Home > Security Tips > Network Security Tactics > How Juniper and F5 SSL VPNs can handle endpoint security
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

NETWORK SECURITY TACTICS

How Juniper and F5 SSL VPNs can handle endpoint security


David Strom
01.09.2007
Rating: -4.33- (out of 5)


Network Security Tactics
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


Setting up endpoint security on an existing SSL VPN architecture is somewhat complex. We'll show you how it is done on two of the leading products: F5 Networks Inc.'s Firepass and Juniper Networks Inc.'s SA-6000 SP. Both use Web-based administrative consoles, and there are various places to configure the endpoint routines within these consoles.

On the Firepass, first we will demonstrate how to set up the various endpoint security policies, and then we will implement them for particular groups of users. On the administrative console, upon going into the Users section, you'll see that Endpoint Security is the third category of menus on the upper left-hand menu bar.

[IMAGE]

Here you'll see a screen that lists all the various endpoint inspection routines that are available, such as checking for an installed firewall or particular antivirus signature. Moving down the left-hand navigation bar menu options, you see pre-login sequence and post-login actions as your next series of choices, and these control what is done at these times.

If you click on pre-login sequence, you will see a screen listing the particular sequences that you have already specified.

[IMAGE]

If you click on one of these sequences, you will be brought to F5's visual policy editor, a Visio-like flowcharting program with which you can drag and drop actions and choices for the software to perform.

[IMAGE]

The last couple of choices on the left-hand nav bar are protected configurations and protected resources. The former will bring up a screen similar to the one below, showing the security policies that have been implemented before a user can access particular resources.

[IMAGE]

Once these policies are created, click on the bottom of the left-hand navigation bar into the Network Access section, and then choose the Policy Checker menu tab on the top.

[IMAGE]

At the bottom of



this screen is a bar that reads, "Endpoint Protection Required for this Resource Group." There is a pull-down box of various choices, such as restricted login or time-dependent login. This is where you specify overall policies for particular users or groups; when you do, you will see a screen similar to the one below.

[IMAGE]

Juniper's endpoint routines are slightly different. On its management interface, there is a separate endpoint security section as with Firepass, and there are two basic configuration sequences for host checking and for its cache cleaner.

[IMAGE]

You can perform the checks on each endpoint every 10 minutes by default, or change this value as you wish. Creating a new host checking policy will bring you to a screen where you can add particular rules.

[IMAGE]

Rules must be specified for Windows, Macintosh and Linux endpoints separately. You'll see a drop-down box on this screen to set up the individual rules, such as checking for personal firewalls installed on each device, where you'll come to a screen such as the one shown below.

[IMAGE]

About the author:
David Strom is one of the leading experts on network and Internet technologies and has written extensively on the topic for nearly 20 years. He has held several editorial management positions for both print and online properties, most recently as Editor-in-Chief for Tom's Hardware. In 1990, Strom created Network Computing magazine and was the first Editor-in-Chief establishing the magazine's networked laboratories. He is the author of two books: Internet Messaging (Prentice Hall 1998) which he co-authored with Marshall T. Rose and Home Networking Survival Guide (McGrawHill/Osbourne; 2001). Strom is a frequent speaker, panel moderator and instructor and has appeared on Fox TV News Network, NPR's Science Friday radio program, ABC TV's World News Tonight and CBS-TV's Up to the Minute.

Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




BROWSE BY TAG
Network Security Tactics,   SSL and TLS VPN Security,   Secure VPN Setup and Configuration,   Enterprise Network Security,   NAC and Endpoint Security Management,   Client security,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Network Security Tactics
Screencast: Samurai offers pen-testing nirvana
Firewall rule management best practices
Chained Exploits: How to prevent phishing attacks from corporate spies
Rootkit Hunter demo: Detect and remove Linux rootkits
Enterprise UTM security: The best threat management solution?
Making the case for network security configuration management
An inside look at security log management forensics investigations
How to find sensitive information on the endpoint
How to perform Microsoft Baseline Security Analyzer (MBSA) scans
How to spot attacks through Apache Web server log analysis

SSL and TLS VPN Security
Creating an SSL connection between servers
Can S/MIME, XML and IPsec operate in one protocol layer?
Can secure USB devices prevent man-in-the middle attacks
How to secure SSL following new man-in-the-middle SSL attacks
SSLstrip hacking tool bypasses SSL to trick users, steal passwords
What firewall controls should be placed on the VPN?
What firewall features will best protect a LAN from Internet hack attacks and malware?
IBM USB banking device stops keyloggers, malware
Debian: A niche OS with a not-so-niche security flaw
Google Chrome unlikely to attract security-minded users

Client security
How to defend against rogue DHCP server malware
Symantec offers endpoint protection management, monitoring services
Sophos integrates encryption into endpoint security
Quiz: Endpoint security on a budget
How to find sensitive information on the endpoint
Trend Micro gets more competitive with BigFix deal
CA steers DLP towards access, identity management
CA to acquire Orchestria for DLP
Microsoft to embed data classification, strengthen ties with DLP
Diverse mobile devices changing security paradigm

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
Secure Shell  (SearchSecurity.com)
Secure Sockets Layer  (SearchSecurity.com)
server accelerator card  (SearchSecurity.com)
SSL VPN  (SearchSecurity.com)
Transport Layer Security  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
More Security Resources for Resellers, VARs and OEMs
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts