140 likes | 264 Views
Přístup k informacím Jaroslav Dvořák. Agenda. SSL jako jediný protokol pro přístup k informacím a datům. any number of employees and partners. any connection. any device. Access Anyone, Anywhere, Any Device over Any Connection. any location. DEMO Citrix Presentation server.
E N D
Agenda • SSL jako jediný protokol pro přístup k informacím a datům
any number of employees and partners any connection any device Access Anyone, Anywhere, Any Device over Any Connection any location
DEMO Citrix Presentation server • Publikovaná aplikace v. desktop • CSG – Citrix Secure Gateway • SSL VPN – CAG – Citrix Access Gateway
K čemu je to dobré ? • Instalace a doručování aplikací (aplikace vyžaduje IE7, verzi office,…, údržba aplikací) • Dostupnost aplikací • Bezpečnost „by design“ • Prodloužení životního cyklu koncové stanice • Mobilitu • Jakékoli zařízení • Jakýkoli typ připojení • Snížení počtu administrátorů • Nižší náklady na LAN/WAN • Doručení aplikace na vyžádání (SPLA licence)
Web Browser Secure Web Server Optional 3rd Party Authentication Citrix Secure Gateway (CSG) Authentication Access Mgmt. Secure Connectivity DMZ ICA/SSL 443 ICA Client CSG Server ICA/1494 MetaFrame Server Farm Firewall Firewall Citrix Secure Gateway .ICA file 443 ClientWorkstations HTTP/S CitrixNFuseClassic NFuse Citrix XML Service Internet XML-HTTP/80 DMZ Internal Network
Internet Legend full access partial access access denied How it works –Citrix Access Gateway Control, Manage and Log Access and Resource usage: OK • Published Apps • Mapped Drives • Local Printing MPS Applications Corporate Laptops Internal Users • Email Synchronization • Attachment Access • Launch locally • ICA Launch • Launch to memory • Preview read-only Firewall Firewall loginagent loginagent Email Servers External Users UI HTTPS • URL Access • File Access • Launch locally • ICA Launch • Launch to memory • Preview read-only Home PCs Web Servers AccessManagementand Control endpointanalysis • File Access • Launch locally • ICA Launch • Launch to memory • Preview read-only Kiosks File Servers PDAs unsecured network DMZ secured network • Other protocols App Servers
Internet Legend full access partial access access denied How it Works Control, Manage and Log Access and Resource usage: OK • Published Apps • Mapped Drives • Local Printing MPS Applications Corporate Laptops Internal Users • Email Synchronization • Attachment Access • Launch locally • ICA Launch • Launch to memory • Preview read-only Firewall Firewall loginagent loginagent Email Servers External Users UI HTTPS • URL Access • File Access • Launch locally • ICA Launch • Launch to memory • Preview read-only Home PCs Web Servers AccessManagementand Control endpointanalysis • File Access • Launch locally • ICA Launch • Launch to memory • Preview read-only Kiosks File Servers PDAs unsecured network DMZ secured network • Other protocols App Servers
Internet Legend full access partial access access denied How it Works Control, Manage and Log Access and Resource usage: • Published Apps • Mapped Drives • Local Printing MPS Applications Corporate Laptops Internal Users • Email Synchronization • Attachment Access • Launch locally • ICA Launch • Launch to memory • Preview read-only Firewall Firewall loginagent loginagent Email Servers External Users UI OK HTTPS • URL Access • File Access • Launch locally • ICA Launch • Launch to memory • Preview read-only Home PCs Web Servers AccessManagementand Control endpointanalysis • File Access • Launch locally • ICA Launch • Launch to memory • Preview read-only Kiosks File Servers PDAs unsecured network DMZ secured network • Other protocols App Servers
Reference • Kraj Vysočina • Magistrát města Jihlavy • Magistrát města Karlovy Vary • Františkovy Lázně • WITTE Nejdek • Bosch Diesel • Automotive Lighting • Poděbradka • Colas CZ • TERCO Telč nábytek • Zexel Valeo • Pleas-Schiesser International • Český Telecom • Kooperativa pojišťovna a.s. • Plastika Nitra • Raven • Cesty Nitra • Biama • Jihomoravská energetika • CE Wood • MINOLTA • …
Jak na to? • Testovat • Aplikace • Profily • Tisky • Výkon • Spustit provoz • Monitorovat a provozovat
Děkuji vám za pozornost! Jaroslav Dvořák jaroslav.dvorak@autocont.cz