Security

last person joined: 6 days ago 

Ask questions and share experiences with Juniper Connected Security. Discuss Advanced Threat Protection, SecIntel, Secure Analytics, Secure Connect, Security Director, and all things related to Juniper security technologies.
  • 1.  MAG series differences and HA features

    Posted 09-04-2011 20:11

    Are there any performance or drastic feature differences between the MAG SSL VPN products other than NAC?

     

    I'm currently looking into deploying an SSL VPN solution for 50 SSL users for basic virus-scanner remediation across windows and mac pc's in addition mobile devices access, i.e ipads.

     

    In addition to the 50 SSL licenses, will i have to also buy another 50 for mobile device users?

     

    I know the MAG's are HA capable, however if i buy two, will I have to also buy 50 licenses for the second unit or will the licenses from the first unit transfer to the secondary unit?

     

    Thanks in advance.



  • 2.  RE: MAG series differences and HA features
    Best Answer

    Posted 09-06-2011 08:45

    From an SSL point of view the MAG and the SA boxes are pretty much the same. There are some older features that ran on the SA platform that are not continued on the MAG platform but for a new customer that should not matter and they run the same code.

     

    You license the total number of concurrent users, regardless of the end user platform - IE PC or I@ or Android. You mentioned AV - there is no facility in the SSL code to handle AV on mobile devices. If you want to do that you would need to look into the Mobile Security Suite to add those features - they are supported on a device by device basis - IE there is not AV for IOS at this point in time.

     

    NOTE - this is NOT Pulse. Pulse is free and is the replacement for Network Connect (long term).

     

    As for box licensing. Somebody could write a book on that one 🙂

     

    If you want all the in-depth details I would recommend going to www.kevpeterson.com - he is the Product Manager and has a wealth of details on licensing. But the short answer is:

     

    You would buy licenses for each box. Say 25 each. You would then have a total of 50 "usable" licenses (sum of the 25x2) - if a box fails you would still have 50 licenses for a preset time period (5 days) during which you need to replace the broken box. NOW - it does get funky if you were to buy 10 licenses for box "A" and 50 for box "B" - if box "B" failed you would only have 20 licenses.

     

    Again, this is just a summary - due to all the ways these guys can be deployed licensing can be very complex.

     

    Hope this answers some of your questions - Also - SSL stuff is best posted in the SSL Forum.