Functional Overview
Accops HySecure is a Secure Access Gateway that:
- allows trusted remote users to access to any kind of application securely over the internet, using secure protocols like TLS 1.2 and strong configurable ciphers.
- supports granular access control - Application-, user- and device-level; and various authentication mechanism - Microsoft Active Directory, LDAP, RADIUS or local authentication.
- supports Clientless Access where in the access provided through browsers that helps hide the details of the application from the remote user.
- supports client-based application access in case more control is needed by the user. The applications can also be accessed through mobile devices like iPad, Android phones or iOS phones.
- acts as an IDP (Identity Provider) and interact with Service Providers using SAML to provide Single Sign-On with applications which are delivered as SaaS like Office 365, Salesforce etc. Alternatively, it can also be used as an Identity Service Provider by hosting the applications indicated above. In either case, an Accops proprietary solution, HyID, can be used for Multi-factor Authentication with password authentication being one and the other being sms/e-mail token, bio-metric etc.
A typical deployment is depicted here followed by some of the common use cases.
Use Cases
Access to organization resources and/or applications.
This is the core solution which is provided by HySecure and helps the mobile users access the company resources like applications, networks, VDI (Virtual Desktop Interface) or hosted applications, in a highly secure manner. The remote users need to have access to internet and a browser. The network access can either be access to a subnet or a range of IPs or for that matter a specific IP.
This kind of access can also be provided to vendors or employees working from home.
Access from Mobile Device
The remote users can connect to the organization resources using either web-based portals or through a client or even by using a hybrid portal. The support of pure web-based portals for accessing the organization resources help in a seamless access of those resources for the mobile device users.
Restricted Internet for Remote users
HySecure can also setup the remote user configuration in a way to force them to route all traffic through the HySecure Gateway. As a result, internet restrictions can be applied on them resulting in better productivity of users.
Prevention of Data Leakage
HySecure can also help in ensuring that the users who connect in to the network, are not able to either print the screen or record the desktop events or for that matter even access clipboard. This restriction can be selectively applied on users.
Replacing old solutions
An existing solution like Juniper / Checkpoint appliance-based VPN can be replaced with Accops HySecure in a relatively seamless manner.