News & Events
June 2005
Michel Susai, the founder and former chairman and CEO of NetScaler, founded NeoAccel™ in March 2003 to "Secure Everything through secure access from anywhere to anything." The company is self-funded along with advance payments from OEMs, and is open to seeking additional capital. NeoAccel™ has been shipping revenue for three quarters and is already cash flow positive. The company has 50 employees.
To date, IPsec VPNs have been used primarily to provide site-to-site access and for key users; however, existing IPSec VPN solutions are too slow and require too much administration and support. For these reasons, enterprises would like to migrate from IPsec to SSL VPNs to provide secure access for all individuals, including mobile workers, those in remote locations and those using wireless networks within the enterprise. SSL VPNs provide great security, eliminate client-side management and are less expensive than IPSEC VPNs.
NeoAccel™ argues that conventional SSL VPNs do not support site-to-site access, are performance constrained because of inherent TCP-over-TCP meltdown and context-switching problems, and offer limited capacity and scalability using today's standard networking architectures. Conventional full-access SSL VPN transactions require multiple traversals of the TCP stack. As a result, tunneling application-layer TCP traffic over encrypted SSL TCP connections can result in "TCP-over-TCP meltdown," which can occur whenever TCP network becomes congested and connections time out.
In addition, problematic environments for conventional SSL VPNs include wireless LANs that are particularly sensitive to "wireless jitter" and secure access networks for remote and mobile workforces that are prone to peak-period congestion on last-mile DSL and cable networks. For these reasons, SSL VPNs have been installed only to provide limited access to Web applications for individual users in small-scale deployments.
NeoAccel™ is developing simplified, full-access SSL VPN technology that overcomes the performance limitations of conventional Web security mechanisms, enabling businesses to implement highly secure, scalable access with the native network performance of IPSec VPNs. NeoAccel's SSL VPN provides complete access to all missioncritical enterprise applications, even those applications that run on legacy systems.
The company recently introduced its flagship product, SSL VPN-Plus™, which is claimed to be the only network security software platform to provide the ASIC-class performance required to overcome the performance barrier that have kept SSL VPNs from replacing IPSec VPNs.
SSL VPN-Plus™ makes it feasible to deploy secure enterprise gateways using low-administration SSL VPN technology. Unlike conventional SSL VPNs, NeoAccel's SSL VPN-Plus™ can be deployed to provide high-performance access to all IP-based applications, including Citrix, database, legacy, and other "non-Webified" enterprise applications, even across latency-prone wireless LANs and congested public access networks. SSL VPN-Plus™ is particularly well suited for high-demand enterprise deployments that are known to choke the performance of conventional SSL VPNs.
SSL VPN-Plus™ is based on the NeoAccel's patentpending Intelligent Connection AccelerationT (ICA) technology, which eliminates the congestion-driven TCP-over-TCP meltdown and performance-sapping context switching associated with conventional SSL VPNs. The results are fewer dropped sessions and an improved user experience, particularly in wireless LAN environments or WAN environments where significant packet loss can produce a 30x performance drain on conventional SSL VPN gateways. SSL VPN-Plus™ provides complete application support, finely grained access control and administration, enterprise-class scalability and strong encryption.
ICA technology ensures that the SSL VPN-Plus™ gateway has complete control of the connections opened from remote client to the private network. This not only provides protection to the gateway machine, but also controls traffic to the private network. The SSL VPN-Plus™ policy engine controls, manages and governs all VPN sessions and packet processing.
SSL VPN-Plus™ sessions are click-and-alive with full application support for thin-client, fat-client and legacy applications, no performance-draining context switching, and high capacity without the TCP-over-TCP meltdown problem even in congested WAN and wireless LAN environments. Initially, SSL VPN-Plus™ supports more than 20,000 concurrent sessions, 1,700 new user logins per second and greater than 950 Mbps throughput using a 1 Gbit NIC.
Customer tests of SSL VPN-Plus™ show that NeoAccel™ achieves from 6x to 30x better performance than conventional SSL VPNs. The greater the packet loss problem (averages up to 20% on wireless LANs), the greater the performance improvement provided by SSL VPN Plus.
Several companies, such as Aventail, supply SSL VPN appliances. NeoAccel™ claims to be the only provider to solve the TCP-over-TCP meltdown problem. NeoAccel™ technology splits the connection, and the company argues that it holds unique know how that has escaped the reach of other vendors. Michel Susai argues that he mastered TCP proxy technology while at Netscaler, who's appliances have become industry standards.
NeoAccel™ will deliver SSL VPN-Plus™ as an OEM friendly software appliance that enables suppliers of firewalls, VPNs and other edge-facing devices to deliver the functional benefits of conventional IPSec VPNs with the ease of use and zero-client administration of SSL VPN.
SSL VPN-Plus™ Release 4 supports popular Linux distributions running on mainstream system and processor families with optional SSL acceleration hardware based on chips from vendors such as Cavium and Broadcom. As a result, the SSL VPN-Plus™ platform architecture is well suited for integration and deployment as part of vendors' existing solutions. Various versions range from the Pentium iV or AMD Athelon-based Enterprise Edition to the i386 class SMB Edition, SOHO Edition, Clientless Edition and Thin-Client Edition.
An early availability edition is available now; general availability is scheduled for June 2005; prices start at $4,000 for 10 users. The early release is currently in evaluation by a growing list of networking, security and IT solutions providers.
Arul Valan
Sudha Karunakaran
Peter Hertan
GM , NeoAccel India
EVP, Operations & Finance
VP of Marketing and Sales
Tel: 408.270.8000
Fax: 408.274.8044
p: +1 (408) 274 8000 / f: +1 (408) 274 8044 / e: sales@neoaccel.com / Directions
