tgreene
Executive Editor

Caymas appliances restrict access

News
Oct 11, 20043 mins

Caymas Systems is introducing appliances that secure network traffic by drawing on existing network infrastructure to enforce restrictions of access to network servers by users on LANs or users connecting via WAN links.

The three devices – called Caymas 220, 318 and 525 – enforce a variety of access policies as well as logging and auditing who accesses what resources. These features can be used to meet security mandates of federal agencies such as the Securities and Exchange Commission as well as federal privacy laws such as the Health Insurance Portability and Accountability Act.

The appliances can be used to support secure remote access, extranets with customers and business partners and access to resources from within corporate networks.

Intuitive Surgical of Sunnyvale, Calif., installed a Caymas appliance to replace a Citrix server and Secure Computing authentication software running in a secure network segment behind the company firewall, says Don Chamberlain, manager of business applications for Intuitive. “It was always a bit of an administrative headache to figure out which was causing the problem when something went wrong,” says Chamberlain.

He says the company resolved that problem because the Caymas gear performs both functions, allowing Intuitive to get rid of two servers and lightening administrative load.

The boxes sit in line with network traffic to control access to resources, offering more granular controls than a network-layer IPSec VPN, but less expensive than full-blown identity management platforms such as those made by Netegrity and Oblix, the company says. The Caymas devices might sit behind a corporate firewall to restrict remote access or in front of a data center to control access to applications.

The equipment identifies users, authorizes resources they can access and determines whether they are behaving as allowed. Access requests can be checked against external authentication platforms such as RADIUS servers, Active Directory or proprietary databases. The devices can also scan for malicious code signatures and check whether data being tapped is authorized.

In addition to checking whether the remote user is authorized to access resources, the Caymas gear can check whether the machine being used meets security policies by verifying eight attributes such as its MAC address, IP address, what certificates it possesses, whether it has updated anti-virus software, and the patch level for the operating system. Similarly, it can identify resources on an application-by-application basis.

The devices can opt to allow access, deny it, restrict it or blacklist the user. The policy rules can be very specific, such as allowing a user to access to a purchasing application but restricting purchases to $10,000 or less.

By monitoring traffic flows from users to servers the devices can identify and block malformed packets, and restrict access if users display behavior beyond the norm for their authorized groups. For example, accessing the same application more than a certain number of times over a weekend could be deemed unusual and be blocked. Logs of access activity can be sorted via five categories of reports supported by Caymas software.

Remote computers can connect securely via the Caymas box with IPSec using a SafeNet IPSec client or via SSL using a browser or via Java or Active X agents. 

The devices are available in North America. 

Caymas 220 for up to 100 users costs $10,000; Caymas 318 for up to 500 users costs $25,000; and Caymas 525 for up to 2,500 users costs $45,000. The 318 and 525 can be paired for high availability so if one fails the other takes over.