Showing posts with label ssl vpn. Show all posts
Showing posts with label ssl vpn. Show all posts

Sunday, April 5, 2020

Connect to the F5 VPN with BIG-IP Edge Client

Your organization may have F5 BIG-IP APM for VPN access. See how you can connect to your org's VPN using the BIG-IP Edge Client along with Chrome, Microsoft Edge and Firefox browsers. How to authenticate, do MFA, check settings and what is split-tunneling. You can also get the F5 Access mobile app for iOS, Android and Windows Phone from the respective app stores.


 

ps

Tuesday, November 13, 2012

SharePoint Conference 2012: Secure Remote Access & SSO with BIG-IP APM

SharePoint Conference 2012: Secure Remote Access & SSO with BIG-IP APM

I catch Greg Coward, F5 Solution Engineer, to show how to configure BIG-IP APM to provide Secure Remote Access and SSO to #SharePoint. Yesterday we configured SharePoint with a F5 iApp and today we’re adding secure remote access to the deployment. #spc12

 

ps

Resources:

Technorati Tags: F5,big-ip,security,management,infrastructure,sharepoint,cloud,waf,tmg, analytics,psilva,video

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Tuesday, October 23, 2012

BYOD Policies – More than an IT Issue Part 5: Trust Model

#BYOD or Bring Your Own Device has moved from trend to an permanent fixture in today's corporate IT infrastructure. It is not strictly an IT issue however. Many groups within an organization need to be involved as they grapple with the risk of mixing personal devices with sensitive information.  In my opinion, BYOD follows the classic Freedom vs. Control dilemma. The freedom for user to choose and use their desired device of choice verses an organization's responsibility to protect and control access to sensitive resources. While not having all the answers, this mini-series tries to ask many the questions that any organization needs to answer before embarking on a BYOD journey.

Enterprises should plan for rather than inherit BYOD. BYOD policies must span the entire organization but serve two purposes - IT and the employees. The policy must serve IT to secure the corporate data and minimize the cost of implementation and enforcement. At the same time, the policy must serve the employees to preserve the native user experience, keep pace with innovation and respect the user's privacy.  A sustainable policy should include a clear BOYD plan to employees including standards on the acceptable types and mobile operating systems along with a support policy showing the process of how the device is managed and operated.

Some key policy issue areas include: Liability, Device Choice, Economics, User Experience & Privacy and a Trust Model.  Today we look at Trust Model.

Trust Model

Organizations will either have a BYOD policy or forbid the use all together. Two things can happen if not: if personal devices are being blocked, organizations are losing productivity OR the personal devices are accessing the network (with or without an organization's consent) and nothing is being done pertaining to security or compliance.

Ensure employees understand what can and cannot be accessed with personal devices along with understanding the risks (both users and IT) associated with such access. While having a written policy is great, it still must be enforced.  Define what is ‘Acceptable use.’ According to a recent Ponemon Institute and Websense survey, while 45% do have a corporate use policy, less than half of those actually enforce it.

And a recent SANS Mobility BYOD Security Survey, less than 20% are using end point security tools, and out of those, more are using agent-based tools rather than agent-less.  According to the survey, 17% say they have stand-alone BYOD security and usage policies; 24% say they have BYOD policies added to their existing policies; 26% say they "sort of" have policies; 3% don't know; and 31% say they do not have any BYOD policies.  Over 50% say employee education is one way they secure the devices, and 73% include user education with other security policies.

Organizations should ensure procedures are in place (and understood) in cases of an employee leaving the company; what happens when a device is lost or stolen (ramifications of remote wiping a personal device); what types/strength of passwords are required; record retention and destruction; the allowed types of devices; what types of encryption is used.  Organizations need to balance the acceptance of consumer-focused Smartphone/tablets with control of those devices to protect their networks.  Organizations need to have a complete inventory of employee's personal devices - at least the one’s requesting access.  Organizations need the ability to enforce mobile policies and secure the devices.  Organizations need to balance the company's security with the employee's privacy like, off-hours browsing activity on a personal device.

Whether an organization is prepared or not, BYOD is here. It can potentially be a significant cost savings and productivity boost for organizations but it is not without risk. To reduce the business risk, enterprises need to have a solid BYOD policy that encompasses the entire organization. And it must be enforced.

Companies need to understand:

• The trust level of a mobile device is dynamic

• Identify and assess the risk of personal devices

• Assess the value of apps and data

• Define remediation options

• Notifications

• Access control

• Quarantine

• Selective wipe

• Set a tiered policy

Part of me feels we’ve been through all this before with personal computer access to the corporate network during the early days of SSL-VPN, and many of the same concepts/controls/methods are still in place today supporting all types of personal devices.  Obviously, there are a bunch new risks, threats and challenges with mobile devices but some of the same concepts apply – enforce policy and manage/mitigate risk  As organizations move to the BYOD, F5 has the Unified Secure Access Solutions to help.

 

ps

Related

Technorati Tags: F5, data breach report, threats, Pete Silva, security, malware, technology, smartphone, cyber-threat, social engineering, attacks, virus, vulnerability,web,internet, cybercrime, identity theft, scam, data breach

Connect with Peter:

Connect with F5:

o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Thursday, September 13, 2012

BIG-IP Edge Client 2.0.2 for Android

app logoEarlier this week F5 released our BIG-IP Edge Client for Android with support for the new Amazon Kindle Fire HD.  You can grab it off Amazon instantly for your Android device.  By supporting BIG-IP Edge Client on Kindle Fire products, F5 is helping businesses secure personal devices connecting to the corporate network, and helping end users be more productive so it’s perfect for BYOD deployments.

The BIG-IP® Edge Client™ for all Android 4.x (Ice Cream Sandwich) or later devices secures and accelerates mobile device access to enterprise networks and applications using SSL VPN and optimization technologies. Access is provided as part of an enterprise deployment of F5 BIG-IP® Access Policy Manager™, Edge Gateway™, or FirePass™ SSL-VPN solutions.

BIG-IP® Edge Client™ for all Android 4.x (Ice Cream Sandwich) Devices Features:

  • Provides accelerated mobile access when used with F5 BIG-IP® Edge Gateway
  • Automatically roams between networks to stay connected on the go
  • Full Layer 3 network access to all your enterprise applications and files
  • Supports multi-factor authentication with client certificate
  • You can use a custom URL scheme to create Edge Client configurations, start and stop Edge Client

410esc3NxBL41ThjiC-I8L

BEFORE YOU DOWNLOAD OR USE THIS APPLICATION YOU MUST AGREE TO THE EULA HERE:
http://www.f5.com/apps/android-help-portal/eula.html

BEFORE YOU CONTACT F5 SUPPORT, PLEASE SEE:
http://support.f5.com/kb/en-us/solutions/public/2000/600/sol2633.html

If you have an iOS device, you can get the F5 BIG-IP Edge Client for Apple iOS which supports the iPhone, iPad and iPod Touch.  We are also working on a Windows 8 client which will be ready for the Win8 general availability.

ps

Resources

Technorati Tags: F5, infrastructure 2.0, integration, cloud connect, Pete Silva, security, business, education,technology, application delivery, ipad, cloud, context-aware,infrastructure 2.0, iPhone, web, internet, security,hardware, audio, whitepaper, apple, iTunes

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]