Thursday, November 6, 2008, 02:47 PM -
TechnologyPosted by Administrator
Few days ago I attanded a training on PortWise SSL VPN.Here, are some important points for the same.
First, for the VPN technologies there are two options available.Those are IPSEC VPN and SSL VPN.In IPSEC VPN the client is mainly
static that means the VPN software has to be installed on the machine where you have to access VPN.So it gets pretty difficult when the user is roaming like the sales guys.
So for the roaming clients there is option available which is SSL VPN.In SSL VPN a small tiny Activex cleint gets loaded which is used for getting the access to the main VPN server through
any browser.
Here is some information on PortWise SSL VPN product.
There are mainly six stages from connection establihment to termination.
The first one is Assess the client machine from which the connection will get established.
There are some conditions which has to be satisfied before allowing the access to your internal nework via VPN.The requirements
can be a specific Antivirus software with latest virus definitions, specific Operaing System with lates patches, Specific Antispyware
with latest definitions, or a specific MAC address.If these conditions are not met then the connection does not get established between client and the VPN server.
These connections simply get refused.
The second one is Authenticate.
It supports following authentication methods
1.Integrated authentication
PortWise Web, Synchronized, Challenge, Mobile Text, and Password
2.Third party client authentication
RADIUS
3.Third party server authentication
RSA SecurID, SafeWord, Active Directory, LDAP etc.
4.Public Key Infrastructure (PKI)
Multiple Certificate Authority (CA) support
Certificate Revocation List (CRL), Control Distribution Point (CDP) support
The third one is Authorize stage.
It determines which applications a user gains access to.
It supports
Policy based authorization based on:
-Group Membership
-AuthenticationType
-Source IP Address
-Date & Time
-Assessment
It Integrates with existing infrastructure It may be Microsoft Active Directory, OpenLDAP, Novell eDirectory Services, etc.
Next stage is Access.It creates a secure encrypted network tunnel between the users device and the application
It supports Mainframe, Client/Server, Web, Terminal Server and File Server application support
Portal-based to mask complexity
Extensible API for custom development
PortWise Access Client
Native Windows, pure Java (Mac/Linux), native Symbian and Pocket PC
The next stage is Audit.
You can audit who accessed which application, when they did it, and what was downloaded
Features are
-Central logging
-Log Viewer
-Debug logging capability
-UNIX syslog/Windows event log
The last stage is Abolish.
In this stage ALL traces of access to the corporate network on completion of the session are removed.
Browsers are renowned for creating a “snail trail” of information during an access session
All traces of access including below are eradicated:
-Cookies
-URL history
-Cached Pages
-Registry Entries
-Downloadable Components
The PortWise network consists of following services.
Administration service,Access point, Policy service, and Authentication service.
These services can be run on either one server or on different servers.The best practice is to keep them on different servers.
The Administrative service provide below things
-Web-based administration interface
-Task-oriented approach
-Wizards for common tasks
-Interface adapted to features included in the license
-Context-sensitive online user assistance
Access point service Handles access decisions, Web access. WAP access, Access Client
You can configure authorization settings and set encryption level, protect specific paths with access rules
Under Policy service you can manage security policies, access rules, users.
Security policy management
-Authenticates
-Audits
-Validates certificates as well as digital signatures
Access rules
-Who wants access
-Which resource is requested
-Through which communication channel
-Which authentication method is required
-User Management
Authentication service manages authentication.The supported authentication methods are
-Web
-Mobile Text
-Challenge
-Synchronized
-Password
It also supports Radius based authentication.
Other categories
Cisco Jokes Photos Tutorials Voip Goa