Aventail's EX-1500SSL VPN Appliances

Do the updates to management, logging and cache-cleaning add up to improvements for this VPN device?

July 2, 2004

2 Min Read
NetworkComputing logo in a gray background | NetworkComputing

Cache Change

Web browsers cache data on the local hard drive--making subsequent page loads faster. However, cached data may stick around after the user has logged off. Aventail's cache control removes cached data, cookies, history, and both temporary and stored passwords. In addition, the cache control can close a browser window after a period of inactivity.

I enabled the cache control for ASAP and configured an inactivity time-out. When I connected to the ASAP Workplace using both Internet Explorer and Netscape Navigator, the Java applet was downloaded and executed before I was directed to the login page. After browsing the Web and closing the browser, the cache was deleted.

Unfortunately, I was able to shut down the cache cleaner easily by opening the Windows Task Manager and halting the cclient.exe process. I kept browsing, but the cache was not cleaned afterward. Aventail says it will fix this in an upcoming release.

Aventail's EX-1500SSL VPN AppliancesClick to Enlarge

Management Updates

Good

Bad

Aventail EX-1500 SSL VPN Appliance 7.1, starts at $9,495 for 25 concurrent users. Aventail Corp., (877) AVENTAIL, (206) 215-1111. www.aventail.com

Managing ACLs (access control lists) can be especially difficult with large lists. With the old device, you had to first define all the objects before you could add an access control rule. With 7.1, Aventail has streamlined the ACL definition process by letting you add objects as needed. Although this isn't ground-breaking, it certainly helps.Version 7.1 supports multiple authentication realms that define which back-end systems are used to authenticate users. Aventail also has simplified user and group definition on 7.1, with a directory browser. You don't need to use multiple tools to discover the schema definition--the browser presents it in a checkbox format.

Aventail also has added some reporting options and support for SNMP traps, but the log files available through the ASAP management interface are in the common log format and, without any processing, are nearly useless for troubleshooting or tracking purposes. Also, the EX-1500 supports only syslog-ng, which uses TCP and not UDP. You must install a syslog-ng server to capture the logs or make manual modifications on the command line.

Mike Fratto is a contributing editor to Network Computing and editor of our sister publication Secure Enterprise. Write to him at [email protected].

SUBSCRIBE TO OUR NEWSLETTER
Stay informed! Sign up to get expert advice and insight delivered direct to your inbox

You May Also Like


More Insights