* Not all scanners are created equal
Software that supports the scanning of computers trying to join VPNs has become a standard part of VPN vendors’ offerings.
Such software is more than just a handy tool; it is a necessity for making sure the remote machines don’t gain VPN access if they don’t comply with corporate security policy. No operating system patches, personal firewall, updated anti-virus software? No access.
Many vendors develop their own versions of this endpoint-checking tool by making alliances with a limited number of security vendors. These arrangements enable the VPN vendors to tap, for example, another vendor’s anti-virus software running on a remote machine to make sure its virus signature files are up to date. Vendor by vendor they build up the ability to scan for a wide range of security applications.
Some other vendors enlist the help of a company called OPSWAT. You can click here to read about the painstaking work the company does to come up with scans for products that OPSWAT has no development agreements with.
While such software was eagerly adopted by SSL VPN vendors that were touting that any browser-enabled computer could access an SSL VPN, they had to come up with a way to make sure these computers were also safe to tie in to the VPN.
Now the endpoint-scanning technology is the cornerstone of network access control schemes designed to make sure that any device accessing a network – not just remote machines accessing via VPN – comply with configuration standards. Vendors are working hard to make their schemes as all-inclusive as possible.
The point here for potential VPN customers is that these scanners are not created equal and it is a good idea to delve into them in some detail to make sure the one you buy fits your needs.




