
All contents are Copyright © 1992–2006 Cisco Systems, Inc. All rights reserved. This document is Cisco Public Information. Page 4 of 10
Table 3 provides a list of features associated with Cisco VPN 3000 Series support for Citrix.
Table 3. Citrix Support: Enhanced Access to Internal Network Infrastructure Resources with Clientless Citrix Support
Feature Description
Access to System Resources Clientless access alleviates potential issues caused when incongruent browser or security settings prohibit the download
of a client or applet
Swift Connectivity Application initiation is instantaneous, with no additional software client or applet downloads required
Highly Stable Support Client software conflicts with unmanaged machines or unfamiliar images are avoided with clientless access
IPsec VPN—Cisco Easy VPN and Auto-Upgradable Cisco IPsec VPN Client
IPsec VPNs offer the security and encryption features necessary to protect enterprise data, IP voice, and video traffic as it traverses the
Internet. Because IPsec can be deployed across any IP network, it is an attractive option for customers needing VPN services and has
become the de-facto standard in remote access.
Fast, Easy, and Scalable Deployment
Simple to deploy and operate, the Cisco VPN Client is used to establish secure, end-to-end encrypted tunnels to Cisco VPN 3000 Series
Concentrators. This thin-client design, IPsec-compliant implementation is licensed for an unlimited number of users. The Cisco IPsec VPN
Client can be preconfigured for mass deployments; the initial logons require little user intervention. It may be automatically upgraded to
newer client versions upon user connection, easing client version management on remotely deployed systems. Using Cisco Easy VPN,
VPN access policies are created and stored centrally in the concentrator and pushed to the client when a connection is established. This
helps ensure dynamically updated, zero-touch configuration of IPsec remote clients. Cisco Easy VPN Remote allows dynamic
configuration of end-user policy, requiring less manual configuration by end users and field technicians—reducing errors and further
service calls while providing centralized security policy management. The Cisco Easy VPN Server allows the concentrator to act a VPN
gateway for site-to-site or remote-access VPNs, and pushes security policies defined at the central site to the remote VPN device, helping
to ensure that those connections have up-to-date policies in place before the connection is established.
Cisco VPN 3002 Hardware Client
The Cisco VPN 3002 Hardware Client is a small hardware appliance that operates as a client in VPN environments. It combines the best
features of a software client, including scalability and easy deployment, with the stability and independence of a hardware platform. By
integrating Cisco Easy VPN with the Cisco VPN 3002 Hardware Client, customers can reduce the management complexity of VPN
deployments and simplify remote-side administration.
Comprehensive Security Policy Compliance with NAC
NAC is an industrywide collaboration effort led by Cisco, established to help ensure that every endpoint complies with network security
policies before being granted access. Cisco VPN 3000 Concentrator Software v4.7 is NAC-enabled for IPsec remote-access scenarios.
NAC reduces the risk associated with extending network resources in remote-access scenarios by preventing vulnerable hosts from
obtaining and retaining normal network access. The Cisco AYT feature enforces firewall policies for users connecting using the Cisco
IPsec VPN Client. Administrators can configure the VPN to refuse endpoints that are in violation of the designated firewall policy. The
Cisco IPsec VPN Client polls the firewall every 30 seconds to make sure it is still running. AYT checks for the Cisco Security Agent,
Cisco Integrated Client Firewall, Network ICE BlackICE Defender, Sygate Personal Firewall, Sygate Personal Firewall Pro, Sygate
Security Agent, Zone Labs ZoneAlarm, and Zone Labs ZoneAlarm Pro.
Komentarze do niniejszej Instrukcji