HOME LITERATURE MarketNotes
ZoneRanger: Secure Telnet & SSH Proxy Print
Even though web-based user interfaces have become very popular, the vast majority of network devices and servers continue to support Telnet, and/or its more security-conscious successor SSH, partly because some users prefer a command-line style of user interface, and partly because the command-line style is better suited to automation. As a result, a significant number of management applications are able to use Telnet and/or SSH to configure, control, or collect information from managed devices.

The common industry practice where networks are partitioned into security zones using conventional firewalls creates a problem for users of these management applications, requiring them to choose between two equally unacceptable alternatives: prevent Telnet and SSH from passing through the firewall, accepting limited ability to manage the devices beyond, or allow Telnet and/or SSH to pass through the firewall, accepting the associated security risks.

ZoneRanger resolves this dilemma, acting as a transport-layer proxy for Telnet and SSH traffic, enabling management applications to extend their reach beyond firewalls, while mitigating the associated security risks in a variety of ways:

  • ZoneRanger effectively breaks the underlying TCP transport connection that carries the Telnet and/or SSH traffic into two connections, helping to protect the management application from TCP-based attacks.
  • ZoneRanger allows management applications to originate Telnet or SSH sessions with managed devices, but connections in the reverse direction are not allowed.
  • ZoneRanger can be configured to restrict Telnet and SSH traffic to specified devices and ports.
  • ZoneRanger can be configured to perform destination port translation, allowing management applications to initiate Telnet or SSH sessions using standard well-known ports, to devices that have been configured to use non-standard ports as a security precaution (i.e. to fool/confuse port scanners).
Telnet / SSH diagram

In addition to enabling management applications to access command line interfaces for managed devices, ZoneRanger SSH proxy can also be used for secure file transfer (i.e. SCP, SFTP), reducing the need to use less secure protocols such as FTP or TFTP.

Telnet and SSH are part of a growing suite of management protocols supported by ZoneRanger. Other supported protocols include:

 

 

How does ZoneRanger fit into your network?

What others are saying...

"Tavve has developed the ZoneRanger product, in order to enable companies to leverage their centralized management infrastructure across firewall-partitioned networks, while mitigating risks associated with management protocols."
Tavve: ZoneRanger 
Subraya Mallya
PrudentCloud.com


"Without a more secure approach to managing the protocols and tools that manage the network - including the 'trusted' internal network - enterprises may be exposing themselves to more risk than they realize."

Scott Crawford, CISSP, ISSAP, ISSMP
Senior Analyst, Enterprise Management Associates

"ZoneRanger effectively extends the reach of management applications to devices located beyond firewalls, eliminating the need for complicated firewall configurations, extensive agent deployments, or expensive application replication. ZoneRanger also provides security, acting as an application layer proxy firewall, inspecting and validating the traffic relayed between applications and devices.
Jim Doble, CISSP
CTO, Tavve