tgreene
Executive Editor

VPN Consortium testing if SSL VPN gateways support JavaScript

Opinion
May 9, 20062 mins

* VPN Consortium issues new certification for SSL VPN gateways

The VPN Consortium has issued a new certification for SSL VPN gateways that tests whether the gear supports JavaScript, a key element of many corporate Web portals.

The purpose of the certification is to put the equipment through a series of tests that determine whether it can figure out a URL when it is written in JavaScript code. The VPNC says this is important because many corporate portals are commonly accessed via SSL VPNs, and many of those same portals are written in JavaScript. If the VPN gateways can’t properly interpret the URLs, they can’t deliver the portals.

As the VPNC puts it, “Many corporate Web sites make extensive use of JavaScript, and rewriting URLs in JavaScript is more difficult than rewriting URLs in HTML.”

Passing the test means the gateway tested is compatible with both Internet Explorer and Firefox Web browsers. The VPNC description of the test is this: “The test URL points to a page on a Web server on the protected network, and is made up of the concatenation of two variables, such as ‘http://www.example.com/’ and ‘somepage.html’.”

So far, the VPNC has granted SSL JavaScript certification to equipment from eight vendors:

* AEP Networks Netilla Security Platform.

* Caymas Networks Caymas gear.

* Check Point Connectra.

* Cisco ASA Servers and VPN 3000 Concentrators.

* F5 FirePass Controller.

* Juniper NetScreen Instant Virtual Extranet.

* Nokia SSL VPN gear.

* Nortel VPN Gateway Portfolio.

VPNC has devised a number of other tests for IPSec and SSL VPN equipment and issues certification for those tests as well. A list of the tests and what equipment has passed them can be found here.