tgreene
Executive Editor

Aventail updates SSL VPN appliances to support digital certificates

Opinion
Jul 13, 20062 mins

* Aventail releases Aventail ST2

Aventail is upgrading the software that runs on its SSL VPN appliances to include support for certificates that identify remote machines when they try to connect to the VPN and can allow or restrict access based on the status of the certificate.

Called Aventail ST2, the software looks for a digital certificate on devices as they log in and checks them against the certificate store to see if they are valid. Depending on the presence and validity of the certificates, policies can grant more or less privileges on the VPN, including blocking entry.

The certificates can be used as a means to shore up network security when mobile devices are lost or stolen. When a laptop or PDA goes missing, administrators can revoke its certificate, making it impossible for, say, a thief to gain access with it. Meanwhile, the access rights of the person whose laptop was involved remain intact so they can continue to reach the VPN via other machines.

Aventail is also adding endpoint checking for mobile Windows devices to check for certain applications, file and directory names, certificates and other criteria. Before, Aventail ST could only check whether a device was mobile, but not gather further information about mobile devices.

The new software version adds a quarantine zone where machines that fall short of configuration policies can be sent custom text directing users to URLs where they can seek remediation for the device’s shortcomings.

ST2 can automatically link applications to servers automatically. Users can script Aventail agents to establish SSL tunnels on schedule, for example, then launch a local application client that connects to its server via the VPN. So, for instance, an inventory application could be launched nightly to upload each day’s sales data after hours when no staff is around.