• No results found

nexus Hybrid Access Gateway

N/A
N/A
Protected

Academic year: 2021

Share "nexus Hybrid Access Gateway"

Copied!
7
0
0

Loading.... (view fulltext now)

Full text

(1)

Product Sheet

neXus Hybrid Access Gateway

neXus Hybrid Access Gateway

neXus Hybrid Access Gateway uses the inherent simplicity of virtual appliances to create matchless security, even beyond the boundaries of the corporate network. Access mission-critical data safely at any time using your favorite device!

neXus Hybrid Access Gateway is an exceptional remote access solution that makes on-premises and cloud applications available on any device or platform. The solution also fits perfectly in Bring Your Own Device (BYOD) scenarios. You can easily deploy the Gateway Virtual Appliance into your virtual infrastructure from the cloud – there is no need to install software or maintain an operating system.

Imagine all your organization can gain with: ž ž Greater security ž ž Ease of use ž ž Minimal administration

Versatile Risk-Appropriate Authentication

The security and trust level of an authentication solution depends on the number of factors required for successful identification. An authentication solution capable of withstanding any type of identity fraud should consist of a combination of these factors:

ž

ž What you know – a static username and password is the most basic authentication level

ž

ž What you have – a unique possession, such as a hardware token, a mobile phone, or smartcard

ž

(2)

Strong multi-factor authentication protects against phishing, password cracking, key logging and many other types of identity theft. neXus Hybrid Access Gateway offers a number of authentication methods with different authentication strengths in one flexible, integrated solution. Organizations can empower their users with authentication technology that is easy to use, easy to manage, cost-effective and secure. The broadness of different authentication methods allows for a versatile authentication strategy.

The benefit of using a platform supporting versatile authentication is that you can apply the most appropriate authentication method to each application. Practically, you can use simple password-based authentication to provide access to less sensitive applications, and more complex authentication to secure access to highly sensitive data. When an already authenticated user request access to a more sensitive application, you can apply step-up authentication, which requires the user to authenticate again with an

additional credential. This is what the industry refers to as risk-appropriate authentication.

neXus Hybrid Access Gateway is easy to integrate with existing infrastructures. It uses standard authentication protocols and is extendible through a plug-in API, which facilitates the use of new or custom authentication methods. Open standards such as X.509, Open Authentication (OATH) and LDAP are supported.

Mobile App Security

The neXus solution also brings strong authentication and secure electronic identities to mobile apps by supporting OAuth 2.0 standards. The OAuth 2.0 authorization framework provides applications (web-based and mobile) with

(3)

authorized applications. Let the neXus solution manage the complex tasks of authentication and authorization – and allow your developers to focus on your core development and core business.

Policy Enforcement

A secure encrypted channel between the user and the application is ensured by Single Sign-On (SSO) enforcement and remote access to applications via your web browser. No client software needs to be installed. Web SSL reverse proxy/SSL VPN functionality is used with session cookies to manage and track sessions from log-on until the connection is terminated.

neXus Hybrid Access Gateway makes it easy to create secure deployments by using Distributed Mode. With Distributed Mode the Policy Enforcement and the Policy Decision Points are split into separate Virtual Appliances. In this way an optimal secure network architecture can be designed.

neXus Hybrid Access Gateway makes it easier to satisfy your company’s enforcement policies as it allows you to set access rules for various authentication levels and locations. Clientless client-server application access is supported using unique application virtualization based on HTLM5 and websocket technology.

Application Portal

(4)

Single Sign-On Enforcement

One user and a single login is a breakthrough with advantages for everyone. In addition to providing seamless access to applications, it also reduces password management and

significantly improves the user experience. The user only needs to sign in once – any subsequent authentication to back-end applications is automatically handled within the system.

All traditional web applications remain accessible. HTML5 and websockets enable the use of non-web applications in browsers and support the ability to offer remote desktops.

The SAML 2.0 standard is supported to secure identities, Federation integrity and Cloud Applications, both inside and outside your system.

Supported SAML 2.0 standards: ž

ž SAML Identity and Service Provider ž

ž Web Browser SSO profile with redirect and POST bindings ž

ž Basic Attribute Profile ž

ž SAML Metadata ž

ž SAML Single Log-out as Service Provider

Identity Orchestration

Using standards like SAML and SCIM or proprietary APIs, first-time users are automatically provisioned for application access. neXus Identity Orchestration provides life-cycle identity management together with access control – for on-premises services as well as public and private cloud services. The result is reduced cost, account control and privacy compliance – all while enhancing the end-user experience.

Authorization and Policy-Based Access

All access in the system is based on dynamic evaluation

(5)

authorization engine using role-based and attribute-based access controls. User storage integration enables the reuse of roles and user attributes.

Access rules are evaluated based on numerous decision

parameters including user role, authentication method, device type and trusted or untrusted location/IP address.

Identity Orchestration integrates with SCIM, Google API and POST-based API making it possible to reduce user account administration by automatically pushing user details, for example to create, authenticate and auto-link new accounts.

Enterprise Administration

As a virtual appliance, neXus Hybrid Access Gateway boasts simplified administration with easier deployments, upgrades and maintenance – all via web-based automation.

A Central Management Console features a comprehensive platform for consolidating your administrative tasks.

Delegated Management shifts administration rights from one organizational level/department to another, and real-time alerts can be sent via email and SMS.

The web-based administration interface provides wizards for common tasks and aids the creation of users, access rules and resources. Rollback functionality tracks the history of published configurations and makes it possible to revert back to prior configurations. The interface automatically adapts to the features included in your neXus Hybrid Access Gateway license. Support is included for delegated administration, graphical reporting and the publication of service

(6)

Auditing

When it is time to audit, all data is at your fingertips.

Consolidated and comprehensive auditing functionality tells you who did what, when, where and how. This is particularly useful for compliance officers and corporate governance teams.

All statistical data from the logging system is stored in a central repository for single-point retrieval. Real-time and historical reporting can be shown in many different graphical formats, such as pie charts, line charts, 3D charts and bar graphs. All data is exportable in text format so that it can be easily processed in, e.g., Excel.

User Data

(7)

Authentication

The Hybrid Access Gateway features strong authentication supporting a wide range of methods:

1-factor authentication

ž

ž Web Token, Password

2-factor authentication ž ž Invisible Token ž ž Mobile Text ž

ž Soft OTP Token (TruID Syncronized/Challenge) ž

ž OATH HOTP

SOTA, Secure Online Token Activation for TruID Soft OTP Token

ž

ž QR code activation url:s support for TruID on Android and iOS Devices (iPhone/iPad)

PKI/Certificates

ž

ž X.509, e-ID, BankID, SITHS, SmartCards etc.

3rd-party authentication

ž

ž Radius, LDAP, Active Directory, Basic, NTLM

Creation of custom authentication plug-ins

ž

ž XPI:am

APIs for third party integration

ž

ž XPI:am, to create custom authentication plugins ž

References

Related documents

The MFH2 Multi satellite tap allows up to four FMC-6 chassis units to be connected to a common satellite distribution

provident दपरदशतर" Every brilliant student might have a provident. relinquish छबड़ दकनक" You should relinquish a bad habit. She relinquished

In this paper, we have analyzed the security threats an ad-hoc network faces and presented the security objective that need to be achieved.In this paper, a survey on

Using the menu available from the Access Gateway icon in the notification area, you can open the Citrix Access Gateway Configuration dialog box.. You can view information about

If you want to connect using the Access Gateway Plugin without using a Web browser, you can configure the plugin to display the logon dialog box when you click the icon in

If you are using Internet Explorer or the Mac OS X Safari Web browser to connect to the Access Gateway logon page, the Access Gateway Plugin for Java changes the proxy settings

For information on obtaining your eMerchant Gateway credentials after signing up for an account and for the setup of the eMerchant Gateway to process transactions and for access

Two recently detected viruses, human metapneumovirus (hMPV) and coronavirus NL63 (HCoV-NL63), have been associated with acute respiratory tract infections, particularly in