, data and corporate assets.</p>
<p>As security has risen to the forefront of IT concerns, firewall-based network partitioning has become a security best practice; unfortunately, firewalls either create a barrier which defeats the goal of centralized management, or must be configured to allow management protocol traffic, which defeats the goal of security, due to the inherent insecurity of management protocols (lack of strong authentication/encryption, ease of spoofing).</p>
<p>Partitioning networks using firewalls is a standard IT practice adopted, but with that comes a management dilemma. Management professionals need to configure, monitor, and control devices and servers regardless of their network location, but security professionals typically resist creating firewall rules to accommodate management protocols, due to associated vulnerability concerns. So how can companies leverage their existing management infrastructure across the entirety of their firewall-partitioned network, without compromising security?</p>
<p><a title="Tavve - Zone Ranger" href="http://www.tavve.com/" target="_blank" rel="nofollow">Tavve</a> (pronounced &#8220;TAH-vay&#8221;) has developed the <strong><a title="Tavve - ZoneRanger" href="http://www.tavve.com/index.php/products/zoneranger" target="_blank" rel="nofollow"><strong>ZoneRanger</strong></a></strong> product, in order to enable companies to leverage their centralized management infrastructure across firewall-partitioned networks, while mitigating risks associated with management protocols.</p>
<p>Recently we had a chance to meet with <strong>Jim Doble</strong>, CTO and Chief Architect, <strong>Donnie Goins</strong>, CEO of Tavve and discuss about ZoneRanger and their company.</p>
<p>Here is an excerpt from the interview.</p>
<p><span style="color: #800000;"><strong>SM:</strong></span> <strong><em>So let us start at the beginning &#8211; what is Tavve&#8217;s raison d&#8217;etre ?</em></strong></p>
<p><span style="color: #008000;"><strong>JD:</strong></span> Tavve has been providing solutions that enhance and augment third party network management applications for over ten years. More recently, we have seen companies that had made significant investments in centralized management infrastructure struggling with the management vs security dilemma. They want to leverage their management investment across the entirety of their networks, regardless of firewall-based partitioning, but they don&#8217;t want to compromise the security of their networks. To resolve this dilemma, Tavve has developed the ZoneRanger product, which serves to extend the reach of existing centralized management applications, while mitigating security risks associated with management protocols.</p>
<p><span style="color: #800000;"><strong>SM:</strong> </span><strong><em>Who is your target market? Is there are a specific industry vertical that you focus on?</em></strong></p>
<p><strong><span style="color: #008000;">JD:</span></strong> The typical ZoneRanger customer is managing a heterogeneous network, making use of a variety of management applications from a variety of vendors, and at the same time has a strong business need for network security, based on industry mandates, or simply the nature of their business. Current customers include financial services institutions, health care companies, managed service providers.</p>
<p><span style="color: #800000;"><strong>SM:</strong> </span><strong><em>How do you see yourself in a HP NNM, Cisco Network Management environment?</em></strong></p>
<p><span style="color: #008000;"><strong>JD:</strong></span> Interestingly enough, Tavve started out as a provider of enhancements and add-on tools tightly integrated with HP OpenView NNM and Tivoli NetView. With ZoneRanger, we made a strategic decision to provide a transparent proxy solution that would be able to work with a wider variety of management applications, without requiring custom development to integrate with specific applications. As a result, our customers have been able to use ZoneRanger with many different management applications, including HP OpenView NNM, CiscoWorks, Concord eHealth, and many more.</p>
<p><span style="color: #800000;"><strong>SM:</strong></span> <strong><em>So are you saying that all the large companies are out there have this problem and need your solution?</em></strong></p>
<p><strong><span style="color: #008000;">JD:</span> </strong>Let me explain the problem in a little more detail and you will see why. IT organizations are typically charged with providing great service, continuity and meeting SLAs, while at the same time reducing costs. In order to accomplish this, most organizations have invested heavily in management tools to automate the necessary processes. No single vendor or tool provides the complete, best answer, so most of these companies have purchased a variety of tools from different vendors. At the same time, regulatory and corporate security mandates have resulted in the partitioning of corporate networks into zones with different levels of trust. For example, companies that provide an internet presence place their web servers in the DMZ. Given that the DMZ is exposed to the internet, it has a greater risk of compromise, so a firewall is placed between the DMZ and the internal corporate network. The presence of this firewall makes it difficult for management applications in the internal corporate network to manage the devices and servers in the DMZ. You can open up the firewall to management protocol traffic, but that defeats the purpose. You can deploy additional copies of management applications in the DMZ but that increases cost and defeats the goal of centralized management. By placing a ZoneRanger in the DMZ you get the best of both worlds: you get the benefits of centralized management, and you don&#8217;t need to open up the firewall to permit management protocols. And the DMZ is just one example. The same problem arises wherever firewall-based network partitions are introduced, whether it be to meet industry requirements such as PCI DSS, or simply to isolate departments that handle sensitive information, such as HR or accounting. So in short, the answer to your question is yes. Management tools are everywhere, firewalls are everywhere, and we believe the best solution for them to co-exist happily is ZoneRanger</p>
<div id="attachment_1191" class="wp-caption alignleft" style="width: 620px"><img class="size-full wp-image-1191" title="partitioned-networks" src="http://www.prudentcloud.com/wp-content/uploads/partitioned-networks.png" alt="A typical partitioned network" width="610" height="406" /><p class="wp-caption-text">A typical partitioned network</p></div>
<p><span style="color: #800000;"><strong>SM:</strong></span> <strong><em>So how is Zone Ranger different from a agent based architecture?</em></strong></p>
<p><strong><span style="color: #008000;">JD:</span> </strong>The problem with agents is that everybody has their own.  If you have management applications from ten different vendors, you will have ten different agents, and typically these agents are neither simple nor cheap. With ZoneRanger, you have a single solution that works with all of your management applications.</p>
<p><span style="color: #800000;"><strong>SM:</strong></span> <strong><em>That would make the whole configuration and change management easy. Wouldn&#8217;t it?</em></strong></p>
<p><span style="color: #008000;"><strong>JD:</strong> </span>Exactly. In fact, some of our customers like ZoneRanger because it simplifies the process of configuring access restrictions on managed devices.  Given that all management protocol transactions are proxied through the ZoneRanger, managed devices can be configured to permit access from the ZoneRanger and nothing else. Management applications can be added, removed, or changed, but there is no need to modify the access control lists in the managed devices, because all management traffic is funneled through the ZoneRanger.</p>
<p><span style="color: #800000;"><strong>SM:</strong></span> <strong><em>Talking about some of the trends, Cloud Computing is all the rage now. Some of your customers must be considering Cloud based services. Have you certified ZoneRanger with say Amazon Cloud or Rackspace Cloud? If not what are your plans to support them?</em></strong></p>
<p><span style="color: #008000;"><strong>JD:</strong></span> Most of our existing customers are in the financial services space, and as you can imagine, they are pretty conservative when it comes to doing things outside their own networks. That being said, when critical functionality is migrated into a cloud, the functionality needs to be managed, and ZoneRanger, or a repackaging of ZoneRanger technology, may provide the answer for doing that securely.</p>
<p><span style="color: #800000;"><strong>SM:</strong></span> <strong><em>Let&#8217;s talk about business. What is your primary channel for sales? Your salesforce or do you have channel partnerships?</em></strong></p>
<p><span style="color: #008000;"><strong>DG:</strong></span> Our primary sales channel is our direct sales force.  We value the close relationships we develop with our customers using the direct sales model.  We&#8217;ve started partnering with MSPs and we believe it gives us an opportunity to reduce our sales cycle because the MSPs have customer accounts and know of the problem they are trying to solve.  The MSPs like the ZoneRanger  because of the additional services they sell to their existing customers.</p>
<p>SM: <em>Excellent. Thanks a lot for your time and information you shared on ZoneRanger. </em></p>
<h2><span style="color: #003366;">Company Profile</span></h2>
<table style="text-align: right;" border="1" cellspacing="1" width="95%">
<tbody>
<tr>
<td class="tablecellprompt" valign="top">Name:</td>
<td class="tablecelldata" style="text-align: left;"><a href="http://www.tavve.com" target="_blank" rel="nofollow"><img class="alignleft" src="http://www.tavve.com/templates/tavve/images/tavve-logo.png" alt="Tavve - Secure Management Appliances" width="180" height="63" /></a></td>
</tr>
<tr>
<td class="tablecellprompt" valign="top">Product</td>
<td class="tablecelldata" style="text-align: left;"><strong>ZoneRanger</strong>, a management proxy firewall provides a cost-effective and secure solution to extend the reach of management applications through firewalls.</td>
</tr>
<tr>
<td class="tablecellprompt" valign="top">Key Customers</td>
<td class="tablecelldata" style="text-align: left;">International Banks, Credit Card Companies, Defense Contractors, HealthCare providers</td>
</tr>
<tr>
<td class="tablecellprompt" valign="top">Critical Problem Solved</td>
<td class="tablecelldata">
<ul style="text-align: left;">
<li>Simplify and streamline the management of technologies deployed in partitioned firewall environments</li>
<li>Reduce the Security risk involved in managing technology components in the DMZ, Firewall environment</li>
<li>Reduce costs incurred due to deploying multiple installations of management applications.</li>
</ul>
</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.prudentcloud.com/solutions/security/tavve-zone-ranger-28052009/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
