Username:  
 
Password:  
    
Forgot Password? Username?   |   Register
register
Banner

Portcullis Systems Unified Access Gateway appliances now with Microsoft Forefront Unified Access Gateway 2010 for secure remote connectivity.


The Portcullis Systems Unified Access Gateway is a flexible, powerful platform that gives mobile workers, partners and customers secure, complete access to almost any application -- without the headaches of creating and maintaining VPN connections.

The Portcullis Systems Unified Access Gateway leverages the full power of Microsoft’s UAG to provide secure access to almost any resource within the enterprise – and allows you to change, limit or forbid access to specific resources based on the location, device or security level of the remote user. Configuration is not only simple, it provides far tighter security and increased flexibility when compared to SSL-VPNs. SSL- VPNs create an encrypted tunnel through your firewall without letting you see what travels through.

The Portcullis Systems Unified Access Gateway monitors traffic on your network, identifies the types of traffic and range of connections, then stops all attempts to penetrate your enterprise except those you have already approved, under conditions you have already set.

High Performance - Tight, Multi-factor Security

For Portcullis Systems, access is not a yes-or-no proposition. The Portcullis Systems UAG appliance lets you offer a conditional ‘yes’ to remote workers who need access but haven’t satisfied all your security requirements.

For example: anti-virus present but not up to date? You can reach network resources One through Five, but not Six. No antivirus at all? You may only get to the Webmail page with no ability to upload files.

The gateway has built-in, deep knowledge of networked applications so it can intelligently analyze traffic and make decisions based on your priorities and almost any characteristic you choose.

Need more security? Add support for two-factor authentication – tokens, smartcards, biometrics and almost any other physical method of confirming a user’s identity – so it takes more than just a password to get into your enterprise.

The high-performing Portcullis Systems appliance – based on Intel’s latest Nehalem architecture and customized Hewlett-Packard high-performance servers -- is hardened for security, streamlined for speed and specifically designed to analyze application traffic without slowing it down.

Application Access - Anywhere, Anytime

The Portcullis Systems Unified Access Gateway (UAG) simplifies remote access and allows you to extend the reach of your organization to mobile workers, partners, clients and customers securely. It allows you to define who should get access to what resources under what circumstances and enforces your policy for each user/device as it attempts to log on to your network.

UAG analyzes each user attempting to access your organization. A deep scan of the endpoint occurs and identifies the location of access, the device type, the state of the device (e.g. antivirus, operating systems, patch level and more) and is combined with the user’s credentials to create a profile of each user at the time of the each attempted access.
This profile is applied against corporate policy that you configure in the gateway to determine what resources should be available based on the user’s current access scenario. This gives you extensive, granular control over what resources are available and under what circumstances.

The gateway can even control access to functionality within an application. For example, if you had a SharePoint portal with important company announcements, sales tools, shared files, and email access, you could limit a remote user with valid credentials, but who does not meet other compliance factors, to view company announcements, view email but restrict upload and download capability, view sales forecasts, and block access to shared files.

By contrast, SSL-VPNs – which have been the best remote-access security option until now – can only provide yes-or-no access approval. Either you shut out workers logging in from public or unmanaged devices, or you open full access to the resource. One option limits productivity, whilethe other increases exposure and risk. The UAG allows for partial access within applications allowing a much finer level of control.

This provides an unmatched level of granular control over access to your critical applications – without completely shutting out remote workers that fail to comply with every security requirement.

UAG Support

World-class 24 x 7 x 365 Global Support

Unique among high-end remote-access gateway providers, Portcullis Systems is able to provide not only around-the- clock support and help desk assistance, but also on-site hardware repair and support available worldwide in as little as four hours.
     

 

 

FAQ's

Q. What is the Portcullis Systems Unified Access Gateway (UAG)?

A. The Portcullis Systems UAG is a ready for deployment Microsoft Unified Access Gateway appliance which delivers comprehensive, secure remote access to corporate resources for employees, partners, and vendors on both managed and unmanaged PCs and mobile devices. Utilizing a combination of connectivity options, ranging from SSL VPN to DirectAccess, as well as built in configurations and policies, the Portcullis UAG provides centralized and easy management of an organization's complete anywhere access offering. Integrating a deep understanding of the applications published, the state of health of the devices being used to gain access, and the user's identity— Portcullis Systems UAG enforces granular access controls and policies to deliver comprehensive remote access, ensure security, reduce management costs and complexity and is delivered on enterprise HP hardware.

 Q. What are the benefits of a Portcullis Systems UAG appliance?

A. At Portcullis Systems, we build upon the great technologies from Microsoft and HP to provide significant additional value for our customers. Our technologies make deployment easy, boost performance of applications and help to centrally manage your array of Portcullis Systems devices wherever they may be located. Portcullis Systems appliances also add significant benefits to UAG deployments with enhanced features like application acceleration through Portcullis Systems Ballista™ and our enterprise auditing software PSAM™.

Q. What support options does Portcullis Systems offer?

A. Portcullis Systems is a world-class provider of Forefront Security appliances and global 24 x 7 support to customers around the world. As a Global OEM partner for HP and Microsoft, we deliver our high-value software solutions on tier-1 hardware platforms to provide reliable, scalable performance with the best support available in the industry. We can provide hardware engineers onsite to your locations around the world in as little as 4 hours for an unmatched level of service.


Q. Are Portcullis Systems appliances FIPs compliant?

A. Our HS-UAG7000F and HS-UAG9000F models conform to FIPS 140-2 Level 2 encryption standards for organizations requiring the highest levels of data encryption. The cryptographic technology is a multi-chip embedded hardware cryptographic module that resides within the gateway appliance. It is contained in its own secure enclosure that provides physical resistance to tampering.


Q. Does the Portcullis Unified Access Gateway include all the features in Intelligent Application Gateway (IAG) and work in the same scenarios as IAG?

A. UAG is built on the proven platform of IAG and extends the capabilities of IAG with new features and functionality. Forefront UAG continues Microsoft's differentiation around application intelligence, endpoint security, granular policy controls, and ease of use. UAG will be deployed in the same scenarios as IAG as well as some expanded scenarios. For DirectAccess scenarios, UAG will further improve deployments by providing access to/from existing infrastructure, simplifying configuration, and enhancing management.


Q. What are the key features of Unified Access Gateway?

 A. Portcullis Unified Access Gateway is designed to build on the secure remote access capabilities in IAG 2007, extending Microsoft's focus on application intelligence, security and control, and ease of use:
• Application Intelligence: Forefront UAG includes broad application support for Microsoft and third-party applications. Key features include granular application filtering, multiple tunnels allowing various levels of client/server and network access, session cleanup and removal, as well as Remote Desktop and RemoteApp integration.
• DirectAccess Enhancement: Forefront UAG extends DirectAccess to legacy applications and platforms and simplifies DirectAccess deployments with wizards and automated policies. Furthermore, it scales DirectAccess through built-in load balancing and array management.
• Endpoint Access Controls: Forefront UAG performs extensive and granular end point health detection, and is integrated with Network Access Protection (NAP) policies.
• Scale and Management: Forefront UAG includes built in load balancing, array management capabilities, as well as enhanced monitoring and management via System Center Operations Manager.


Q. How is DirectAccess different from current VPN solutions?

A. Virtual private networks (VPNs) securely connect remote users to their network. While DirectAccess can also do that, it is only one of the many things that DirectAccess can perform well. Additionally, DirectAccess can ensure that users are connecting to the exact server to which they think they are connecting (end-to-end authentication) and provide data encryption all the way to the server (end-to-end encryption). DirectAccess also allows IT professionals to service remote computers whenever the DirectAccess client has Internet connectivity. Additionally, working together with Network Access Protection (NAP), DirectAccess can ensure that the clients are always compliant with system health requirements to ensure a secure and healthy IT environment.


Q. How does the Portcullis Unified Access Gateway extend DirectAccess?

A. DirectAccess in Windows 7 and Windows Server 2008 R2 enhances the productivity of mobile workers by connecting them seamlessly and more securely to their corporate network any time they have Internet access—without the need to establish a VPN session. DirectAccess enables corporate network file shares, intranet Web sites, and line-of-business applications so they can remain accessible wherever you have an Internet connection. DirectAccess requires Windows 7 Enterprise Edition or Windows 7 Ultimate Edition computers and a Windows Server 2008 R2 DirectAccess Server at the edge of your network. Unified Access Gateway 2010 (UAG) extends the benefits of DirectAccess across your infrastructure, enhancing scalability and simplifying deployments and ongoing management.
UAG takes DirectAccess deployments to a new level as it helps:
• Extend access to line of business servers with IPv4 support such as Windows 2003 and non-Windows servers.
• Provide SSL VPN access for down level (Windows 7 standard & home/Vista/XP) and non-Windows clients as well as PDAs.
• Enhance scale and management through array management capabilities and integrated load balancing.
• Simplify deployments and ongoing administration using wizards and automated tools.
• Deliver a hardened, edge-ready, solution that can swiftly be deployed.


Q. What are minimum operating system requirements for DirectAccess?

A. DirectAccess clients must run Windows 7 Enterprise Edition or Windows 7 Ultimate Edition, and must connect to a Windows Server 2008 R2 DirectAccess server. The client machines must also be joined to an Active Directory Domain Services (AD DS) domain.


Q. What gets installed on the client to enable DirectAccess?

A. DirectAccess does not require any client-side installation. DirectAccess clients use Active Directory domain membership and Group Policy settings for their configuration and leverage software already built in to the Windows 7 Enterprise or Ultimate operating systems. Group Policy settings are applied while connected to the local area network (LAN) or through a DirectAccess connection. There is no user interface on the DirectAccess client. When DirectAccess is operating effectively, it is transparent to the end user.

Q. How is Forefront Unified Access Gateway different from the Forefront Threat Management Gateway (TMG)? Why should I use UAG for application publishing rather than TMG?

A. Forefront Threat Management Gateway is a comprehensive, secure Web gateway that helps protect employees from Web-based threats. It provides multiple layers of continuously updated protections, including URL filtering, antimalware inspection, and intrusion prevention. These technologies are integrated with core network protection features, to create a unified, easy-to-manage gateway that reduces the cost and complexity of Web security. Forefront UAG, on the other hand, delivers secure, anywhere access to messaging, collaboration, and other resources, increasing productivity while maintaining compliance with policy. Integrating a deep understanding of the applications published, the state of health of the devices being used to gain access, and the user's identity—UAG enforces granular access controls and policies to deliver comprehensive remote access, ensure security, and reduce management costs and complexity.



 

Direct Access and Unified Access Gateway

 

DirectAccess provides direct connectivity for remote managed devices into your corporate network without the need for archaic and expensive-to-manage VPNs. It provides “Always On” functionality for the end-user regardless of their location and gives access as if the user was locally attached to the corporate network. Combined with NAP (Network Access Protection), it gives organizations the ability to control remote devices even before the user attempts to sign on to the network. Portcullis Systems Unified Access Gateway provides critical tools required to implement DirectAccess.


 The Portcullis Systems Unified Access Gateway extends the capability of DirectAccess to a greater array of endpoint devices. While DirectAccess supports Windows 7 Enterprise clients connecting to Windows Server 2008 R2-base resources over an IPv6 network, UAG combines with Direct Access to extend access to all end-user devices, managed and unmanaged, both Windows and non-Windows, and connects those to any of your internal information resources.

The Gateway integrates DNS6to4 and NAT6to4 technology to allow access in mixed-mode environment running both IPv4 and IPv6. This provides a simple, easy way to begin incorporating DirectAccess functionality while simultaneously providing an enhanced experience to the rest of your user base. This allows your organization to make a planned migration toward the newest technology at your own pace. The power and simplicity of the Gateway allows for the successful deployment of DirectAccess in today's environments.

 

 

Portcullis Systems UAG & DirectAccess Server - Better Together


DirectAccess and uag

 

Portcullis Systems Appliance Management suite (PSAM)

 

Rich, Complete Remote Management

Portcullis Systems builds on iLO with the Portcullis Systems Appliance Management suite (PSAM) -- a rich set of monitoring and management capabilities that provide more detail and control than any other Gateway on the market.

Alerts

PSAM uses the instrumentation built into the hardware to monitor temperatures, performance and other factors so that when the unit exceeds thresholds, it will alert both you and Portcullis Systems. Alerts about operating temperature, hard disk performance, disk capacity and other developing problems are sent via Syslog, SNMP and email. Alerts flow at your discretion on anything from total system or power failures, to the failure of a particular service or connection, to an increase in temperature.

Patch Management

As threats and countermeasures proliferate, keeping patches up to date for operating systems, applications, firmware and networking software has become a major headache. Portcullis Systems appliances come with a patch management system that not only frees you from patching the appliances, they can reach out and patch other systems as well.
The Portcullis Systems patch system monitors the patch status of both Microsoft software and non-Microsoft products, and routinely checks for new patches it can apply or install. The system also supplies detailed reports and executive summaries on current patch status and update histories.

Reports and Updates

PSAM provides a robust reporting capability and pre-defined reports that help keep you up to date on the status of the gateway protecting your enterprise – including, real-time snapshots of their current status, summaries of recent activity, or historical data that can highlight trends or be used for financial or security audits.
• A Patch Management Report shows all suggested updates and those that have been installed;
• A Network Status Report displays network volumes and usage for all Portcullis Systems appliances.
• A Machine Change Report tracks software versions and identifies changes, which are often required for financial or
security audits.
• An Executive Summary Report displays an easily digestible summary of performance data, alerts, patch status, disk space usage and overall health of your appliances.

Remote Support and Backup

PSAM features a remote-access capability that puts a virtual engineer on your site to help address issues without waiting for a human to arrive. Remote-support sessions allow our engineers to troubleshoot appliances in real time to minimize downtime, bottlenecks and other issues.
We also provide robust Backup and Restore capabilities that include the ability to schedule backups, run them on demand, and store a defined number of backups where you choose. Periodic backups to files or folders shared on the network, for example, get you up and running promptly if there is ever an event that requires you to restore a machine image from one stored on disk. Full appliance backups and differential backups can run independently of other configuration or backup options, without impacting either the performance of the Gateway or requiring you to get involved.

 

.
 
Copyright © 2010. Portcullis Systems, Inc.