
Secure Remote Access Technical Solution Guide v1.0
______________________________________________________________________________________________________
19
Figure 3: Active/active HA solution
See the VPN Gateway BBI Application Guide or CLI Application Guide for configuration
information about DNS round robin integration, clustering, and Nortel Application Switch
integration.
Design recommendation: For remote access environments with large numbers of users, high
traffic volumes, or those that support critical applications, employ an active/active topology,
including VPN Gateway clustering and dual Application Switches. When designing highly resilient
VPN solutions, the network infrastructure, including DNS and AAA services, must also be
designed using high-availability architectures.
4.2.2 Application access
4.2.2.1 Clientless Mode
When possible, use Clientless Mode for providing application access. Clientless Mode is simple
and provides a high degree of access control, down to the individual file-share directory and web
URL path level. Clientless Mode can also provide application-level auditing and logging of every
object requested, if such detail is needed.
Clientless Mode requires web-based applications (examples include Microsoft Outlook Web
Access and Lotus iNotes). Many enterprise-class applications have web front ends or interface
options.
Another benefit of Clientless Mode is that it supports a wide range of client platforms and has
minimal dependencies, as no additional ActiveX or Java applets are required.
Komentarze do niniejszej Instrukcji