Specifications
About SODA Endpoint Security
20-2 Configuring SODA Endpoint Security for a RoamAbout Switch
• CacheCleaner–EnsuresthatWebbrowserinformation,suchascookies,history,auto‐
completiondata,storedpasswords,andtemporaryfilesareerasedorremovedupon
terminationoftheuser’ssession,inactivitytimeout, orclosing ofthebrowser.
• Connection Control–ControlsnetworkconnectionsbasedonDomain,IPaddress,Port,and
Service.Forexample,ConnectionControlcanpreventaTrojanfromsendingouta
confidentialdocument,downloadedlegitimatelythroughanSSLVPNtunnel,toamalicious
e‐mailserver(SMTP)usingasecondnetworktunnel.
• AdaptivePolicies –Sensethetypeandlocationofdeviceandadjustsaccessbasedon
endpointparameters
suchasIPrange,registrykeys,andDNSsettings
TheSODAendpointsecuritymodulesareconfiguredthroughSygateOn‐DemandManager(SODA
Manager),aWindowsapplication.SODAManagerisusedtocreateaSODAagent,whichisaJava
appletthatisdownloadedbyclientdeviceswhentheyat temptto
gainaccesstothenetwork.Once
downloaded,theSODAagentrunsaseriesofsecuritycheckstoenforceendpointsecurityonthe
clientdevice.
SODA Endpoint Security Support on RoamAbout Switches
RoamAboutSwitchessupportSODAendpointsecurityfunctionalityinthefollowingways:
•SODAagentappletscanbeuploadedtoaRoamAboutSwitch,storedthere,anddownloaded
byclientsattemptingtoconnecttothenetwork.
•TheRoamAboutSwitchcanensurethatclientsruntheSODAagentsecuritychecks
successfullypriortoallowingthemaccess
tothenetwork.
•Differentsetsofsecuritycheckscanbedownloadedandrun,basedontheSSIDbeingusedby
theclient.
•Ifthesecuritychecksfail,theRoamAboutSwitchcandenytheclientaccesstothenetwork,or
granttheclientlimitedaccessbasedonaconfiguredsecurityACL.
•Whenthe
clientclosestheVirtualDesktop,theRoamAboutSwitchcanoptionallydisconnect
theclientfromthenetwork.
How SODA Functionality Works on RoamAbout Switches
ThissectiondescribeshowtheSODAfunctionalityisconfiguredtoworkwithaRoamAbout
Switch,andtheprocedurethattakesplacewhenauserattemptstoconnecttoanSSIDwherethe
SODAfunctionalityisenabled.
Notethatinthecurrentrelease,theSODAfunctionalityworksonlyinconjunctionwiththe
Web
PortalWebAAAfeature.
SODAfunctionalityonaRoamAboutSwitchisconfiguredasfollows:
1. UsingSODAManager,anetworkadministratorcreatesaSODAagentbasedonthesecurity
needsofthenetwork.
2. Thenetworkadministratorexportsthe SODAagentfilesfromSODAManager,andsaves
themasa.zipfile.
3. TheSODAagent
.zipfileisuploadedtotheRoamAboutSwitchusingTFTP.
4. TheSODAagentfilesareinstalledontheRoamAboutSwitchusingaCLIcommandthat
extractsthefilesfromthe.zipfileandplacesthemintoaspecifieddirectory.