|
Netilla's Secure Application
Access Overview The
Netilla Security Platform (NSP) appliance is a 1-U high,
rack-mountable server, running Netilla's proprietary Netilla
dynaTRUST O/S, a comprehensive policy management and enforcement
operating system for secure application access management. The
NSP resides in the DMZ, typically behind the corporate firewall
and in front of application servers. With the NSP, ease of
maintenance is key: No integration or programming is required,
while Netilla's Subscription Software Services deliver automated
security and feature updates and upgrades.
As the industry’s most
versatile SSL VPN, the NSP combines three application-access
technologies into a single gateway device. The NSP is available
in three performance classes designed to meet varying capacity
needs, and can be modeled to support one, two or all three
access methods.

NSP
Security Zone
The NSP shields private network resources with application layer
security. The NSP performs as a proxy that terminates, analyzes
and processes all incoming user requests for authentication and
policy before allowing any traffic to reach a secured resource.
Once cleared, traffic is delivered to the appropriate access
engine where it may undergo protocol translation that adds an
additional layer of security for backend resources. Since the
NSP enforces authentication and policy before allowing any data
stream to reach the network, internal resources are effectively
protected.
1.
Secure Intranet Access through Web-Reverse Proxy
The NSP enables secure access to internal Web-based
applications, intranet sites and portals with a proprietary Web
Reverse Proxy technology. The NSP’s built-in HTML translation
engine dynamical rewrites all user requested Web pages,
obscuring the URL, network topology, and source code of the
originating Web application. Also, since all requested pages are
re-written, the NSP is able to filter potentially malicious Web
components on an as-needed basis.
2.
Clientless Access to Remote Applications
With no application client software required, and with just a
Web browser, users can interact with actual applications that
reside in the data center, in the same format as in the office –
but within a browser window securely over the Web. When a user
requests a remote application, the NSP functions as an
application–layer proxy, translating the native protocol used by
the server-based application into a thin-client application
protocol for safe, fast transmission over the Internet. This
remote application protocol also provides dynamic bandwidth
optimization between the remote user and the NSP to insure
greater application performance and enhanced user experience.
Supported Protocols:
- RDP for Windows applications
- X protocol for X Window applications
- Telnet or SSH for UNIX/Linux applications
- 3270 for Mainframes
- HTTP for Web servers
3.
Client/Server Synchronization through SSL Tunneling
The NSP also allows users to work off line with local clients
and “synch up” with remote servers over a secure SSL tunnel.
When synchronizing these applications, such as Microsoft®
Outlook, Lotus Notes, or customer relationship management (CRM)
programs with a remote server, the NSP facilitates a secure, SSL
session that "tunnels" HTTP traffic through complex firewall
environments. The NSP facilitates this connection through the
Netilla Virtual Adapter, an ActiveX component that automatically
downloads to the user’s machine, offering remote connectivity to
TCP- and UDP-based applications.
Additionally, the NSP proactively safeguards against
unauthorized access by enforcing permissions-based policy that
authorizes each user to synchronize specific local desktop
applications with the remote server. Controlled by Netilla's
SecureRealm Framework technology, the policy includes a dynamic
session-based firewall that opens and closes ports on a per-user
and per session basis.
Designed
to insure VPN simplicity, the NSP’s client/server access only
requires a single firewall port to the Internet and is
compatible with environments that implement Network Address
Translation (NAT). See
Features and Benefits...
|