HTTPS vs. VPN for communication between business partners?

Posted by Andrew H on Server Fault See other posts from Server Fault or by Andrew H
Published on 2009-08-14T13:47:41Z Indexed on 2011/01/13 7:54 UTC
Read the original article Hit count: 238

Filed under:
|
|

A business partner has asked to set up a site-to-site VPN just so that a few servers can communicate with each other over HTTPS. I'm convinced this isn't necessary, or even desirable. To be fair it must be part of a wider policy, potentially even a legal requirement. However I'd like to convince them to simply offer an IP to us (and us only) and a port of their choosing for HTTPS.

Has anyone had a similar experience, or had to come up with a cast-iron argument against a VPN?

Allow me to expand a little - we have a web service that initiates a connection to the partner's corresponding service using an encrypted HTTP connection. The connection uses a client certificate to authenticate. The connection is firewalled so only our IPs can contact the service. So why is a VPN necessary?

© Server Fault or respective owner

Related posts about vpn

Related posts about http