Release Notes. NCP Secure Enterprise Mac Client. 1. New Features and Enhancements. 2. Improvements / Problems Resolved. 3.

Similar documents
Release Notes. NCP Secure Enterprise Mac Client. 1. New Features and Enhancements. 2. Improvements / Problems Resolved. 3.

This version of the des Secure Enterprise MAC Client can be used on Mac OS X 10.7 Lion platform.

Data Sheet. NCP Secure Enterprise macos Client. Next Generation Network Access Technology

Data Sheet. NCP Exclusive Remote Access Mac Client. Next Generation Network Access Technology

Data Sheet. NCP Secure Entry Mac Client. Next Generation Network Access Technology

NCP Secure Enterprise macos Client Release Notes

Data Sheet. NCP Secure Enterprise Linux Client. Next Generation Network Access Technology

NCP Secure Entry macos Client Release Notes

NCP Secure Client Juniper Edition (Win32/64) Release Notes

NCP Secure Client Juniper Edition Release Notes

NCP Secure Enterprise macos Client Release Notes

Release Notes. NCP Android Secure Managed Client. 1. New Features and Enhancements. 2. Improvements / Problems Resolved. 3.

Data Sheet NCP Exclusive Remote Access Client Windows

In the event of re-installation, the client software will be installed as a test version (max 10 days) until the required license key is entered.

Data Sheet. NCP Exclusive Entry Client. Next Generation Network Access Technology

Data Sheet. NCP Secure Enterprise Client Windows. Next Generation Network Access Technology

Data Sheet. NCP Secure Entry Client Windows. Next Generation Network Access Technology. Universal VPN Client Suite for Windows 32/64 bit

NCP Secure Managed Android Client Release Notes

NCP Secure Entry Client Release Notes

NCP Secure Entry Client Release Notes

NCP Secure Entry Client (Win32/64) Release Notes

Release Notes. NCP Secure Enterprise Client (Win32/64) 1. New Features and Enhancements. 2. Changes Made and Problems Resolved

Release Notes. NCP Secure Client Juniper Edition. 1. New Features and Enhancements. Major Release: build Date: July 2015

Release Notes. NCP Secure Enterprise Client (Win32/64) 1. New Features and Enhancements. Service Release 9.30 Build 162 Date: May 2012

NCP Secure Entry Client (Win32/64) Release Notes

Teldat Secure IPSec Client - for professional application Teldat IPSec Client

Release Notes. NCP Secure Enterprise VPN Server. 1. New Features and Enhancements. 2. Improvements / Problems Resolved

Data Sheet. NCP Secure Enterprise VPN Server. Next Generation Network Access Technology

Configuration of an IPSec VPN Server on RV130 and RV130W

NCP Secure Enterprise Client (Win32/64) Release Notes

NCP Secure Enterprise Client (Win32/64) Release Notes

Release Notes. NCP Secure Entry Client (Win32/64) 1. New Features and Enhancements. 2. Improvements / Problems Resolved. 3.

OCSP When the OCSP responder was not available, clients not establish connections, although in case of error was configured.

Release Notes. NCP Secure Enterprise Client (Win32/64) 1. New Features and Enhancements. Service Release: 9.31 Build 116 Date: February 2013

Release Notes. NCP Secure Enterprise VPN Server. 1. New Features and Enhancements. 2. Improvements / Problems Resolved. 3.

Windows 10 Update 1511 (Threshold 2/Build 10586) causes problems with installed NCP Secure Client

Windows 8.1 Adaptation The Secure Enterprise Client is supported on the Microsoft Windows 8.1 operating system.

CVE / "POODLE"

Release Notes. NCP Secure Enterprise Client (Win32/64) 1. New Features and Enhancements. Service Release: 9.32 Build 142 Date: October 2013

Release Notes. NCP Secure Entry Client (Win32/64) 1. New Features and Enhancements in this Service Release

Table of Contents 1 IKE 1-1

Release Notes. NCP Secure Entry Client (Win32/64) 1. New Features and Enhancements. Service Release: 9.32 Build 160 Date: November 2013

Release Notes. NCP Secure Enterprise VPN Server. 1. New Features and Enhancements. 2. Improvements / Problems Resolved. 3.

Release Notes. NCP Secure Enterprise VPN Server. 1. New Features and Enhancements. 2. Improvements / Problems Resolved. 3.

Virtual Private Networks

Release Notes. NCP Secure Enterprise Client (Win32/64) 1. New Features and Enhancements. 2. Improvements / Problems Resolved. 3.

Configuration of Shrew VPN Client on RV042, RV042G and RV082 VPN Routers through Windows

The EN-4000 in Virtual Private Networks

Release Notes. NCP Secure Enterprise VPN Server. 1. New Features and Enhancements. 2. Improvements / Problems Resolved. 3.

Set Up a Remote Access Tunnel (Client to Gateway) for VPN Clients on RV016, RV042, RV042G and RV082 VPN Routers

Use Shrew Soft VPN Client to Connect with IPSec VPN Server on RV130 and RV130W

Release Notes. NCP Secure Enterprise Client (Win32/64) Service Release: r29675 Date: May 2016

Astaro Security Linux v5 & NCP Secure Entry Client A quick configuration guide to setting up NCP's Secure Entry Client and Astaro Security Linux v5

Release Notes. NCP Secure Enterprise Client (Win32/64) 1. New Features and Enhancements. Service Release: Revision Date: January 2016

Data Sheet NCP Secure Enterprise Management

FAQ about Communication

CONTENTS. vii. Chapter 1 TCP/IP Overview 1. Chapter 2 Symmetric-Key Cryptography 33. Acknowledgements

ZyWALL 70. Internet Security Appliance. Quick Start Guide Version 3.62 December 2003

VPN Ports and LAN-to-LAN Tunnels

NCP Secure Enterprise Management for Windows Release Notes

Sample excerpt. Virtual Private Networks. Contents

How to Configure a Site-to-Site IPsec IKEv1 VPN Tunnel

VPN Configuration Guide. NETGEAR FVS318v3

VPNC Scenario for IPsec Interoperability

QuickStart. NCP Secure Enterprise Server. Configuration Guide

Configuring VPN from Proventia M Series Appliance to NetScreen Systems

Integration Guide. Oracle Bare Metal BOVPN

D-Link VPN Client. Manual

Junos Security. Chapter 8: IPsec VPNs Juniper Networks, Inc. All rights reserved. Worldwide Education Services

VPN Configuration Guide. NETGEAR FVG318 / FVS318G / FVS336G / FVS338 / DGFV338 FVX538 / SRXN3205 / SRX5308 / ProSecure UTM Series

Configuring VPNs in the EN-1000

Apple Inc. Apple IOS 11 VPN Client on iphone and ipad Guidance Documentation

Configuring a Hub & Spoke VPN in AOS

Configuration Guide. How to connect to an IPSec VPN using an iphone in ios. Overview

How to Configure a Site-to-Site IPsec IKEv1 VPN Tunnel

Hillstone IPSec VPN Solution

Index. Numerics 3DES (triple data encryption standard), 21

SonicWALL Addendum. A Supplement to the SonicWALL Internet Security Appliance User's Guide

Service Managed Gateway TM. Configuring IPSec VPN

NCP Exclusive Remote Access Management

Windows 10 Update 1511 (Threshold 2/Build 10586) causes problems with installed NCP Secure Client

Chapter 5 Virtual Private Networking

How to Configure Forcepoint NGFW Route-Based VPN to AWS with BGP TECHNICAL DOCUMENT

Internet Key Exchange

How to Configure an IPsec VPN to an AWS VPN Gateway with BGP

NCP Secure Enterprise Management for Linux Release Notes

Configuring VPN from Proventia M Series Appliance to Proventia M Series Appliance

Digi Application Guide Configure VPN Tunnel with Certificates on Digi Connect WAN 3G

NCP Secure Enterprise Management (Win) Release Notes

VPN Option Guide for Site-to-Site VPNs

Secure Entry CE Client & Watchguard Firebox 700 A quick configuration guide to setting up the NCP Secure Entry CE Client in a simple VPN scenario

Configuring VPN from Proventia M Series Appliance to Symantec 5310 Systems

Crypto Templates. Crypto Template Parameters

How to Configure an IKEv1 IPsec VPN to an AWS VPN Gateway with BGP

A. Verify that the IKE gateway proposals on the initiator and responder are the same.

BCRAN. Section 9. Cable and DSL Technologies

Virtual Tunnel Interface

IPSec VPN Setup with IKE Preshared Key and Manual Key on WRVS4400N Router

Chapter 6 Virtual Private Networking

Secure Access Configuration Guide For Wireless Clients

Transcription:

NCP Secure Enterprise Mac Client Service Release 2.05 Build 14711 Date: December 2013 Prerequisites Apple OS X Operating System: The following Apple OS X operating system versions are supported with this release: OS X 10.9 Mavericks OS X 10.8 Mountain Lion 1. New Features and Enhancements OS X 10.8 and 10.9 Support This release is ONLY supported on OS X 10.8 and 10.9. Support for the OS X Keychain as Certificate Store for Hardware and User Certificates The computer is authenticated with the VPN gateway by means of a Hardware Certificate. When used in addition to a User Certificate, this ensures that the user must always connect from the same computer. The certificate can be imported, together with the Private Key, from the "System" keychain using keychain management. If imported this way it can be used for authenticating the Client. Access to the certificate must be enabled for the ncprwsmac service located in /Library/Application Support/NCP/Secure Client/ When the Client software is updated, every Hardware Certificate already imported and bound to the Client must be confirmed by entering the root-user-id and root-password. A VPN connection using a profile with a Hardware Certificate will only be correctly established when using the latest bindings in the keychain. 2. Improvements / Problems Resolved No disconnect when smartcard is removed Problems with this feature in earlier releases have been resolved. Compatibility and Reliability Improvements 3. Known Issues None page 1 of 7

Service Release 2.02 Build 14 Date: October 2011 Prerequisites Apple OS X Operating System: The following Apple OS X operating system versions are supported with this release: OS X 10.7 OS X 10.6 OS X 10.5 1. Changes in Version 2.02 Build 14 DNS Domains to be resolved in the Tunnel Regardless of whether or not Split Tunneling is in use, which DNS queries must be routed through the tunnel can be defined in the configuration field IPsec Address Allocation ; enter the DNS name required under DNS Domains to be resolved in the Tunnel. In a newly created VPN profile the default entry in DNS Domains to be resolved in the Tunnel is blank, i.e. the default is that all DNS queries are routed outside the tunnel to the DNS server that has been allocated in the Internet (by the provider). 2. Problems Resolved Selection of a defined VPN Connection Under certain circumstances a VPN Profile could not be selected from the profile selection in the Client Monitor. This problem has been resolved. Communication between Central Site and Client when using XAUTH When Extended Authentication (XAUTH) was being used, the communication between the central site and the Client would fail meaning that the dialogue with the central site for requesting a new password was not correctly displayed (e.g. when using external authentication). This problem has been resolved. 3. Known Issues None page 2 of 7

4. Getting Help for the NCP Secure Enterprise MAC Client To ensure that you always have the latest information about NCP s products, always check the NCP website at: http://www.ncp-e.com/en/downloads.html For further assistance with the NCP Secure Enterprise MAC Client, visit: http://www.ncp-e.com/en/company/contact.html Mail: helpdesk@ncp-e.com page 3 of 7

5. Features Operating System Requirements See Prerequisites on page 1. Note: NCP has not withdrawn support for earlier releases of the NCP Secure Enterprise Mac Client that are supported on Apple OS X 10.7 and earlier. Central Management As the Single Point of Management, NCP s Secure Enterprise Management (SEM version 2.05 or higher) provides functionality and automation for the rollout, commissioning and efficient use of Secure Enterprise Clients. Using the VPN connection or the LAN (when on the company network), the Secure Enterprise Management (SEM version 2.05 or higher) provides Enterprise Clients automatically with: configuration updates, certificate updates, and updates to the Update Client. Network Access Control The policies for Endpoint Security (Endpoint Policy Enforcement) are created centrally at the Secure Enterprise Management (SEM) and each Enterprise Client is permitted access to the company network according to the corresponding rules. High Availability Services The NCP Secure Enterprise Client supports the NCP HA Services. These services are client server based and can be used in two different operating modes: load balancing or failsafe mode. Regardless of the load on the server or whether a server has failed, the VPN connection to the company network is established reliably, in the background and without any delay for the user of the Enterprise Client. Security Features The NCP Secure Enterprise MAC Client supports the Internet Society s Security Architecture for the Internet Protocol (IPsec) and all the associated RFCs. Virtual Private Networking RFC conformant IPsec (Layer 3 Tunneling) IPsec Tunnel Mode IPsec proposals are negotiated via the IPsec gateway (IKE Phase 1, IPsec Phase 2) Communication only in the tunnel Message Transfer Unit (MTU) size fragmentation and reassembly Network Address Translation-Traversal (NAT-T) Dead Peer Detection (DPD) Dynamic Host Control Protocol (DHCP) page 4 of 7

Authentication Internet Key Exchange (IKE): Aggressive Mode and Main Mode, Quick Mode Perfect Forward Secrecy (PFS) IKE Config. Mode for dynamic allocation of virtual IP address from address pool Pre-shared secrets or RSA Signatures (with associated Public Key Infrastructure) User authentication: XAUTH for extended user authentication One-time passwords and challenge response systems Access details from certificate (prerequisite PKI) Support for certificates in a PKI: Multi Certificate Configurations for PKCS#11 and PKCS#12 interfaces Seamless rekeying (PFS) IEEE 802.1x: Extensible Authentication Protocol Message Digest 5 (EAP-MD5): Extended authentication relative to switches and access points (layer 2) Extensible Authentication Protocol Transport Layer Security (EAP-TLS): - relative to switches and access points on the basis of certificates (layer 2) RSA SecurID ready Encryption and Encryption Algorithms Symmetrical: AES 128,192,256 bits; Blowfish 128 / 448 bits; Triple-DES 112 / 168 bits Asymmetrical: RSA to 2048 bits, dynamic processes for key exchange Hash / Message Authentication Algorithms SHA-1, SHA-256, SHA-384, SHA-512, MD5 Diffie Hellman groups 1, 2, 5, 14 used for asymmetric key exchange and PFS Public Key Infrastructure (PKI) - Strong Authentication X.509 v.3 Standard Support for certificates in a PKI via the following interfaces: PKCS#11 interface for 3 rd party authentification solutions (Tokens / Smartcards) PKCS#12 interface for private keys (soft certificates) PIN policy: administrative specification of PIN entry to any level of complexity Revocation: End-entity Public-key Certificate Revocation List (EPRL formerly CRL) Certification Authority Revocation List, (CARL formerly ARL) Online Certificate Status Protocol (OCSP) Certificate Management Protocol (CMP)* Personal Firewall Stateful Packet Inspection IP-NAT (Network Address Translation) page 5 of 7

Friendly Net Detection (Firewall rules adapted automatically if connected network recognized based on its IP subnet address, the DHCP server s MAC address or an NCP FND server*) Supports secure hotspot logon feature Differentiated filter rules relative to: Protocols, ports or IP addresses LAN adapter protection Networking Features Secure Network Interface Interface Filter NCP Interface Filter interfaces to all standard Network Interfaces from the PPP and Ethernet families. Wireless Local Area Network (WLAN) support Wireless Wide Area Network (WWAN) support Network Protocol IP Communications Media LAN Communications media supported using Apple or 3 rd party media interfaces and management tools: LAN / Ethernet Wi-Fi GPRS / 3G and GSM ISDN Modem iphone tethering via USB or Bluetooth Line Management Dead Peer Detection with configurable time interval Short Hold Mode Inactivity Timeout (send, receive or bi-directional) Split Tunneling When using Split-Tunneling, those domains whose DNS packets are to be routed via the VPN Tunnel can be specified exactly VPN Path Finder NCP VPN Path Finder Technology Fallback to HTTPS (port 443) from IPsec if neither port 500 nor UDP encapsulation are available** Data Compression IPsec Compression: LZS, deflate page 6 of 7

Standards Conformance Internet Society RFCs and Drafts Security Architecture for the Internet Protocol and assoc. RFCs (RFC2401-2409), Internet Key Exchange Protocol (includes IKMP/Oakley) (RFC 2406), Negotiation of NAT-Traversal in the IKE (RFC 3947), UDP encapsulation of IPsec Packets (RFC 3948), Encapsulating Security Payloads (ESP), IKE Ext. Authentication (XAUTH), IKE configure (IKECFG) and Dead Peer Detection (DPD) FIPS Inside The Secure Client incorporates cryptographic algorithms conformant to the FIPS standard. The embedded cryptographic module incorporating these algorithms has been validated as conformant to FIPS 140-2 (certificate #1051). FIPS conformance will always be maintained when any of the following algorithms are used for establishment and encryption of the IPsec connection: Diffie Hellman Group: Group 2 or higher (DH starting from a length of 1024 Bit) Hash Algorithms: SHA1, SHA 256, SHA 384, or SHA 512 Bit Encryption Algorithms: AES with 128, 192 or 256 Bit or Triple DES Client Monitor Intuitive Graphical User Interface Bilingual (English, German): Monitor & Setup, Online Help and License Icon indicates connection status Configuration, connection statistics, Log-book (color coded, easy copy&paste function) Password protected configuration and profile management Trace tool for error diagnosis Options for starting the Monitor automatically after system reboot: either maximized; or as an icon in the menubar * If you wish to download NCP's FND server as an add-on, please click here: http://www.ncp-e.com/en/downloads/software.html ** Prerequisite: NCP Secure Enterprise Server V 8.0 and later page 7 of 7