* New feature in iPass intends to keep infected machines off of the VPN
IPass is adding a new security feature to its remote access VPN services with the intention of making sure the devices that are logging in are secure.
The new feature is called Device Lockdown, and its job is to keep possibly infected machines off of the VPN where they could spread malware.
Device Lockdown is an endpoint-checking tool that compares a machine’s configuration with what it ought to be to meet corporate security policies. Before it does this “pat-down” of the computer, the device that is trying to log in is quarantined on a virtual LAN where it cannot reach any corporate resources.
The iPass policy server compares the configuration of the device with the standard set by the business. If the scan finds that the device comes up short of the standard, Device Lockdown will update the machine to remedy the shortcomings.
All this is done as part of the service that is based in iPass’s network, not the customer’s network. The initial connection is made between the end device and an iPass point of presence. This architecture eliminates the need for gear at customer sites, but also insulates the customer network entirely from whatever infections remote machines might carry. They are cleaned up before they gain corporate access.
Customers get a Web management portal where they can set policies and pull down detailed reports on compliance of endpoints.
This type of checking has been a standard part of VPN gear for awhile now. It’s an asset to a managed remote access VPN service that customers should consider buying if they decide on iPass.




