VDI vs. VPN Comparison – A Parallel Reality of Parallels?

In this article, I will attempt to compare two technologies that are completely different in their purpose: VDI and VPN. I have no doubt that due to the pandemic that unexpectedly hit us all in March of this year, specifically the necessity to work from home, you and your company have already made your choice on how to optimally ensure comfortable working conditions for your employees.

VDI vs. VPN Comparison – A Parallel Reality of Parallels?
The writing of this article was inspired by reading a comparative 'analysis' of the two technologies on the Parallels company's blog,VPN vs VDI – What Should You Choose?, specifically its incredible bias, without even the slightest claim to impartiality. The first paragraph of the text is titled 'Why a VPN solution is becoming outdated,' followed by 'VDI advantages' and 'VPN limitations.'

My work is directly related to VDI solutions, primarily with products from Citrix. So the direction of the article should have appealed to me. However, such bias only evokes my dislike. Dear colleagues, is it possible to see only disadvantages in one technology and only advantages in the other when comparing two? How can one take seriously everything a company like this says and does after such reasoning? Have the authors of such 'analytical' articles never encountered popular IT phrases like 'use case' or 'it depends'?

The advantages of VDI according to Parallels:

The mentioned advantages of VDI highlighted in the article (in my translation)

VDI provides centralized management of data.

  • What specific data? The purpose of VDI is to provide remote access to a virtual desktop. When using VPN to access the corporate network, for example to corporate SharePoint, the data will also be managed centrally.
  • Perhaps if by centralized data management we mean user profiles, then this statement is correct.

VDI provides seamless access to work files and applications using the latest encryption protocols.

  • What are you talking about, gentlemen? What are these latest encryption protocols from Parallels? TLS 1.3? Then what is VPN?

VDI eliminates the need for optimized bandwidth.

  • Seriously? If I understand correctly, it doesn't matter for Parallels RAS whether the user has two 4K 32" monitors or one 15" laptop? Such protocols as ICA/HDX (Citrix) and Blast (VMware) were created specifically for bandwidth optimization.

Since VDI is located in a data center, there is no requirement for "powerful end-user hardware" for the end-user.

  • This statement may be true, for example when using Thin Clients, but it is completely abstract and does not take various scenarios into account.
  • What is considered powerful end-user hardware in 2020?

VDI allows connections from various devices, such as tablets and smartphones.

  • Certainly a correct statement. But let's not be disingenuous; while it is somewhat possible to work from a tablet, working from a smartphone... only from certain smartphones with an external monitor.
  • The user's work should be comfortable and should not impair their vision. For example, I use a 28" monitor but plan to switch to a larger diagonal.
  • A laptop is currently the most popular computer for corporate use.
  • Let me remind you that VPN clients can be downloaded for both tablets and smartphones.

VDI provides access to Windows applications from other operating systems like Mac and Linux.

  • I believe the colleagues simply made a mistake; we are not talking about VDI at all, but rather about Hosted Application.
  • As for VPN, leading manufacturers like Cisco and CheckPoint certainly offer VPN clients for both Mac and Linux. Citrix also provides VPN, including for its VDI solutions.

Disadvantages of VDI

Deployment costs

  • additional hardware will be required, lots of hardware.
  • additional licenses will need to be purchased for both the base infrastructure (Windows Server) and for the VDI itself (Windows 10 + Citrix CVAD, VMware Horizon, or Parallels RAS).

Complexity of the solution

  • you cannot simply install Windows 10, name it a "golden image," and then just replicate it into X copies.
  • when designing, it is necessary to consider many nuances, from geographical location to assessing the actual needs of users (CPU, RAM, GPU, Disk, LAN, Software).

VDI vs. HSD

  • Why is the discussion focused solely on VDI, rather than Hosted Shared Desktop or Hosted Shared Application? This technology requires significantly fewer resources and is suitable in 80% of cases.

Disadvantages of VPN

There is no granular control for monitoring and restricting user access.

  • A VPN Client may have a sufficiently complex and granular access control mechanism, such as something like 'System Compliance Scanning, Policy Compliance Enforcement, End Point Analysis.'
  • Since the article discusses VDI, there is also no particularly granular control here; it’s quite straightforward—either access is granted or it is not.
  • Analytical systems have emerged that centrally monitor the situation based on data about VPN and other connections and alert to unusual user behavior. For example, an unusual or out-of-hours increase in bandwidth.

Corporate data is not centralized and is complex to manage.

  • Neither VDI nor VPN are designed for centralized management of corporate information.
  • I cannot imagine that critical information is stored on a user’s local computer in a serious company.

A high bandwidth connection is required.

  • I agree with this statement only partially. It all depends on the user’s work specifics. If they are streaming 4K video over the corporate network, then undoubtedly.
  • The real problem is that all internet traffic from remote users is routed through the corporate network. It might be worth attempting to set up a separate traffic channel.

The end user needs good hardware.

  • This statement doesn’t entirely hold true, as actual resource consumption depends on the configuration, but it is also minimal.
  • The VDI client also consumes resources, and it generally depends on the intensity of the user’s work.
  • In general, corporate users are provided with quality equipment based on a reasonable usage period and return on investment. When designing, the cost of such equipment should be less than the cost of downtime for the end user. No one plans to include obviously poor equipment in a project.

It is not possible to access Windows applications on other operating systems.

  • The reason for this statement likely lies in the fact that the colleagues are unaware that a VPN can be used on almost any modern platform – Windows, Linux, MacOS, iOS, Android, etc.

Criteria affecting the choice of one solution over another

Infrastructure for VDI

It seems that VDI proponents forget that substantial infrastructure is required for VDI, primarily servers and storage systems. Such infrastructure is not free. Its deployment requires careful selection of the necessary components according to your specific scenario.

User workspace

  • What should the user work on? Their personal laptop or a corporate one that they can take home? Or perhaps a tablet or thin client would suffice?
  • Can the user connect their home computer to the corporate network?
  • How can you ensure the security of the home computer and compliance with the company's security requirements?
  • What about the user's internet access speed (they may have to share it with other family members)?
  • Don’t forget that your company has different user groups, such as the sales department used to working from home, or the technical support department in the call center.

Necessary applications for work

  • What are the requirements for the user's main working applications?
  • Web applications, locally installed applications, or are you already using VDI, SHD, SHA?

Internet and other company resources

  • Does your company have enough bandwidth to serve all remote users?
  • If you are already using a VPN, can your equipment handle the additional load?
  • If you are already using VDI, SHD, SHA, are there sufficient resources?
  • How quickly can you scale up the necessary resources?
  • How to handle compliance with security requirements? Those working from home may not be able to meet all security standards.
  • How to handle technical support, especially if you decide to rapidly implement new technology for users?
  • You may be using hybrid cloud solutions and be able to redistribute some resources?

Conclusion

As you may notice from everything mentioned above, the right choice of technologies is a process based on a balanced assessment of many factors. Any IT specialist who categorically claims the unquestionable advantages of one technology over another simply demonstrates their unprofessionalism. I wouldn't waste my time conversing with them.

Dear reader, I wish you encounters only with competent IT specialists. Those who treat the client as a partner for long-term and mutually beneficial cooperation.

I am always open to constructive comments and describing your experience with the product.

Source: habr.com

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster