Home > Security Tips > Security Buyer's Guide > SSL VPN: AEP SureWare A-Gate AG-600
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

SECURITY BUYER'S GUIDE

SSL VPN: AEP SureWare A-Gate AG-600


George Wrenn, CISSP
08.23.2005
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


AEP SureWare A-Gate AG-600
AEP Systems
Price: $8,995/400 users

AEP Systems SureWare A-Gate AG-600 provides SSL VPN remote access for connecting external users to internal systems.

The appliance provides clientless access to HTTP and Windows Terminal Server apps and full access to client-server apps from Windows XP/2000 clients. It has four Ethernet interfaces, features high availability and session-level failover and handles 400 simultaneous connections. Enterprises will appreciate its capacity to cluster up to 16 boxes for supporting thousands of users.

AEP packs strong security in the AG-600, which runs a hardened version of Linux. Booting the box over a serial connection initially blocks access to system resources. You'll need to set a password and options for Web-based administration, remote root logins to the network, SSH, syslog and SNMP to unlock configuration. This is a radical departure from security hardware that, once connected, and without so much as a password, allows anyone to configure network and device settings.

We launched a browser, authenticated and proceeded to solve the obfuscated text riddle, or 'completely automated public Turing test to tell computers and humans apart' (CAPTCHA) utility. CAPTCHA is an image with slightly skewed characters and numbers, designed for enhancing authentication and preventing automated attacks. You decipher and type a displayed code and enter a user name and password.

Configuration is a comprehensive process using GUI setup tabs, although the interface conspicuously lacks a help menu. We methodically assigned IP addresses to Ethernet interfaces and configured the LAN/WAN interfaces, DNS server, incoming access to port 443 (SSL) and external gateway to route traffic to the Internet.

Setting up digital certificates for authenticating users is a breeze. Clicking on the site security tab allows you to create a certificate signing request (CSR). We pasted our CSR into a VeriSign form to access a trial certificate, and, with our new SSL-site identity, we configured the remote access policy. AG-600 supports two Windows authentication options: LDAP for AD domains, and the Windows Server Message Block file sharing protocol (SMB) for old-school domain services. A-Gate also integrates with Sun LDAP and Novell NDS servers. Its RADIUS support hooks into other authentication methods, including CASQUE, Crypt-Card and SecurID. Our configuration using the internal database and Windows SMB domain authentication worked flawlessly.

AG-600 provides two modes of VPN access: A-Gate Anywhere can proxy application traffic via a Java applet, for instance, to Windows Terminal Services; the A-Gate Central is a thin-client SSL VPN that enables access to TCP/UDP applications. Users launch the client by clicking the link on the user A-Gate portal page, which is customizable to reflect user's branding. Establishing WAN access to these services was an easy configuration of A-Gate's host MYSQL database, server names and IP addresses. But, adding the Anywhere Web servers to the remote access configuration, and again in the portal page, was bothersome; an automated mechanism would be easier.

Policy configuration was a challenge. While we easily defined a HTTP global access policy for authenticated users, the GUI made it tough to configure more granular access control rules. It's confusing to decipher how menu branches relate to others in the tree. A more intuitive grid or matrix for defining devices, URL strings as services and authorized users/groups would be simpler.

While AG-600's granular policy and portal elements could use some tweaking, this hardcore appliance provides enviable security defaults and convenient access to sensitive applications.

About the author
George Wrenn, CISSP (gwrenn@infosecuritymag.com), is a technical editor for Information Security and a security director at a financial services firm. He's also a fellow at the Massachusetts Institute of Technology.

This review orginally appeared in Information Security magazine.

Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




BROWSE BY TAG
Security Buyer's Guide,   Secure VPN Setup and Configuration,   Enterprise Network Security,   SSL and TLS VPN Security,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Security Buyer's Guide
Keystroke dynamics makes BioPassword Internet Edition a viable authentication option
Access security with KoolSpan's SecurEdge
NetChk Protect 5.5
Biometrics: Best practices, future trends
2006 Products of the Year: Emerging Technologies
Secure Sphere 2.0
Scan & Deliver: SLAs force service providers and outsources to hit the mark ... or hit the road
Secure remote access: SSH Tectia Manager
Spycatcher Enterprise 3.2
Configuresoft's Enterprise Configuration Manager v4.7

SSL and TLS VPN Security
Expert calls SSL protocol vulnerability a non issue
How SSL-encrypted Web connections are intercepted
Best Remote Access Products
How to set up a split-tunnel VPN in Windows Vista
Securing the intranet with remote access VPN security
A short enterprise VPN deployment guide
Creating an SSL connection between servers
Can S/MIME, XML and IPsec operate in one protocol layer?
Can secure USB devices prevent man-in-the middle attacks
How to secure SSL following new man-in-the-middle SSL attacks

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
Secure Shell  (SearchSecurity.com)
Secure Sockets Layer  (SearchSecurity.com)
server accelerator card  (SearchSecurity.com)
SSL VPN  (SearchSecurity.com)
Transport Layer Security  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts