---
title: "General information about the GOST VPN service"
sidebar_label: "General information"
sidebar_position: 1
description: "Basic information about the GOST VPN service: description, operating principle, hardware, areas of responsibility, cost"
---

import Tabs from '@theme/Tabs'
import TabItem from '@theme/TabItem'
import {TabItemLabel} from '@selectel/docux/components'
import {CustomTable} from '@selectel/docux/components'
import Formbricks from '@theme/MDXComponents/Formbricks'

# General information about the GOST VPN service

GOST VPN is a service for establishing a secure connection between your infrastructure in Selectel and infrastructure located at an external site. Information transmitted through the secure connection is encrypted via GOST according to the requirements of the FSB and FSTEC of Russia.

[Hardware](#hardware) ViPNet Coordinator is used to establish secure network interaction. Selectel provides and configures hardware only on its side. We do not install or configure hardware and software at external sites; see more in the [Areas of Responsibility section](#areas-of-responsibility).

To [connect the GOST VPN service](/gost-vpn/connect-gost-vpn.mdx), ViPNet Coordinator hardware must be installed and configured at the external site in compliance with the [requirements](#external-hardware-requirements).

If you need to organize a secure connection to your infrastructure in Selectel, you can use the [GOST VPN Remote Access](/gost-vpn/connect-remote-gost-vpn.mdx) service. As part of this service, we configure a secure connection between a ViPNet Coordinator in Selectel and our partner's ViPNet Client.

## Tasks solved \{#tasks-to-be-solved}

GOST VPN helps to:

* organize a secure GOST-compliant connection for data transmission between your infrastructure in Selectel and infrastructure at an external site: telecom operators, government agencies, banks, hospitals, commercial biometric systems, and others;
* comply with the requirements of Russian legislation regarding data security.

GOST VPN Remote Access helps to:

* organize a secure remote GOST-compliant connection for your employees to work and for administering your infrastructure in Selectel;
* comply with the requirements of Russian legislation regarding data security.

## Operating principle \{#principle-of-operation}

In Selectel, the ViPNet Coordinator cryptographic information protection tool (CIPT) and your infrastructure are connected via a private L3 network using a [global router](/global-router/). If you need to set up network connectivity between a ViPNet Coordinator and a server in Selectel directly via L2, you can place a dedicated server in a [certified data center segment](/certified-data-center-segment/).

The connection scheme and service selection depend on the tasks you need to solve:

* [GOST VPN](#gost-vpn) — a secure site-to-site connection is configured between your infrastructure in Selectel and the infrastructure at an external site;
* [GOST VPN Remote Access](#remote-gost-vpn) — a secure client-to-site connection is configured from a remote workstation to your infrastructure in Selectel.

### GOST VPN \{#gost-vpn}

A [cross-network interaction agreement](https://files.selectel.ru/docs/ru/gost-vpn-inter-network-interaction-approval.pdf) is concluded between Selectel and the network owner at the external site.

Under this agreement, your infrastructure in Selectel and the infrastructure at the external site are combined into a private network. ViPNet Coordinator CIPTs are installed as gateways on each side to route and process traffic for the secure channel.

![](https://423.selcdn.ru/kb/gostvpn-about-gost-vpn-principle-of-operation-LANG-THEME.png)

### GOST VPN Remote Access \{#remote-gost-vpn}

A direct agreement is concluded between you and our partner for the provision of ViPNet Client software based on the number of remote workstations. Under this agreement, a secure communication channel is created between the ViPNet Coordinator in Selectel and the ViPNet Client provided by our partner, through which information is transmitted in encrypted form. To access your infrastructure in Selectel, you must connect from a remote workstation using ViPNet Client. Compatibility of ViPNet Client software with various operating systems, devices, and platforms can be found in the official documentation for [ViPNet Client](https://infotecs.ru/products/vipnet-client-4u/) by InfoTeCS.

![](https://423.selcdn.ru/kb/gostvpn-about-gost-remote-vpn-principle-of-operation-LANG-THEME.png)

## Hardware \{#hardware}

If different ViPNet security equipment (SKZI) models are installed in the Selectel data center and at the external site, the channel bandwidth and protection class will match the specifications of the less powerful model.

### Hardware in Selectel data centers \{#hardware-in-selectel-data-centers}

As part of the service, hardware models from the ViPNet Coordinator HW 4 line from InfoTeCS are provided in Selectel data centers. The equipment holds the following certificates:

* FSB of Russia — protection class KS3;
* FSTEC of Russia — firewall type A.

<CustomTable>
  <table>
    <thead>
      <tr>
        <td />

        <td><strong>**HW100C(N)**</strong></td><td><strong>**HW100C(Q)**</strong></td><td><strong>**HW1000**</strong></td><td><strong>**HW1000 D**</strong></td><td><strong>**HW2000**</strong></td><td><strong>**HW5000**</strong></td>
      </tr>
    </thead>

    <tbody>
      <tr>
        <th>Platform</th><td>N1</td><td>Q1</td><td>Q7</td><td>Q9</td><td>Q5</td><td>Q2</td>
      </tr>

      <tr>
        <th>L3 VPN bandwidth, Mbit/s</th><td>175</td><td>400</td><td>915</td><td>2500 `*`</td><td>6600</td><td>10 000 `*`</td>
      </tr>

      <tr>
        <th>L2 VPN bandwidth, Mbit/s</th><td>175</td><td>400</td><td>915</td><td>2500 `*`</td><td>6000</td><td>10 000 `*`</td>
      </tr>

      <tr>
        <th>Firewall, Mbit/s</th><td>930</td><td>1400</td><td>930</td><td>2800 `*`</td><td>9200</td><td>13 000 `*`</td>
      </tr>

      <tr>
        <th>Interfaces</th><td>4 x RJ-45<br />1 x SFP</td><td>4 x 1G RJ-45<br />2 x 1G SFP</td><td>6 x RJ-45</td><td>8 x RJ-45<br />4 x SFP</td><td>4 x RJ-45<br />4 x SFP<br />4 x SFP+</td><td>4 x RJ-45<br />8 x SFP+</td>
      </tr>
    </tbody>
  </table>
</CustomTable>

`*` When combining two or more physical network interfaces

### Requirements for hardware at an external site \{#external-hardware-requirements}

To organize a secure channel at an external site, any of the ViPNet Coordinator models—hardware (HW) or virtual (VA)—must be used. Selectel does not rent out equipment or software for use at external sites. To select and purchase equipment and create a ViPNet network, you can engage one of the [official partners of the ViPNet manufacturer](https://infotecs.ru/partners/?filter%5Bp-type%5D%5B%5D=4\&filter%5Bp-status%5D%5B%5D=3\&PAGEN_1=1).

## Areas of responsibility \{#areas-of-responsibility}

The distribution of responsibility depends on the service — GOST VPN or GOST VPN Remote Access.

<Tabs queryString="areas-of-responsibility">
  <TabItem value="areas-of-responsibility-gost-vpn" default>
    <TabItemLabel>
      GOST VPN
    </TabItemLabel>

    <CustomTable>
      <table>
        <tbody>
          <tr>
            <th>Selectel</th>

            <td>
              * provides ViPNet Coordinator HW and places it in a Selectel data center;
              * configures connection of ViPNet Coordinator HW in a Selectel data center to the internet and local network;
              * maintains the operability of equipment, local network, and internet connection, and replaces equipment in case of failure;
              * installs software updates on ViPNet Coordinator HW in a Selectel data center;
              * modifies traffic rules on ViPNet Coordinator HW upon request from a Selectel user
            </td>
          </tr>

          <tr>
            <th>Selectel user</th>

            <td>
              * rents infrastructure in a Selectel data center;
              * configures a global router for their infrastructure in Selectel;
              * organizes signing of an agreement between Selectel and the network owner at the external site;
              * organizes interaction between Selectel and the network owner at the external site after the agreement is signed;
              * provides information for configuring network connectivity and rules on ViPNet Coordinator HW
            </td>
          </tr>

          <tr>
            <th>Network owner at the external site</th>

            <td>
              * signs consent to exchange cross-network information;
              * places SKZI equipment on their side;
              * organizes and administers the ViPNet network on their side;
              * transmits the cross-network master key and cross-network information;
              * imports the cross-network information received from Selectel
            </td>
          </tr>
        </tbody>
      </table>
    </CustomTable>
  </TabItem>

  <TabItem value="areas-of-responsibility-remote-gost-vpn">
    <TabItemLabel>
      GOST VPN Remote Access
    </TabItemLabel>

    <CustomTable>
      <table>
        <tbody>
          <tr>
            <th>Selectel</th>

            <td>
              * provides ViPNet Coordinator HW and places it in a Selectel data center;
              * organizes cross-network interaction between our partner’s ViPNet networks and Selectel;
              * ensures exchange of cross-network information when connecting ViPNet Client;
              * installs software updates on ViPNet Coordinator HW in a Selectel data center;
              * modifies traffic rules on ViPNet Coordinator HW upon request from a Selectel user
            </td>
          </tr>

          <tr>
            <th>Selectel user</th>

            <td>
              * rents the necessary infrastructure in a Selectel data center;
              * concludes a contract with our partner for the installation and administration of ViPNet Client SKZI;
              * rents ViPNet Client from our partner;
              * configures a global router for their infrastructure in Selectel
            </td>
          </tr>

          <tr>
            <th>Our partner</th>

            <td>
              * fulfills the terms of the signed contract with the Selectel user for the installation and administration of ViPNet Client software;
              * purchases and configures ViPNet Client software;
              * transmits information to Selectel for organizing remote connection
            </td>
          </tr>
        </tbody>
      </table>
    </CustomTable>
  </TabItem>
</Tabs>

## Cost \{#price}

### GOST VPN \{#price-gost-vpn}

The cost of the GOST VPN service is affected by:

* ViPNet Coordinator HW model;
* number of cross-network connections;
* need for a high-availability cluster made of two ViPNet Coordinator devices.

The service cost can be viewed at [selectel.ru](https://selectel.ru/services/additional/gost-vpn/) or in the [Control panel](https://my.selectel.ru/security/gost_vpn): in the top menu click **Products** and select **GOST VPN**. If the model you need is not in the list, to calculate the service cost [create a ticket](https://my.selectel.ru/tickets/create/).

To pay for the service, depending on the account balance type, either a [unified balance](/balance-and-payments/balance.mdx#united-balance) or [main balance](/balance-and-payments/balance.mdx#balances-by-service-type) is used. The service is billed monthly; when ordering the service, the payment for the first month is deducted from the balance, and subsequent payments are deducted automatically at the beginning of each following period.

### GOST VPN Remote Access \{#price-remote-gost-vpn}

The payment for the GOST VPN Remote Access service consists of the cost of:

* [GOST VPN service](#price-gost-vpn). The service is billed monthly; when ordering the service, the payment for the first month is deducted from the balance, and subsequent payments are deducted automatically at the beginning of each following period;
* rental of our partner’s ViPNet Client — annually;
* installation of ViPNet Client by our partner — one-time.

To calculate the cost, [create a ticket](https://my.selectel.ru/tickets/create/).

<Formbricks />
