EZ-VPN Status - PowerPoint PPT Presentation

1 / 13
About This Presentation
Title:

EZ-VPN Status

Description:

EZ-VPN Status Campus-wide VPN Service September 13, 2006 Overview Provides VPN service for individuals remote to campus provides encrypted session from the end ... – PowerPoint PPT presentation

Number of Views:33
Avg rating:3.0/5.0
Slides: 14
Provided by: ccdCornel
Category:
Tags: vpn | status

less

Transcript and Presenter's Notes

Title: EZ-VPN Status


1
EZ-VPN Status
  • Campus-wide VPN Service
  • September 13, 2006

2
Overview
  • Provides VPN service for individuals remote to
    campus provides encrypted session from the end
    user to the VPN concentrator
  • Uses incumbent AAA backend services
  • Roughly analogous to dial-up services
  • Survey Results file service and remote
    application access.

3
Service Scenarios
  • Internet to campus private address space
    connectivity.
  • Encryption for traditionally non-ciphered
    applications (e.g. file service).
  • Identify source by User and remote IP.
  • Additional access control to campus service.

4
Scenario campus private address space
5
Scenario campus private address space
6
Scenario campus private address space
7
Scenario encrypting non-encrypted services
8
Initial Goals
  • Windows and MacOS support.
  • Cisco VPN client software (IPSec) or java-based
    WebVPN (SSL).
  • Login with campus NetID.
  • Common pool (no group support).
  • Preconfigured Keys with Client Distribution.
  • Basic Login and Traffic accounting.
  • Network Quarantine support.
  • Dual, load-balancing servers.

9
IPSec VPN Tunnels
  • IPSec requires Cisco VPN client. Native VPN
    clients not initially supported.
  • Split-tunnel routing. Tunnels campus-only
    traffic all other remote traffic routes
    normally.
  • Export Restriction Do not download, resell,
    transfer, export, or re-export software images to
    any end user or entity in the following countries
    without a United States Export License
  • Cuba, Iran, Libya, North Korea, Sudan, and Syria.

10
WebVPN (SSL-based)
  • SSL connectivity via any Web Browser.
  • Java jars downloaded from VPN server (can be
    saved too).
  • Specific Connectivity planned for http and
    Microsoft services only.
  • Resource Intensive on the VPN server. For truly
    casual access.

11
Cisco VPN Client Screen
12
WebVPN Client Screen
13
Issues
  • Camping Idle timeouts and stale credentials?
  • Cable Router Support?
  • Guest Login?
  • Groups and pools?
  • Detailed Admission Requirements patch-levels,
    firewall, AV?
  • Multicast (Apple, Plug-and-Play, Ghost, CUTV)?
  • Site-to-Site and Static Reverse Tunnels?
Write a Comment
User Comments (0)
About PowerShow.com