JuniperForum.com
July 29, 2010, 07:47:03 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: If you have an interesting idea for an article or knowledgebase entry, please submit it!
 
  Home Help Login Register  
* *
Pages: [1]
  Print  
Author Topic: SA 2500 Questions  (Read 757 times)
vp911
Newbie
*
Posts: 1


View Profile
« on: February 19, 2010, 11:09:16 AM »

The company I work for made the mistake of buying a Barracuda SSL VPN device which has been nothing but trouble (disconnects, network connect not working on half the OSs, etc.)

I have a few questions I need clarified about the SA 2500. Please forgive me if some of these have been answered already.

1. Does the network connect ACTUALLY work on all OSs? Specifically we use the following: Windows XP, 7, Vista, Mac OS X (Snow), Ubuntu 9.10 AND CentOS 5

2. Can we route ALL traffic through the network connect? We want it to be the gateway for our remote users so all their traffic appears on our IP subnets (essentially acting as a proxy)

3. Does anybody have thoughts on lower cost alternatives to RSA for two factor support?

4. Remote Desktops / Terminal Services - can we set this up without using RADIUS? Basically we give RDP access to all of our remote techs; however, we don't need to give them individual user/passes, we want to hard code one user/pass login for them.

5. Are there RDP clients built in for Linux and Mac? i.e. Microsoft has a client for mac which the Barracuda uses, and then the Linux uses use Rdesktop.

6. Are there options to use the VPN on a iPhone? Or would we need to setup a separate PPTP/LT2P server for this?

7. For those users who use network connect, is it possible to setup the web interface to just add "bookmarks" - i.e. there are some fairly complex internal applications which haven't worked properly through other SSL VPNs via web forwards, but we have a TON of internal apps, so some users will use network connect to gain local access to the network, but we want the interface to give them essentially direct bookmarks so they don't need to have an updated bookmark list on their laptop.

8. Can we set it to allow the use of a public IP range rather than an internal range?

Logged
alan
Hero Member
*****
Posts: 795


View Profile WWW
« Reply #1 on: March 01, 2010, 06:13:01 PM »

1. Code 6.5R3.1 works will all the O.S. mentioned except I have not tested CentOS 5
2. Yes. Network Connect is a full layer 3 VPN
3. Nope, we use RSA. Soft tokens are cheaper.
4. Limit RDP access with a Role. I'm sure you can use RADIUS but I haven't done this.
5. You can do Java applets for RDP.
6. Activesync is supported, don't use it. There's an RSA client for free in the App Store.
7. Yes, bookmarks work fine but do behave a bit differently as a bookmark is forced thru the rewrite engine (unless you explicitly exclude).
8. Not clear what you mean. The assigned IP pool must be routable on your internal network so doubt this will work if the IP range is outside.
Logged
c3lin3
Newbie
*
Posts: 36


View Profile
« Reply #2 on: March 02, 2010, 12:33:44 PM »

I have some comments:

3. ActivIdentity
8. You can configure the gateway dual homed (external port facing the internet - internal port pointing to your network)
Logged
spacyfreak
Sr. Member
****
Posts: 472


View Profile
« Reply #3 on: March 02, 2010, 01:47:26 PM »


1. Does the network connect ACTUALLY work on all OSs? Specifically we use the following: Windows XP, 7, Vista, Mac OS X (Snow), Ubuntu 9.10 AND CentOS 5
Should work. Need Java RE on Linux machines.
I did get it running on different linuxes, need to configure firefox to find java path. Works with suse, redhat, debian, ubuntu, but depends on versions of webbrowser and java, mostly no problem for linux experts.

Quote
2. Can we route ALL traffic through the network connect? We want it to be the gateway for our remote users so all their traffic appears on our IP subnets (essentially acting as a proxy)

You can configure anything you can imagine with split tunneling options.
Very flexible and easy to handle.

Quote
3. Does anybody have thoughts on lower cost alternatives to RSA for two factor support?
yes. watch this ..  https://login.bilfinger.net
You can use PIN authentication with "mouse clicks" as rudimentary "keyloggerprotection" if that is enough for your security.
Alternative (or additionally.. you can use clientcertificates.
RSA SecurID Implementation is anyway very easy and stable with IVE.
It supports ACE native protocol.

Quote
4. Remote Desktops / Terminal Services - can we set this up without using RADIUS? Basically we give RDP access to all of our remote techs; however, we don't need to give them individual user/passes, we want to hard code one user/pass login for them.

You can use local useraccounts on IVE local database and hardcode username/password on admin config very easily.
But i love radius.. When you plan authentication via active directory, trust me - radius is easy, stable and fast. IAS Radius is installed and configured on DC in 20 Minutes!

Quote
5. Are there RDP clients built in for Linux and Mac? i.e. Microsoft has a client for mac which the Barracuda uses, and then the Linux uses use Rdesktop.

Dont think so. But you can use free linux rdp clients and let them connect via network connect vpn tunnel or jsam maybe.

Quote
6. Are there options to use the VPN on a iPhone? Or would we need to setup a separate PPTP/LT2P server for this?

Depends on your requirements. If iPhone does run JAVA it "could" work, never tried out. If users only need clientless access via webbrowser on intranet webpages or fileshares, you can do this with any browser and enddevice.

Quote
7. For those users who use network connect, is it possible to setup the web interface to just add "bookmarks" - i.e. there are some fairly complex internal applications which haven't worked properly through other SSL VPNs via web forwards, but we have a TON of internal apps, so some users will use network connect to gain local access to the network, but we want the interface to give them essentially direct bookmarks so they don't need to have an updated bookmark list on their laptop.

Clientless webaccess via rewrite engine, and accessing internal ressources via local client webbrowser and network connect are two separated methods. The webbookmarks on IVE webportal dont have anything to do with network connect. IVE also supports "passthrough proxy" for websites which cannot be rewritten, helps sometimes.

Quote
8. Can we set it to allow the use of a public IP range rather than an internal range?
You can use any range you can imagine, just routing has to be fine.


I am not a Juniper man - but i really love this IVE system.
You cant go wrong with it - very flexible, stable.
Dream Mashine. I tried it all out - Citrix AG, Cisco ASA, Avantail - but once you go Juniper Secure Access you ll never go back.

Logged
Pages: [1]
  Print  
 
Jump to:  

Navigation

Donate

Please consider donating if we've saved you time or money. It helps pay for the bandwidth, equipment, and hosting charges to keep this site running

Tools

Submit Article/KB - Do not submit questions here.

Recent

Stats

Members
Stats
  • Total Posts: 39593
  • Total Topics: 10459
  • Online Today: 72
  • Online Ever: 393
  • (August 06, 2008, 07:40:57 AM)
Users Online
Users: 2
Guests: 31
Total: 33
TinyPortal v1.0 beta 4 © Bloc
Powered by MySQL Powered by PHP Powered by SMF 1.1.11 | SMF © 2006-2009, Simple Machines LLC Valid XHTML 1.0! Valid CSS!

Sponsored in part by CollarWise

Page created in 0.222 seconds with 39 queries.