extending isa/iag beyond the limit. agat security suite - introduction agat security suite is a set...

28
Extending ISA/IAG beyond the limit

Upload: magdalen-malone

Post on 05-Jan-2016

241 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Extending ISA/IAG beyond the limit. AGAT Security suite - introduction AGAT Security suite is a set of unique components that allow extending ISA / IAG

Extending ISA/IAG beyond the limit

Page 2: Extending ISA/IAG beyond the limit. AGAT Security suite - introduction AGAT Security suite is a set of unique components that allow extending ISA / IAG

AGAT Security suite - introductionAGAT Security suite is a set of unique

components that allow extending ISA / IAG functionality to solve complex architectures and requirements, typically implemented in large, complex and well secured networks.

To learn more about our solutions please visit our website at http://www.agat.co.il or contact [email protected]

Page 3: Extending ISA/IAG beyond the limit. AGAT Security suite - introduction AGAT Security suite is a set of unique components that allow extending ISA / IAG

Main Filter listAG Authentication RelayActiveSyncAG Remote Cert AuthAG SSOAG MultiplexerAG Secured File Upload

Page 4: Extending ISA/IAG beyond the limit. AGAT Security suite - introduction AGAT Security suite is a set of unique components that allow extending ISA / IAG

AG Authentication Relay

Page 5: Extending ISA/IAG beyond the limit. AGAT Security suite - introduction AGAT Security suite is a set of unique components that allow extending ISA / IAG

AG Authentication RelayGeneral description

The Authentication Relay filter allows users to authenticate using a digital certificate when the application is protected by more than one ISA server in a cross domain architecture.

.

Page 6: Extending ISA/IAG beyond the limit. AGAT Security suite - introduction AGAT Security suite is a set of unique components that allow extending ISA / IAG

AG Authentication Relay (cont)

The solution is based on two web filters: In the front ISA the Relay filter signs the user’s

name (after being authenticated by ISA) and time stamp and submits the signed data in the request header.

In the back ISA the Consumer filter verifies that the message was received from the front ISA and then performs the authentication to the required application..

The solution does not require any domain trust relationship between the front and back domains.

Page 7: Extending ISA/IAG beyond the limit. AGAT Security suite - introduction AGAT Security suite is a set of unique components that allow extending ISA / IAG

AG Authentication Relay (cont)

ArchitectureOption A- Basic Authentication Relay

Page 8: Extending ISA/IAG beyond the limit. AGAT Security suite - introduction AGAT Security suite is a set of unique components that allow extending ISA / IAG

AG Authentication Relay (cont)

ArchitectureOption B- Strong Authentication Relay

Page 9: Extending ISA/IAG beyond the limit. AGAT Security suite - introduction AGAT Security suite is a set of unique components that allow extending ISA / IAG

AG Authentication Relay – Use casesWhen more than one ISA is protecting the application and smart card authentication is needed.When there is a single front end ISA in the external domain protecting several sub-networks that are using ISA.Typically when using IAG as a gateway and several ISA servers are protecting the internal domains.When you need the client’s certificate at the back end of multiple ISA architecture.

Page 10: Extending ISA/IAG beyond the limit. AGAT Security suite - introduction AGAT Security suite is a set of unique components that allow extending ISA / IAG

AG Active Sync Filter

Page 11: Extending ISA/IAG beyond the limit. AGAT Security suite - introduction AGAT Security suite is a set of unique components that allow extending ISA / IAG

AG ActiveSync - intro & requirementActiveSync is a data protocol used to

synchronize end user devices with Exchange server.

Typically the exchange server is published using IAG/ISA.

 Organizations need to control the content

published to the client (ie iPhone, windows mobile) to ensure that the content published is compatible with the device security level requirements.

Page 12: Extending ISA/IAG beyond the limit. AGAT Security suite - introduction AGAT Security suite is a set of unique components that allow extending ISA / IAG

AG ActiveSync filter solutionThe ActiveSync filter allows configuring

publishing rules according to device type and Exchange objects (mail, events, tasks and contacts).

In addition, the filter can block publishing of attachments and can perform content filtering.

Page 13: Extending ISA/IAG beyond the limit. AGAT Security suite - introduction AGAT Security suite is a set of unique components that allow extending ISA / IAG

AG ActiveSync filter featuresFilter rule configuration by device type (iPhone,

windows mobile etc)Allowing or blocking Sync of the following objects:

mail messages, contacts, tasks and calendar events.Allowing or blocking Sync of attachments in mails

messages or eventsFiltering by words in content of mail and calendar

events.Allowing meeting requests to be published even

when mail is blocked.Support ActiveSync 4.5

Page 14: Extending ISA/IAG beyond the limit. AGAT Security suite - introduction AGAT Security suite is a set of unique components that allow extending ISA / IAG

AG Remote Cert Auth

Page 15: Extending ISA/IAG beyond the limit. AGAT Security suite - introduction AGAT Security suite is a set of unique components that allow extending ISA / IAG

AG Remote Cert Auth- DescriptionEnable to perform certificate authentication

using an LDAP that is not in the same domain as the ISA server.

Page 16: Extending ISA/IAG beyond the limit. AGAT Security suite - introduction AGAT Security suite is a set of unique components that allow extending ISA / IAG

AG Remote Cert Auth -Use casesWhen users are using smart cards to login

and the LDAP is in a different domain than the ISA.

Typically when organization is securing theLDAP / Active directory in a separate domain then the ISA

Page 17: Extending ISA/IAG beyond the limit. AGAT Security suite - introduction AGAT Security suite is a set of unique components that allow extending ISA / IAG

AG SSO

Page 18: Extending ISA/IAG beyond the limit. AGAT Security suite - introduction AGAT Security suite is a set of unique components that allow extending ISA / IAG

AG SSO - DescriptionAdd user certificate and LDAP properties to

header request for application authentication.

Page 19: Extending ISA/IAG beyond the limit. AGAT Security suite - introduction AGAT Security suite is a set of unique components that allow extending ISA / IAG

AG SSO - Use casesWhen your web application is not

configured to use Windows authentication and user identity is needed.

Properties from LDAP are needed for the application.

When you need to pass the client certificate to your internal IIS.

Page 20: Extending ISA/IAG beyond the limit. AGAT Security suite - introduction AGAT Security suite is a set of unique components that allow extending ISA / IAG

AG Multiplexer

Page 21: Extending ISA/IAG beyond the limit. AGAT Security suite - introduction AGAT Security suite is a set of unique components that allow extending ISA / IAG

AG Multiplexer - DescriptionEnable transmitting the user's request

via a single point of access to several internal destinations according to user organization unit or group

Automatically generate a menu page listing all accessible URLs.

Page 22: Extending ISA/IAG beyond the limit. AGAT Security suite - introduction AGAT Security suite is a set of unique components that allow extending ISA / IAG

AG Multiplexer – Use casesWhen you need to provide a single point of

access to all users to browse to different web applications.

When routing users is needed according to the location in the Organization Unit (OU) or Group.

Typically when the network is divided into several subnets/domains managed separately.

Avoid publishing many internal sites.

Page 23: Extending ISA/IAG beyond the limit. AGAT Security suite - introduction AGAT Security suite is a set of unique components that allow extending ISA / IAG

AG Access Controller

Page 24: Extending ISA/IAG beyond the limit. AGAT Security suite - introduction AGAT Security suite is a set of unique components that allow extending ISA / IAG

AG Access Controller- DescriptionThe filter extends the ISA web publishing

rule system with additional criteria.Supports configuring the web publishing

rules based on user OU or Group.Enables working with an LDAP server that is

not in the same domain as the ISA/IAG.

Page 25: Extending ISA/IAG beyond the limit. AGAT Security suite - introduction AGAT Security suite is a set of unique components that allow extending ISA / IAG

AG Access Controller - SSL VPN Allows filtering users that use SSL VPN.Enables identifying the user in SSL VPN in

order to prevent anonymous requests entering the firewall

Page 26: Extending ISA/IAG beyond the limit. AGAT Security suite - introduction AGAT Security suite is a set of unique components that allow extending ISA / IAG

AG Secured File Upload

Page 27: Extending ISA/IAG beyond the limit. AGAT Security suite - introduction AGAT Security suite is a set of unique components that allow extending ISA / IAG

AG Secured File Upload- DescriptionFast file content verificationVerify that the extension of the file matches

the file contentPass file to antivirus to check virus in contentBlock dangerous content before reaching

internal site.

Page 28: Extending ISA/IAG beyond the limit. AGAT Security suite - introduction AGAT Security suite is a set of unique components that allow extending ISA / IAG

ENDSee more filters available on

http://www.agat.co.il