Juniper this week is announcing technology that promises to give businesses more ways to guarantee computers making remote links to corporate networks have appropriate security software in place.
Juniper this week is announcing technology that promises to give businesses more ways to guarantee computers making remote links to corporate networks have appropriate security software in place.
Juniper is offering programming hooks into its software that other vendors can use to integrate their products – such as firewalls and anti-virus products – with Juniper’s endpoint-protection software.
Juniper Endpoint Defensive Initiative (JEDI) will make it possible to more thoroughly inspect the defenses on remote-access computers to make sure their operating systems are patched and other security software is updated and configured to meet corporate policies.
JEDI is similar to Microsoft’s network access protection (NAP) program, which will open up APIs on Windows XP to other vendors. These APIs support XP’s monitoring whether the other vendors’ software is turned on, current or properly configured. New features of Windows 2003 Server then would determine if the machine meets security policies and either allow access, deny it or redirect to a quarantine network where the computer can get the updates it needs. NAP is due out next year.
Juniper is different in that JEDI will push required software to the remote machine. For example, if a company policy called for remote computers to have Whole Security’s Confidence Online malware scanner before being given access, Juniper’s Host Checking Agent could look for it. If it’s not there, the gateway can push a lightweight version to the computer.
These lightweight software versions that Juniper partners are developing generally will be ActiveX controls that terminate when the Secure Sockets Layer sessions terminate, Juniper says. The push mechanism also could be used to distribute, permanent client software, the company says.
Six vendors are cooperating to better integrate their gear via the Juniper gateway API: InfoExpress (personal firewall, policy compliance check); Microsoft (personal firewall); McAfee (anti-virus); Sygate (personal firewall, virtual desktop, malware scanning); Trend Micro (anti-virus); and WholeSecurity (malware scanner).
In the case of Microsoft, Juniper wrote its software to comply with Microsoft’s Internet Connection Firewall, the firewall added to XP.
Juniper acknowledges the overlap with Microsoft NAP, but says JEDI is shipping now while NAP ships next year. After NAP ships, Juniper gateways will support NAP and could act as enforcement points for policies that a NAP server checks.
JEDI features are part of a software upgrade that comes standard with Juniper NetScreen Secure Access Gateways.




