How It Works
In an unsecured network, client applications connect to their server(s) directly, as shown below:
In the above diagram, the client computer is located somewhere across the Internet. In order for it to reach a server inside the LAN,
such as the Web Server (192.168.0.8) or the Mail Server (192.168.0.65), the network traffic (originated by a network
application on the client computer, e.g. Internet Explorer or an email client program) has to traverse through
the Internet and the Firewall. If the Firewall allows traffic to the Web Server and/or Mail Server to go through, the client
is able to communicate with them.
The firewall in our diagram does not make network traffic between the client computer and the servers secure.
The function of the firewall is essentially to block unwanted traffic or network connections. If the destination of a network connection
is allowed, the firewall lets it go; otherwise the connection is blocked. That's what firewalls do. It has nothing to
do with protecting the bits and bytes that flows in the network pipes.
Many network protocols such as HTTP, FTP, POP, SMTP, etc. are clear-text protocols. When you transmit
anything - including your username and passwords - through such protocols, information sent from either side of
the connections is put on the network carrier as is, without any protection added.
With the introduction of K-Secure VPN™, all network traffic are encrypted and compressed before they go out
of the client machine, as shown in the following diagram.
In this diagram a K-Secure VPN™ Client is running on the client computer and network traffic are encrypted
and compressed. Only the corresponding K-Secure VPN™ Server can decompress and decrypt the traffic and, depending
on the VPN rules configured on the server machine, only certain destination are accessible to the clients.
It must be mentioned that because such decompression and decryption happen in
a secure environment, e.g. inside the company LAN, data sent and received over the public network are free from
being eavesdropped.
The security provided by K-Secure VPN™ Client is transparent to network applications. With a
K-Secure VPN™ Client running on the client machine, existing network applications suddenly send and receive
data in a secure environment - without themselves even knowing of it. There is no need to modify or reconfigure
such network protocols and/or applications.