Juniper Networks Secure Access SSL VPN Configuration Guide

As firewalls and NAT have become widely implemented, traditional attacks against internal machines are not directly possible. Therefore, many attackers have been shifting their attack mechanisms to attack clients through indirect methods (e.g., luring clients to malicious Web sites) rather than directly, because they cannot directly access the clients. This shift in attack methodology has forced administrators to alter their defensive practices as well. Administrators are increasingly relying on software on the client machines (antivirus, antispyware, and antimalware software, patch management, firewalls, etc.) to help prevent attacks from external sources. Because many of your users will either have mobile assets that travel to many different networks and/or use machines that you do not manage, you need something to turn to that can provide remote access and help ensure that users are in compliance with your security standards before they can connect to your network. Host Checker helps to ensure compliance on Windows, Macintosh, and Linux machines.
Direct attacks are not the only thing you have to worry about as an administrator. You also have to worry about your intellectual property being stolen or compromised. For instance, if a user logs into a machine, browses for some content on your company intranet site, and then leaves the machine, he may leave sensitive information behind. The IVE implements two features to help protect against this. One is called Cache Cleaner, which removes files remaining on the user's computer, and the other is Secure Virtual Desktop, which creates a virtual environment where...