Security Basics mailing list archives

Re: SSL VPN


From: Jurgen Vermeulen <jurgen () vermeulen-debondt be>
Date: Wed, 16 Jan 2008 20:31:15 +0100

Paul Hosking wrote:
It depends on what functionality you're choosing to use; "SSL VPN"
products tend to offer a bundle of fairly different remote access
solutions.  If you're doing something like web rewrites (kind of like
using a web-based web browser) then it's just the single IP address
involved.  If you use a full VPN like Juniper's Network Connect, then
you have an additional IP address assigned to a virtual adapter on the
user's system.

I've had a lot of positive experience with Juniper's IVE product line.
It is highly configurable and offers a number of different access
solutions (web rewrite, JAVA / ActiveX tunnels, RDP / Telnet / SSH
clients, web-based SMB / NFS file access, Network Connect - full VPN).
It has become something of a swiss army knife of remote access -
allowing us to tailor the solution to specific needs.  We can allow some
people full access and limit others to only the specific resource they
need.

I perform installations of most Juniper and check Point solutions. I must say both Check Point's Connectra and Juniper's IVE are good products. We also have a few Cisco SSL installations but I don't have any hands-on experience with it.

If you already have Check Point firewalls running, you can easily integrate Connectra management on the SmartCenter (on R65), however the IVE does have a lot more configuration options and a nice variety of appliances, combined with a decent web GUI. A simple SA-700 has basic clientless access and on top of that, you get the network connect IPSEC like solution. If you don't have too many users, this is mostly the ideal solution. Put it in the DMZ and use a new private range for the network connect clients.

If your users don't have admin privileges, you have the option to push an installer service to the pcs. Once installed, all Juniper applications like NC, SAM, host checker, ... can be installed/upgraded with regular user rights.

If you're not 100% sure if it fits your needs, try to arrange a try-and-buy solution or demo.

Kind regards,
Jurgen


Current thread: