Skip Links

Network World

  • Social Web 
  • Email 
  • Close

Juniper adds IPSec to its SSL platform

By Tim Greene , Network World , 06/06/2005
  • Share/Email
  • Comment
  • Print

Juniper is upgrading its remote access platform to support IPSec or SSL sessions, deciding on the fly which technology is better suited for the current connection.

This is the first time a remote access vendor has incorporated both IPSec and SSL transport in an agent that is downloaded to a remote machine at the time of connection. The agent overcomes the objection that IPSec requires a separately installed client on remote machines. Juniper says it first tries IPSec because that technology has less inherent delay than SSL and so provides better performance.

As remote users try to connect over the Internet to a Juniper SSL VPN box at the edge of a business network, the device sends down a dual agent. If the IPSec connection is blocked, as can occur across network devices that swap private IP addresses for public ones, the software will fall back to an SSL connection, which can generally get through these network address translation devices.

"This way you can have your choice of the better one to use, but the end user doesn't have to figure out which connection to make," says Zeus Kerravala, an analyst with The Yankee Group.

Nortel and other vendors have gateways that support SSL and IPSec but require a pre-installed client on remote machines for IPSec connections.

In addition, Juniper is adding XML rewrite capabilities to the platform to make it possible to reach applications with XML-based content.

The company is upgrading its host-checker software that scans remote computers before allowing them to connect to a VPN to make sure they meet security policies. If an end-user machine fails a policy, the software can specify to the user why the machine failed and redirect it to a site where the problem can be fixed. The host checker then re-evaluates the machine. Before, the software just told the end user where to go to download fixes.

  • Share/Email
  • Comment
  • Print
Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.

Download the white paper.

Applications: taking back control

Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.

Learn more today.

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed