cancel
Showing results for 
Search instead for 
Did you mean: 

So you use your SA as a firewall or just a point of access.

haas_
Contributor

So you use your SA as a firewall or just a point of access.

Just looking for a general consensus here. We have a large

network with about 30,000 users and a large data center. I am wondering do you
build access control on the SA as far as ip's etc that users can go to or do
you just bring them in and control their access with a firewall. Obviously on a
small network you use the SA for both but I would think on a large network you
would let firewalls do the security?

3 REPLIES 3
alan_
Contributor

Re: So you use your SA as a firewall or just a point of access.

I have over 20,000 users but distributed across 9 SA6000's. If they're employees we allow access as if they were at their desktop. From my perspective remote access is just an extension of the LAN - many people telecommute. For Business Partners (and we have lots) we use the access controls on the SA to provide very granular access to resources. If you limit internal users with internal firewalls I'd continue this way and let the SA just provide access.
haas_
Contributor

Re: So you use your SA as a firewall or just a point of access.

Thank you Alan for your reply. I was hoping some others would chime in as well.

Regards,

Haas

Fahad_khan_
Occasional Contributor

Re: So you use your SA as a firewall or just a point of access.

Juniper Secure Access Box provides profile based VPNs over SSL. It facilitates a great deal of Flexibility regarding secure LAN access. You can also provide secure access of client server applications via SAM.

I have seen that what ever we think of deploying any technique under VPN, we can have it with SSL.

Its endpoint security checks are simply owesome.

One of a very good aspects is client doecnot need to do any thing. He/she can have all the allowed resources by just writing a URL in a web brower.

It can also be intergarted with IDP and NSM (for managment).

I should say, it is simply a fantastic box for e-commerce.

regards,