<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Partner Technical Specialists Ireland : IAG Server</title><link>http://blogs.technet.com/ptsirl/archive/tags/IAG+Server/default.aspx</link><description>Tags: IAG Server</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Intelligent Application Gateway (IAG) Server 2007 overview</title><link>http://blogs.technet.com/ptsirl/archive/2007/06/04/intelligent-application-gateway-iag-server-2007-overview.aspx</link><pubDate>Mon, 04 Jun 2007 13:22:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1141319</guid><dc:creator>Partner Technical Specialists</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/ptsirl/comments/1141319.aspx</comments><wfw:commentRss>http://blogs.technet.com/ptsirl/commentrss.aspx?PostID=1141319</wfw:commentRss><wfw:comment>http://blogs.technet.com/ptsirl/rsscomments.aspx?PostID=1141319</wfw:comment><description>&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 10pt"&gt;&lt;FONT face=Calibri size=3&gt;IAG Server (formerly known as WHALE) is a SSL VPN appliance that considerably simplifies the way you can provide remote access to applications.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The acquisition of IAG from Whale Communications, was one of those instances where we liked the product so much, we bought the company. &lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 10pt"&gt;&lt;FONT face=Calibri size=3&gt;Most SSL VPN solutions are hard to implement, because they do not work from most locations, due to an inability to install client-side software and/or due to firewall restrictions.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;With IAG Server you simply need a web browser (Internet Explorer, Firefox...) to get access to the published applications.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 10pt"&gt;&lt;FONT face=Calibri size=3&gt;The uniqueness of IAG Server resides in the fact it will give remote users access to a specific application but not to the local network or servers themselves (the remote user’s machine is never connected to the corporate network).&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;To explain: IAG Server typically would not handle packets from layer 1 to 6 and will only send/receive packets from layer 7 (application layer) to the remote user.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;In other words it means the remote user does not even get a company’s network IP address. So the user has absolutely no network access at all to a company network, but still he/she will be able to access published applications such as Outlook Web Access, Domino, SAP, WebSphere, SharePoint (Just some examples of the predefined application-specific positive logic to protect back-end servers out of the box).&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 10pt"&gt;&lt;FONT face=Calibri size=3&gt;Out of the box IAG Server is able to work with 60 authentication vendors such as RSA Security, Vasco, Swivel, ActivCard Aladdin. It also works with numerous authentication systems and protocols such as Active Directory, RADIUS, LDAP, NTLM, Lotus Domino, PKI and TACACS+ &lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 10pt"&gt;&lt;FONT face=Calibri size=3&gt;Another great feature is the “attachment wiper”. This feature will systematically erase all traces of the session from the access device (with a pre-downloaded ActiveX or Java applet).&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 10pt"&gt;&lt;FONT face=Calibri size=3&gt;Every time the remote user logs off or simply closes the internet browser, the applet will kick off and delete any trace, including cookies, user credentials memorised by the browser, URL entries, temporary files created by the downloading of files or any other mechanism during the user session. The “attachment wiper” will overwrite seven times the disk clusters where those files were stored, making any reinstatement attempt technically impossible, even with the help of the FBI/NSA forensic tools!&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 10pt"&gt;&lt;FONT face=Calibri size=3&gt;The other main feature of IAG Server is its capability to instantly generate an “endpoint report”.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 10pt"&gt;&lt;FONT face=Calibri size=3&gt;IAG will be able to see if there any anti-virus or a certain patch or application level on the remote machine. So depending of the policy and the user group membership we have the possibility to actually dynamically limit access to some features. For example we could define the fact that if a remote user does not have the latest version of the corporate anti-virus solution, he will not be allowed to upload any attachment to his emails.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 10pt"&gt;&lt;FONT face=Calibri size=3&gt;IAG Server simply eliminates the risk of network attacks and operating system vulnerabilities as it only provides a means to access specific applications (or some of the features only) to approved users from approved machines.&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0cm 0cm 10pt"&gt;&lt;FONT face=Calibri size=3&gt;Michael RIVA, MCSE: Security, MCT&lt;/FONT&gt;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=1141319" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/ptsirl/archive/tags/Microsoft/default.aspx">Microsoft</category><category domain="http://blogs.technet.com/ptsirl/archive/tags/Security/default.aspx">Security</category><category domain="http://blogs.technet.com/ptsirl/archive/tags/IAG+Server/default.aspx">IAG Server</category><category domain="http://blogs.technet.com/ptsirl/archive/tags/Whale+Communications/default.aspx">Whale Communications</category></item></channel></rss>