|
Improved traffic shaping and bandwidth management, a professional web filter and integration of OpenVPN are the highlights of the new release. Additionally, an integrated user management on the basis of LDAP has been developed and so the configuration of many services has been simplified. The new release of Gibraltar is available since September 10, 2007. After developing and testing longer than a year we were able to make Gibraltar more reliable than ever and we integrated many new features. Apart from many small innovations the highlights of the new version are:
- Dynamic web filter powered by PureSight
- OpenVPN for an easy configuration of client VPN connections
- Clientless SSL VPN on the basis of SSL-ExplorerTM
- User management on the basis of LDAP or Active Directory
- Captive portal with form based authentication
Dynamic web filter powered by PureSight
The dynamic web filter of PureSight analyses and categorizes web pages both dynamically and on the basis of user-defined and server-based lists. For the administrator it is possible to block selectively defined categories of web pages for everyone or for several user groups. This feature is especially appreciable for schools and public institutions, but it also can be used to block web mailers. Using Web mailers is a big security risk in every company, because users are able to bypass internal email server and security checks. The PureSight web filter is an optional feature in Gibraltar and will be offered in two different versions:
- Web filter Basic Edition: Several categories can be blocked.
- Web filter Enterprise Edition: Several categories can be blocked, the access to the web can be limited for several user groups and traffic can be logged and analyzed in detail.
OpenVPN
OpenVPN is a comfortable and secure modification to build client-to-site VPN connections and it expands the already existing VPN alternatives L2TP, PPTP and IPSec. The main advantage of OpenVPN is the very easy configuration and administration of it. In combination with the integrated user management of Gibraltar it is possible for the administrator to define remote access for selected users with very less effort. The authentication is based on digital certificates which can be revoked anytime. Connections are established using free of charge client software which works reliably with every kind of internet connection. Data will be encrypted with SSL.
Clientless SSL VPN
Gibraltar SSL VPN is based on the product SSL-ExplorerTM. This feature allows remote users browser based access to resources on the internal network; without using a VPN client. The following resources and services can be accessed with SSL VPN:
- Virtual network computing (VNC)
- Remote desktop protocol (RDP)
- PuTTY and WinSCP
- File access to network shares
Browser based means that the access to the mentioned services is done with a web browser and java plug-ins. The installation of a VPN client or other software isn’t necessary. After successful authentication the user has access to all resources configured by the administrator. Using SSL VPN, remote users are able to access the selected resources from each internet computer. The only preconditions are a web browser and internet access.
User management
Gibraltar 2.5 offers an integrated user management based on LDAP or Active Directory. This user management is used by the following services:
- VPN: PPTP, L2TP, OpenVPN
- Mail: SMTP authentication
- Web: Proxy authentication
- Captive portal
Each user can be activated or de-activated for one or more services. The integration of Active Directory allows authentication via global security groups. So the administrator is able to define a group which is allowed to access the web for example.
Captive portal
The captive portal of Gibraltar redirects users to a built-in login form at their first network request. After successful authentication, the user will get full access to the network. The captive portal can be deployed for protecting WLAN hotspots. Users have to log in at their first access to WLAN and then they get the authorization to access the internet for a period of the time. In addition it is possible to log and analyse the network traffic with the captive portal.
SSL-Explorer is a trademark or registered trademark of 3SP Ltd in the United States and other countries.
|