Why does SSL VPN require client for full functionality?So What's the point?

I was interested in SSL VPN because I thought that I could have the same functionality I have when connecting via Cisco VPN 3000 concentrator (IPSec with AH and ESP enabled), but without the hassle to deploy and maintain client VPN's for thousands of users.
However, to my disappointment, based on the information below from www.cisco.com (and I believe that it is the case from other vendors, right?) SSL VPN offers limited functionality if deployed clientless. Why is like that?
Imagine I have a VPN (IPSec) solution functional today. If I deploy SSL VPN (clientless) what lack in functionality should I experience? Why a VPN client is required if SSL VPN can successfully establish the tunnel? I don't get it.
"...SSL VPNs provide two different types of access: clientless access and full network access. Clientless access requires no specialized VPN software on the user desktop; all VPN traffic is transmitted and delivered through a standard Web browser. Because all applications and network resources are accessed through a browser, only Web-enabled and some client-server applications-such as intranets, applications with Web interfaces, e-mail, calendaring, and file servers-can be accessed using a clientless connection. This limited access is suitable for partners or contractors that should be provided access to a limited set of resources on the network. And because no special-purpose VPN software has to be delivered to the user desktop, provisioning and support concerns are minimized."

Hi,
Clientless SSL VPN only able to access application through browser (i.e. HTTP and HTTPS). If you need to acces other application like RDC, you need full SSL client.
Full SSL Client is deployed automatically depends on how you configure the SSL VPN box (temporary or permanently);
1. From the SSL VPN box, you can configure it to download and be installed to user PC permanently (500KB+). When the user successfully authenticated by the SSL VNP box, it will download the client and install automatically/permanently without any help from the network administrator. The user need to login on his/her PC with administrator priviledge.
2. From the SSL VPN box, you can configure it to download and be installed to user PC temporary (500KB+). When the user successfully authenticated by the SSL VPN box, it will download the client and install temporary without any help from the network administrator. The user need to login on his/her PC with administrator priviledge.
In one of my deployment, I have 1000+ SSL VPN user. I just need to create a 10 page User Manual/Guide complete with troubleshooting on their own. I use the first option which is automatically download and permanently install in their PC. Patching the SSL VPN Full Client need to upload the new client in the SSL VPN box only and it will automatically patch the client in user PC.
Dandy

Similar Messages

  • Why does each app require a separate activation if I am using the same cable subscription for each one?

    Why does each Apple TV app that requires a cable subscription require separate activation/cable verification? I only have one cable subscription, so can the Apple TV just store my info and give me access to all of the app my cable subscription allows? At the very least apps from the same company should all activate at one (ABC and the Disney apps).

    Currently each app is treated separately
    if you wish to give Apple feedback, use the form
    https://www.apple.com/feedback/

  • Why does My Verizon require me to answer my secret question all the time?

    I rarely login to My Verizon.  Let's face it, the account information for Verizon's site aren't exactly as fresh in memory as my mail account or social network authentication details.
    So every few months when I do need to check on something about my account, I will go to login and I am presented with my secret question, because Verizon has never seen this computer before.
    Let me tell you something about secret questions.  They are the most insecure things ever.  "Where is your favorite spot to vacation?"  Well someone who wants in could maybe look at my social networking pictures.  "What was your first pets name?" I don't think it would be very hard for someone to find that out.  These are totally pointless.  The only time I have ever legitimately used one (years ago when these first came out) I set a secret question that was more obscure than these examples and someone guessed it.  So when asked for a secret question what do I do now?  I type a random series of letters beacuse I don't want to weaken my accounts security.
    So every few months when I go to login to Verizon, it thinks my computer is different and at that point decides to prompt me for this worthless "security" question that I am not stupid enough to have legitimately answered.... except now I can't login to my account, so I've got to have Verizon text my phone a code and reset my password and security question just to check some little detail of my bill.
    Get rid of the stupid requirement for a security question for well ANYTHING please, but particularly for not recognizing my PC.  I have NEVER seen another website require this.  My bank doesn't require me to answer security questions to login.  I work in IT at a bank and we don't require this to login unless other authentication methods fail.
    At least Verizon's password rules aren't entirely unique.  I mean, I don't use the same passwords for each account, but at the same time I don't have 72 totally unrelated passwords for my different accounts.  So at least I know my password when I go to login, but it doesn't much matter when my security question now is pretty much set to an illegitimate answer that I am using a second "password".....the only site on the whole Internet I need two passwords for.  Fix this garbage.

        thrift Your security is important to us. We want to make sure that we take the necessary measures to prevent your my verizon account being comprimised. The secret question is used if your computer is not recognized. The next time you log in, look for the option 'remember this device/computer'. This way you will not be asked for the secret question as long as the computer is the same and  password is correct. We hope ths helps.
    Sheritah_vzw
    Follow us on Twitter
    @VZWSupport

  • Why does it take so long for uploaded photos to appear in the photos folder?

    It takes too long for uploaded photos to appear in the photos folders.  I do not like the "new" photos.  I much prefer iPhoto.  Can I make iPhoto my default or am I stuck with this stupid Photos???  Editing is lousy, too.

      Can I make iPhoto my default or am I stuck with this stupid Photos?
    You can continue using iPhoto depending on what version your have?  Currently the only version that runs with 10.10.3 is iPhoto 9.6.1.  What version do you have?  Also do you have a backup copy of your iPhoto library made just prior to upgrading to 10.10.3?

  • SSL VPN with client, anyconnect.

    I've set up a simple test on SSL VPN with client on a 3800.
    It didnt work. I assume i have to turn on the IP http server so that the client can hit it.
    but when I turned it on, the client goes to SDM, nothing with ssl vpn happened. it tells me the pay is not available.
    The underlying routing is fine.
    Could you tell me where it is configured wrong?
    Config is copied below.
    thanks,
    Han
    =======
    Current configuration : 3340 bytes
    version 12.4
    service timestamps debug datetime msec
    service timestamps log datetime msec
    no service password-encryption
    hostname Router
    boot-start-marker
    boot-end-marker
    enable password cisco
    aaa new-model
    aaa authentication login default local
    aaa session-id common
    no network-clock-participate slot 1
    crypto pki trustpoint TP-self-signed-3551041125
    enrollment selfsigned
    subject-name cn=IOS-Self-Signed-Certificate-3551041125
    revocation-check none
    rsakeypair TP-self-signed-3551041125
    crypto pki certificate chain TP-self-signed-3551041125
    certificate self-signed 01
    3082024F 308201B8 A0030201 02020101 300D0609 2A864886 F70D0101 04050030
    31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274
    69666963 6174652D 33353531 30343131 3235301E 170D3131 31313135 31383238
    30365A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649
    4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D33 35353130
    34313132 3530819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281
    8100CFCF CFFAD76A 50DA82C9 8D4E3F90 64AD24EB 5409C5E2 43BC64F3 07F6C0E0
    29FF2D71 0DA0D897 2F814BD2 7F817503 429D4BC6 6AD6EEA4 DFA74BAD 0EAF84D5
    6ED55EC0 6C637178 BEEBCD1D 184BB90C CA84E974 48003885 87B53F2E 36A04661
    23DA2CBB DD8EEE1D 2F25AF9A E21DC288 BF76A17C C1F4BA07 95F09377 A12BE01A
    53750203 010001A3 77307530 0F060355 1D130101 FF040530 030101FF 30220603
    551D1104 1B301982 17526F75 7465722E 776E7362 6E6F632E 696E7465 726E616C
    301F0603 551D2304 18301680 14BE9E8F ED788928 560D7CA1 EED89B0D DE34D772
    5D301D06 03551D0E 04160414 BE9E8FED 78892856 0D7CA1EE D89B0DDE 34D7725D
    300D0609 2A864886 F70D0101 04050003 818100BC 4A2A3C47 7BF809AF 78EE0FD9
    73692913 F280765E BAFAECAB ED32C38D 3030810B C62C7F45 13C8A6EE AE96A891
    CDD4C78B 803299AD EB098B27 383CEF6F 0E2B811F 3ECFADBA 07CD0AC6 BBB8C5FE
    B2FC0FD8 562B7100 BB28036E 4575D1F5 B17687C6 8EACBD66 A9E52FEE A030E69A
    CAAE9F1B 618FA59D 02C25BC8 77D6CAC2 C7E56F
    quit
    dot11 syslog
    ip cef
    multilink bundle-name authenticated
    voice-card 0
    no dspfarm
    username cisco1 privilege 15 secret 5 $1$L2RA$Zqs6FLce5Ns5fny5aRL49/
    archive
    log config
    hidekeys
    interface GigabitEthernet0/0
    ip address dhcp
    duplex auto
    speed auto
    media-type rj45
    end
    interface Loopback1
    ip address 1.1.1.1 255.255.255.0
    interface GigabitEthernet0/0
    ip address dhcp
    duplex auto
    speed auto
    media-type rj45
    ip local pool svc-poll 1.1.1.50 1.1.1.100
    ip forward-protocol nd
    ip route 0.0.0.0 0.0.0.0 192.168.1.254
    ip http server
    no ip http secure-server
    control-plane
    line con 0
    logging synchronous
    line aux 0
    line vty 0 4
    scheduler allocate 20000 1000
    webvpn gateway SSLVPN
    ip interface GigabitEthernet0/0 port 443
    ssl trustpoint local
    inservice
    webvpn install svc flash:/webvpn/svc.pkg
    webvpn context SSLVPN
    ssl authenticate verify all
    policy group default
       functions svc-required
       svc default-domain "test.org"
       svc keep-client-installed
       svc split dns "primary"
    default-group-policy default
    gateway SSLVPN
    inservice
    end

    Using the SDM follow the below config example
    http://www.cisco.com/en/US/products/ps6496/products_configuration_example09186a008071c58b.shtml
    The text "cisco 3800 ssl vpn configuration" in my favorite search engine, identified the above.
    HTH>

  • Why does my file requiring ActiveX cant run in my Apple computer?

    Why does my file requiring an ActiveX cannot run in my Apple computer?

    Active X is chiefly a Windows > Internet Explorer browser based function and there is no Internet Explorer for OS X.
    The only way you can run this Active X script is install Windows into Apple's BootCamp dual boot partition solution or by running Windows in a virtual machine program in OS X itself.
    Windows in BootCamp or Virtual Machine?
    https://discussions.apple.com/community/notebooks/macbook_pro?view=documents

  • Why does Skype charge my account for minutes that ...

    why does Skype charge my account for minutes that i am not using ?
    Solved!
    Go to Solution.

    Hi sydneysmith1234,
    I can see in your account that you have an active calling subscription. Please note that subscriptions renew automatically, as stated in our Terms of Use. You will be charged for it's renewal depending on the period you selected. Please refer to the private message I sent to you for further details.
    To check your private message, just go to Skype Community home page (community.skype.com), scroll at the bottom of the page. You will see "Private Message" just above "Users Online."
    Due to the time it can take for some transactions to be processed, we charge you three days in advance to ensure prompt delivery of your subscription. You do not lose these three days: your subscription is still valid for the full period that you sign up for.
    Your subscription will renew even if you are not using it. Skype subscription is the same with other subscriptions like cables, telephones, etc., wherein you are automatically charged for their renewal.
    For more information on how subscriptions work, you may refer to this link: https://support.skype.com/en/faq/FA10414/
    If answer was helpful please mark it with Kudos and if issue is resolved mark it with solution. This will help other users find this answer more easily. Thanks in advance!

  • HT1338 Why does my VPN keep dropping out on my new MAC?!?! Could it be anything to do with the MTU settings?

    Why does my VPN keep dropping out on my new MAC?!?! Could it be anything to do with the MTU settings?

    I am having the same exact problem as you described I can't see your Screen Shot.
    Try these methods.. they are supposed to work, but havent for me maybe your luck is different. http://osxdaily.com/2012/11/30/resolving-stubborn-wi-fi-connection-problems-in-m ac-os-x/t
    If i go right next to my router the internet works fine but where I used to get 5 bars I get like none and if im lucky 1. Didnt' have this issue 2 - 3 days ago

  • HT4623 why does my ipad kick me out of FB and sometimes to the 'settings' page or sometimes to the desk top, for what reason?     I have 50.8 GB of capacity available; it is version 5.1.1 and model MC497LL.   it is WIFI and internet via AT&T???  Can you h

    Can anyone help me?  Why does my ipad kick me out of FB?  Sometimes to the 'settings' page and sometimes to the desk top?  I would like to know why this happens and what I can check or change to make it stop.   I have 50.8 GB of capacity available; it is version IOS 5.1.1; model MC497LL.  It is WIFI and internet via AT&T?   Can anyone give me some clues on what to do; or change in settings???  Thank you very much! 

    Please read this whole message before doing anything.
    This procedure is a diagnostic test. It’s unlikely to solve your problem. Don’t be disappointed when you find that nothing has changed after you complete it.
    The purpose of the test is to determine whether the problem is caused by third-party software that loads automatically at startup or login, by a peripheral device, by a font conflict, or by corruption of the file system or of certain system caches.
    Disconnect all wired peripherals except those needed for the test, and remove all aftermarket expansion cards, if applicable. Start up in safe mode and log in to the account with the problem. You must hold down the shift key twice: once when you turn on the computer, and again when you log in.
    Note: If FileVault is enabled, or if a firmware password is set, or if the startup volume is a Fusion Drive or a software RAID, you can’t do this. Ask for further instructions.
    Safe mode is much slower to start up and run than normal, with limited graphics performance, and some things won’t work at all, including sound output and Wi-Fi on certain models. The next normal startup may also be somewhat slow.
    The login screen appears even if you usually login automatically. You must know your login password in order to log in. If you’ve forgotten the password, you will need to reset it before you begin.
    Test while in safe mode. Same problem?
    After testing, restart as usual (not in safe mode) and verify that you still have the problem. Post the results of the test.

  • Why does mac os keep asking for keychain password

    why does mac os keep asking for keychain password

    I'm getting this same problem. It seems random when it asks for the password, maybe every 3 or 4 days it'll ask when I plug it in at night. I've tried restoring from an older backup, which has not resolved the issue.

  • Why does it take more space for pictures to be stored in iPad than iPhone?

    Why does it take more space for pictures to be stored in iPad than iPhone?
    The same pictures in iPhone utilises half the storage space than in the iPad.

    Photos on the ipad should take up little  more space than It does on The iPhone because of the screen resolutions size.
    Keep in mind If the photos are being stored on the device by Photo stream they will Take up less Space or if The photo Are being store by itunes syncing they may take up a little more.
    A previous Discussion talks about This also
    https://discussions.apple.com/message/20031028#20031028
    Does This make Sense or would you like me To explain More?

  • Why does my Premiere Elements 10 for mac freeze?

    Why does my Premiere Elements 10 for mac freeze (makes spinning circle loading) and doesn't stop when I am asked to select my country/region? I already had trouble downloading it originally because there was an error downloading, and then the following image happens (note: the screenshot couldn't capture the spinning circle freeze, but just look at the "application not responding" message below):
    Why does this happen? I downloaded and opened photoshop elements 10 (that came with the bundle) fine, but I can't open this.
    For reference, I am using a mac book pro from 2012 that is 64bit on OS X 10.8.5.
    Edit: Also, for the aforementioned error that I was getting earlier when installing, I would try to install and then half way through it said that the download failed. I had to follow the second method to fix in this link:
    http://helpx.adobe.com/premiere-elements/kb/updated-installation-instructions-premiere-ele ments.html

    1000
    I do not think we are in sync yet, but I will need to sign off soon. It is about 1 am where I am.
    1. Not sure what you mean by 2 warranty licenses that the CD comes ith in the package.
    If you purchased the Premiere Elements 10 Mac in boxed packaging, then you should have an installation disc and a purchased serial number. You cannot lose that. You can install and reinstall the program when you need to do so. There is no limit on uninstalling or reinstalling. The only limit is Adobe allows you to have your purchased serial number on no more than 2 of your computers. We can talk about it some more if necessary but there is a distinction between Deactivate and Uninstall. There has not been a limit on Deactivations in years.
    Another approach if you think your installation files or disc is corrupt is to download tryout files from the following web site and then install from them and insert you purchased serial number at installation.
    http://prodesigntools.com/photoshop-elements-10-direct-download-links-pse-premiere-pre.htm l
    You have to read the Note: Very Important Instructions very carefully otherwise you end up with Access Denied.
    If you think that we are now in sync, then I would suggest
    a. Delete the preference file (settings file)
    or
    b. Deactivate, uninstall, ccleaner run through, reinstall as per your instructions that worked for you.
    I will be watching for further details in the morning. Hopefully some of the Premiere Elements Mac users will join the thread to give the Mac perspective to the situation.
    Thanks.
    ATR

  • I downloaded Adobe Flash 7 times.... why does my system keep asking for it?

    I downloaded Adobe Flash 7 times.... why does my system keep asking for it?

    Read Before Posting: How To Get A Useful Answer To Your Question

  • Why does my iphoto continue to say " photos are being imported to the photo library" every time I try to close? I have not been imported and this has been keeping me from closing for weeks.

    Why does my iphoto continue to say " photos are being imported to the photo library" every time I try to close? I have not been imported and this has been keeping me from closing for weeks.

    What Operating System are you running?
    Mountain Lion there seem to be a glitch that continually ask this on quit. 
    You have  Apple Menu ()>force quit>iPhoto

  • Why does my shutter not open for front facing camera?  and remains black during FaceTime, iphone 5 6.1.3 completely restored to factory

    Why does my shutter not open for front facing camera?  and remains black during FaceTime calling over wifi even to a macbook, iphone, ipad 2, ipod touch and the device i have is iphone 5, 6.1.3 completely restored to factory, 5 times, 4 without restoring from back up, the last one i figured might as well have my content on it if its not going to work anyways.
    Thanks

    Hello, PJCPace. 
    Thank you for visiting Apple Support Communities. 
    Here are some troubleshooting steps that I would try when experiencing this issue. 
    Intel-based Macs: Resetting the System Management Controller (SMC)
    http://support.apple.com/kb/ht3964
    Safari: Unsupported third-party add-ons may cause Safari to unexpectedly quit or have performance issues
    http://support.apple.com/kb/ts3230
    Cheers,
    Jason H. 

Maybe you are looking for