Remote access is a necessity for today's businesses, whether it's for getting at data and apps from a remote office or from the living room sofa after hours. SSL VPNs help provide that access securely and easily through the ubiquitous Web browser without requiring a "fat" software client on the remote PC. And now SSL VPN vendors are finally bringing feature-rich clientless remote-access solutions to the little folks, small and midsize companies, at a price low enough for everyone to afford.
Among these solutions aimed at SMBs is the ZyXel ZyWall SSL 10 VPN appliance. The box delivers access to a variety of applications, plus it can connect to various authentication schemes. Moreover, it can check end points for compliance before allowing clients network access. The product sports a Java-based client engine, thus leveraging Java's wide availability on all platforms – but not without the language's notorious performance penalty.
| Click for larger view. |
Notably, admins can allow secure entry to Microsoft's Outlook Web Access through ZyWall using the predefined OWA application type. This is important because OWA does strange things to the rendered page, and not all SSL VPN appliances – big or small – handle it correctly.
Like the big guys, ZyWall allows remote access to non-Web applications, a feature I really appreciate. Upon successful login to the appliance, a Java applet is pushed down to the client. This client redirects connections to the local loopback addresses (such as 127.0.0.3), sending them to the appliance and on to the application.
For example, I created policies that let me access Microsoft Terminal Services using Remote Desktop Connection from my Windows XP Pro client. I then connected to the loopback address specified by the Java client and was able to link up to the service. Higher-end SSL appliances, such as offerings from Aventail and F5, are more transparent to the end-user – they don't have to connect to the loopback address – but they're much more expensive.
Another nice feature: ZyWall can access file shares on both Windows and Linux servers from within a Web browser. I was able to create multiple links in the appliance's portal page to various shares on both platforms without too much trouble. I did, however, find that connecting to shares on a Windows Server 2003 domain controller brought up some problems. I was not able to authenticate to my server unless I disabled Server Message Block signing in the server's domain controller security policy. Not a problem on small networks, but it requires a little policy fiddling to make it work. I had no issues with shares on Windows XP or Windows 2000 Server.
| Test Center Scorecard | ||||||
|---|---|---|---|---|---|---|
| 25% | 25% | 20% | 20% | 10% | ||
| ZyXel ZyWall SSL 10 VPN | 9 | 8 | 7 | 8 | 9 |
8.2
Very Good
|
This whitepaper explains the terminology and concepts behind Data Replication technologies and establishes some sizing rules through worked examples. Learn the new paradigm in disaster tolerance—protect data anywhere.
Download now »Server virtualization is a popular option for dealing with mounting datacenter costs. Another equally promising approach is the use of an Application Delivery Controller. Citrix NetScaler provides a low-cost way for organizations to reduce their server count and accrue cost savings from a reduction in space, cooling, power and personnel.
Download now »
The emergence of WLANs has created a new breed of security threats to enterprise networks.
Included in HP ProCurve WLAN solutions is security technology that alleviates threats from WLANs through:
* Monitoring wireless activity inside and out of the enterprise
* Classifying WLAN transmissions into harmful and harmless
* Preventing transmissions that pose a security threat to the enterprise network
* Locating participating devices for physical remediation
Effectively address data protection challenges, implementing solutions that help store and protect businesscritical data while cutting costs and improving efficiency and reliability.
Download now »
Sign up to receive Security Resource Alerts
This white paper provides guidance on how to develop a strategic approach to managing and monitoring logs, a key function required for compliance with many regulatory mandates and a critical defense against security threats.
Download now! »Learn about the processes and technologies that support security information management (SIM) operations, as well as the business case for SIM. The series examines different options for implementing SIM and gives you evaluation criteria for selecting the best option for your organization.
Download now! »Learn the strategies, actions, and capabilities that Best-in-Class organizations employ and technologies they choose to obtain superior performance against various security performance metrics. This report provides guidelines for identifying which security solutions to consume as a MSS and defines best practices for choosing and managing MSSPs.
Download now! »