logo
logo
Sign in

Static IP rush in Indian Retail: Convenience vs Resiliency & Security

avatar
COSGrid Networks
Static IP rush in Indian Retail:  Convenience vs Resiliency & Security

Post pandemic, the retail industry is making buzz with applications of metaverse, NFT, using Drones delivery and Social Commerce etc. Are we going to discuss it now? Nope, we’re not. But about the digital foundations for any trends and technologies that would come up! 

 

Retail industry has been adopting various business applications like CRM, ERP, HR, PoS integrations etc with Cloud fuelling the transformation. Today, they are on a mission to integrate all the biz functions and applications whether on-premises or on the cloud to get a 360 degree digital seamless operations enabled by booming SaaS start ups that provide aggregations and workflow integrations.


A lot of SaaS vendors such as payment processing offer webhooks for integrations with their customers and their partners. This is typically safe with sufficiently hosted security and protection.  


The software/SaaS vendors like PoS, CRM, food delivery aggregators etc also want their customers/partners to provides Public IP (of on-prem or cloud deployments) so that they can use 


 i. webhooks to push orders to the branch stores

 ii. Static IP as identity base - two-factor authentication! 

 

The problem starts with many software/SaaS vendors including POS vendors are asking for public IP as key requirements for on-prem/branch stores deployments. They do it because:


  •   Static IP is dead simple than VPN to configure  
  •   Remote Access to branch POS for vendors is not easy if in case of any issues 


Here are the key challenges in using plain Static IP in branch WAN for webhook type of integrations:


1. Published ‘Static IP’ fails: If WAN link provided by an Internet service provider A (ISP A) fails at peak time, the application completely stalls even though there are backup WAN links with static IPs from another ISPs B and/or ISP C. 


2. Cybersecurity attacks: Likely to lead to ransomware attacks, DDoS and Loss of Data at unpredictable times as the deployments are typically not secured with secure SD-WAN or Firewall/UTM. 


To address the above challenges, enterprises use the concept of Same IP failover. It’s a simple concept of making a public/private IP always reachable across the Internet without any dependency of particular ISP.  


Here, we have two approaches : 


  • Same IP failover using SD WAN tunnels ( Private IP) with integrated network security 


VPN tunnels encapsulates the IP packet with original headers and doesn’t carry the WAN link IP address (in the inner header). WAN link switchovers only impact the outer packet header and hence no change in the visible IPs in the private subnets.


  • Same IP failover using SD-WAN + Cloud Secure Web Gateway (for Public IP) ,


Public IP provided through Cloud Service Providers (CSP) are inherently resilient even in the case of ISP outage due to solid AS (Autonomous system) Number based BGP (Border Gateway Protocol) routing implementations. 


In addition to providing ‘Always’ available and secure connectivity for branch applications and operations, SD-WAN makes it extremely easy to manage the entire organization WAN connectivity from a single pane of glass. It makes even things easier with the ability to push the security policies across all the branches in one click!  At the same time, the above requires some initial planning and rollout efforts from IT teams so that it becomes easier to manage later. 


With upcoming AR/VR (Augmented Reality /Virtual Reality) use cases enabled by upcoming & growing Edge computing / 5G in the coming days, a resilient and automated SD-WAN Edge can help retail chains go a long way in operating better and serving customers better!  




 

collect
0
avatar
COSGrid Networks
guide
Zupyak is the world’s largest content marketing community, with over 400 000 members and 3 million articles. Explore and get your content discovered.
Read more