10
Overview: Juniper SSL VPN Strategy, Architecture and Introduction

ssl vpn presentation 2

Embed Size (px)

Citation preview

Page 1: ssl vpn presentation 2

Overview: Juniper SSL VPN

Strategy, Architecture and Introduction

Page 2: ssl vpn presentation 2

Technical Overview

Features– Extranet style web interface access to resources– Full/split tunnel capabilities with Network Connect– Mobile ready with Junos Pulse– No client installation required– Granular Authentication, Authorization and Auditing

capabilities– Secure Meeting Space

Page 3: ssl vpn presentation 2

Basic Concepts

• Juniper model for secure remote access is granular allowing each component to be administered en masse or individually– Realms -> Users -> Roles -> Resources– Realms: Groupings of authentication resources (RADIUS, AD, LDAP,

Local, etc)– Users: User objects (individuals who will be granted access)– Roles: Ad-hoc groups of users that can contain one or more security

groups– Resources: Specific network resources that roles are enabled to access

• RDP connections to servers• Web pages• Network CIDR blocks (ie, 165.124.188.0/26)• File Shares

Page 4: ssl vpn presentation 2

Basic Concepts, Cont’d

Page 5: ssl vpn presentation 2

IPsec VPN v. SSL VPN: What’s the difference?IPsec • Designed for site-to-site encryption over insecure networks• Encapsulates packets at the network layer• Operates in two modes– Transport Mode: Packets payload is encrypted at sender

and decrypted at receiver– Tunnel Mode: Sessions are built and torn down between

endpoints (sites and user)

=

Page 6: ssl vpn presentation 2

IPsec Modes

Page 7: ssl vpn presentation 2

IPsec continued

Page 8: ssl vpn presentation 2

SSL VPN

• Designed specifically for individual remote access to resources

• Allows for granular access to resources• Requires no software installation or

configuration• Allows for users to have a seamless

experience- no more connections and disconnections

Page 9: ssl vpn presentation 2

SSL Crypto Negotiation

Page 10: ssl vpn presentation 2

SSL VPN Cont’d