130 likes | 320 Views
Overview. Provides VPN service for individuals remote to campus provides encrypted session from the end user to the VPN concentratorUses incumbent AAA backend servicesRoughly analogous to dial-up servicesSurvey Results: file service and remote application access.. Service Scenarios. Internet to
E N D
1. EZ-VPN Status Campus-wide VPN Service
September 13, 2006
2. Overview Provides VPN service for individuals remote to campus – provides encrypted session from the end user to the VPN concentrator
Uses incumbent AAA backend services
Roughly analogous to dial-up services
Survey Results: file service and remote application access.
3. Service Scenarios Internet to campus private address space connectivity.
Encryption for traditionally non-ciphered applications (e.g. file service).
Identify source by User and remote IP.
Additional access control to campus service.
4. Scenario: campus private address space
5. Scenario: campus private address space
6. Scenario: campus private address space
7. Scenario: encrypting non-encrypted services
8. Initial Goals Windows and MacOS support.
Cisco VPN client software (IPSec) or java-based WebVPN (SSL).
Login with campus NetID.
Common pool (no group support).
Preconfigured Keys with Client Distribution.
Basic Login and Traffic accounting.
Network Quarantine support.
Dual, load-balancing servers.
9. IPSec VPN Tunnels IPSec requires Cisco VPN client. Native VPN clients not initially supported.
Split-tunnel routing. Tunnels campus-only traffic; all other remote traffic routes normally.
Export Restriction: Do not download, resell, transfer, export, or re-export software images to any end user or entity in the following countries without a United States Export License:
Cuba, Iran, Libya, North Korea, Sudan, and Syria.
10. WebVPN (SSL-based) SSL connectivity via [any] Web Browser.
Java jars downloaded from VPN server (can be saved too).
Specific Connectivity: planned for http and Microsoft services – only.
Resource Intensive on the VPN server. For truly casual access.
11. Cisco VPN Client Screen
12. WebVPN Client Screen