Pulse Connect Secure
The best mobile VPN to enable secure access from any device to enterprise apps and services in the data center or cloud
Our Price: $2,495.00
Our Price: $4,945.00
Our Price: $8,795.00
Click here to jump to more pricing!
Overview:
Enterprises and service providers have the difficult challenge of providing location- and device-independent network connectivity that is secure and capable of controlling resource access for authorized users. Breaches and threats continue to spiral out of control, and increasing numbers of employees and users want to use their own personal productivity solutions from devices to cloud based applications. Making this challenge even more difficult. Pulse Secure Connect Secure provides secure, authenticated access for remote and mobile users from any web-enabled device to corporate resources—anytime, anywhere.
Pulse Connect Secure is the most widely deployed SSL VPN for organizations of any size, across every major industry. Pulse Connect Secure includes Pulse Secure Clients and the AppConnect SDK. Pulse Clients are dynamic, multiservice network client for mobile and personal computing devices. Pulse Clients are simply deployed, enabling users to quickly “click and connect” from any device, anywhere. Pulse Secure AppConnect SDK delivers per application SSL VPN connectivity for iOS and Android clients, enabling IT to create an even more transparent and secure mobile app experience for their users.
Secure Access starts with an awesome mobile VPN
Pulse Connect Secure is 15 years of innovation and refinement which has led to the most reliable and feature rich VPN built for the next generation.
- Market Leader
40 of the Fortune 50 companies and over 18 million endpoints secured. - Data Center and Cloud
Simply blend data center applications and public cloud services for your workers. - Easy Compliance
Granular control over who is accessing what, from where, when, and how. - Familiar Experience
No matter what the device your user chooses, they'll get the same experience they love. - Mobile VPN
Per-app VPN for Secure Access from iOS and Android. - Single Sign-On
Remembering passwords is a thing of the past for both on premises systems or cloud based solutions. - Transparent Visibility
Beautifully designed and easy to use consoles that IT will love. - Variety of Deployment Options
Purpose built secure access appliances or virtual machine option.
Pulse Secure Clients
Pulse Clients securely connect users to networks, both datacenter and cloud. Wrapped in an extremely user-friendly package, Pulse Client dynamically enables the appropriate network and security services on users’ endpoints. Users are not distracted from their work activities to figure out what network they are on or what service to enable. With Pulse Secure, the connection just works, helping to deliver the productivity promised by mobile devices. Pulse Client delivers dynamic access control, seamlessly switching between remote (SSL VPN) and local (NAC) access control services on Microsoft Windows devices. Pulse Client also enables comprehensive endpoint assessment for mobile and desktop computing devices, and quarantine and remediation, if necessary.
The digital world continues to create workforce productivity beyond BYOD. More enterprises are combining apps and data that were traditionally delivered privately on premises with a variety of 3rd party, cloud hosted service offerings, whether it be cloud based storage, SaaS applications or IaaS platforms. This evolution of combining and managing private and public IT architectural worlds is Hybrid IT. Learn how to embrace Hybrid IT with Pulse Cloud Secure and have the capabilities to blend cloud and datacenter access into a seamless user experience for your next generation workforce.
Architecture and Key Components:
Pulse Connect Secure is available on a hardware-based (Pulse PSA or MAG Series) or as a virtual appliance as noted below.
- PSA300 Pulse Secure Appliance: Fixed configuration, compact appliance ideal for small and mid-size businesses, supporting up to 200 SSL VPN concurrent users. PSA300 is ideal for desktop deployments.
- PSA3000 Pulse Secure Appliance: Fixed configuration, rack-mount appliance ideal for small and mid-size businesses, supporting up to 200 SSL VPN concurrent users.
- PSA5000 Pulse Secure Appliance: Fixed configuration appliance ideal for scalable mid-size businesses, supporting up to 2,500 SSL VPN concurrent users.
- PSA7000 Pulse Secure Appliance: Fixed configuration appliance ideal for meeting the highest scalability needs of large businesses, supporting up to 25,000 SSL VPN concurrent users.
- MAG2600 Pulse Secure Appliance: Fixed configuration, compact appliance ideal for small and mid-size businesses, supporting up to 100 SSL VPN concurrent users.
- MAG4610 Pulse Secure Appliance: Fixed configuration appliance ideal for mid-size and large businesses, supporting up to 1,000 SSL VPN concurrent users.
- MAG6610 Pulse Secure Appliance: Chassis-based appliance ideal for scalable large businesses, supporting up to 20,000 SSL VPN concurrent users; it requires at least one service module (maximum of two) to be ordered and installed (MAG-SM160 or MAG-SM360).
- MAG6611 Pulse Secure Appliance: Chassis-based appliance ideal for meeting the highest scalability needs of large businesses, supporting up to 40,000 SSL VPN concurrent users; it requires at least one service module (maximum of four) to be ordered and installed (MAG-SM160 or MAG-SM360).
- Virtual Appliance: VMWare, KVM, and Hyper-V virtual appliances for scalable elastic deployment of SSL VPN services.
*Total number of licenses cannot exceed the maximum supported per PSA Series Appliance.
Tech Info:
Clientless Access
Access web base apps and virtual desktop products with nothing to install.
Group Policy
Integrate with directory services like Active Directory and LDAP.
Strong Authentication
Support for two factor authentication, SAML 2.0, PKI, IAM and digital certificates.
Host Checker
Ensure that the connecting device complies with your requirements.
Virtual Desktop Access
Uncomplicated Secure Access to all the VDI leader's solutions.
Granular Auditing
The when, where, what and how for security as well as capacity planning.
MDM Integration
Integration with 3rd party solutions to enable enhanced policy enforcement.
Universal Client
We reduce complexity with only one client, both remote or onsite, for smooth roaming.
That's just the beginning, take a look at features and benefits tab for more information.
Features and Benefits:
Key Features of Pulse Connect Secure
Feature | Feature Description |
---|---|
Layer 3 SSL VPN | Dual-transport (SSL + Encapsulating Security Payload) full Layer 3 VPN connectivity with granular access control. |
Application VPN | Client/server proxy application that tunnels traffic from specific applications to specific destinations (available for Windows devices only). |
Layer 7 Web single sign-on (SSO) via SAML | Allows end users to authenticate to the network through a Layer 3 tunnel, while simultaneously enjoying SSO to Web applications accessed through their browser via SAML SSO support. |
Ease of use | Seamless roaming from remote access to local LAN access (Pulse Policy Secure). |
Endpoint integrity and assessment | Assess and remediate end user devices prior to authentication with easy policy definition. Available on Windows, Mac OS X, Apple iOS, Android, and Windows Mobile 6.5 (capabilities vary by platform). Available pre-installed with Microsoft Windows 8.1 and RT. |
Split tunneling options |
|
Flexible launch options (standalone client, browser-based launch) |
Users can easily launch SSL VPN via their Web browser, or directly from their desktop. |
Supports Pulse Cloud Secure Solution |
|
Preconfiguration options (Windows and Mac only) |
Administrators can preconfigure a Pulse Secure deployment with a list of gateways for end users to choose from. |
Authentication options | Administrators can deploy Pulse Secure for remote user authentication using a wide array of authentication mechanisms, including hardware token, smart card, soft token, Google Authenticator, one-time passwords and certificate authentication. |
RDP/Telnet/SSH sessions using HTML5 | 100% clientless access using HTML5 browsers. |
VMWare Horizon and Citrix Xen Support | Supports VMWare Horizon View 6.0.1, 6.1 & 6.2; 7.0 for VMWare Horizon View, Citrix Xen 7.6, StoreFront 2.6 & 3.0. |
Granular SSL Cipher Configuration | Enables the administrator to select specific ciphers over those pre-configured for highly secure compliance. |
End-to-End Layered Security
Pulse Connect Secure provides complete end-to-end layered security, including endpoint client, device, data, and server layered security controls.
Feature | Feature Description | Benefits |
---|---|---|
Host Checker |
|
|
Trusted Network Connect (TNC) support in Host Checker | Allows interoperability with diverse endpoint security solutions from antivirus to patch management to compliance management solutions. | Enables customers to leverage existing investments in endpoint security solutions from third-party vendors. |
Always-On VPN | Ensure all traffic from endpoints is sent over the tunnel which is set up automatically when an Internet connected is detected. | Enables organizations to enforce security, compliance and visibility on all traffic from endpoints even when they are not on-prem. |
Ease of Administration
In addition to enterprise-class security benefits, Pulse Connect Secure has a wealth of features that make it easy for the administrator to deploy and manage.
Feature | Feature Description | Benefits |
---|---|---|
Mobile Device Management (MDM) integration (Available with AirWatch and MobileIron) |
|
Extend MDM investments to gain comprehensive endpoint visibility and support additional mobile use cases. |
Secure Access for SAP Applications | Embeds Pulse Secure Per-App VPN SDK into SAP’s Fiori mobile applications. | Provides transparent, secure data center connectivity for SAP services through the existing Pulse Secure VPN appliance. Additional details are available: https://www.pulsesecure.net/solutions/sap/ |
Integration with strong authentication and identity and access management (IAM) platforms | Ability to support SecurID, Security Assertion Markup Language (SAML) including standards-based SAML v2.0 support, and public key infrastructure (PKI)/digital certificates. | Leverages existing corporate authentication methods to simplify administration. |
Bridge Certification Authority (BCA) support |
|
Enables customers who use advanced PKI deployments to deploy the Pulse Secure Appliances to perform strict standards-compliant certificate validation—before allowing data and applications to be shared between organizations and users. |
Multiple hostname support | Ability to host different virtual extranet websites from a single appliance. |
|
Intuitive Dashboard Design | View and control enterprise access to the data center and cloud from one console. (Reference Diagram 1) |
|
Customizable user interface | Creation of completely customized sign-on pages. | Provides an individualized look for specified roles, streamlining the user experience. |
Pulse One Compatible | With Pulse One, configuring, updating, and monitoring PSA or MAG Series Appliances under a centralized management console with the capabilities of a single device/cluster or across a global cluster deployment. | Enables companies to conveniently manage, configure, and maintain PSA or MAG Series Appliances and other Juniper devices from one central location. |
Pulse Application Launcher (PAL) | Enhanced support for non-JAVA based browsers. | Support for latest generation browsers (Apple, Microsoft, Google, Firefox, etc) that do not support Java and Active X. |
Diagram 1 - Dynamic UI for Pulse Connect Secure, Version 8.2
Rich Access Privilege Management Capabilities
Pulse Connect Secure provides dynamic access management capabilities. When users log into Pulse Connect Secure, they pass through a pre-authentication assessment, and are then dynamically mapped to the session role that combines established network, device, identity, and session policy settings. Users have access only to those resources that are deemed necessary for that session, according to administratordefined policies.
Feature | Feature Description | Benefits |
---|---|---|
Dynamic role mapping with custom expressions |
|
Enables the administrator to provision by purpose for each unique session. |
SSL VPN federation with NAC (Pulse Policy Secure) |
|
|
Support for RSA Authentication Manager | RSA Authentications Manager 8.1 enables Risk Based Authentication. | Offer another authentication layer option via email account. |
Support for Google Authenticator | Enables multi-factor authentication using smartphones | Leverage ubiquitous smart phones to roll out a cost-effective and self-serve two-factor authentication mechanism, where one time passcodes are generated by a mobile app |
Multiple sessions per user | Allows remote users to launch multiple remote access sessions. | Enables remote users to have multiple authenticated sessions open at the same time, such as when accessing VPN from a laptop and from a smartphone simultaneously. |
User record synchronization | Supports synchronization of user records such as user bookmarks across different Pulse Secure Appliances. | Ensures a consistent experience for users who often travel from one region to another and therefore need to connect to different Pulse Secure Appliances running Pulse Connect Secure. |
Mobile-friendly SSL VPN login pages | Provides predefined HTML pages that are customized for mobile devices, including Apple iPhone and iPad, Google Android, and Nokia Symbian devices. | Provides mobile device users with a simplified and enhanced user experience and webpages customized for their device types. |
Flexible Single Sign-On (SSO) Capabilities
Pulse Connect Secure offers comprehensive single sign-on (SSO) features. These features increase end user productivity, greatly simplify administration of large diverse user resources, and significantly reduce the number of help desk calls.
Feature | Feature Description | Benefits |
---|---|---|
SAML single sign-on for cloud and Web applications access |
|
Single sign-on to a user’s Web and cloud-based applications, simplifying the user’s connectivity experience. |
Kerberos Constrained Delegation |
|
Eliminates the need for companies to manage static passwords resulting in reduced administration time and costs. |
Kerberos SSO and NT LAN Manager (NTLMv2) support | Pulse Connect Secure will automatically authenticate remote users via Kerberos or NTLMv2 using user credentials. | Simplifies the user experience by eliminating users entering credentials multiple times to access different applications. |
Password management integration | Standards-based interface for extensive integration with password policies in directory stores (LDAP, AD, and others). |
|
Web-based SSO basic authentication and NTLM | Allows users to access other applications or resources that are protected by another access management system without reentering login credentials. | Alleviates the need for users to enter and maintain multiple sets of credentials for web-based and Microsoft applications. |
Web-based SSO forms-based, header variable-based, SAML-based | Ability to pass user name, credentials, and other customer defined attributes to the authentication forms of other products and as header variables. | Enhances user productivity and provides a customized experience. |
Provision by Purpose
Pulse Connect Secure includes different access methods. These different methods are selected as part of the user’s role, so the administrator can enable the appropriate access on a per-session basis, taking into account user, device, and network attributes in combination with enterprise security policies.
Feature | Feature Description | Benefits |
---|---|---|
Pulse Secure Client | Single, integrated, remote access client that can also provide LAN access control, and dynamic VPN features to remote users. |
|
Clientless core Web access |
|
|
IPsec/IKEv2 support for mobile devices |
|
Full L3 VPN support for new devices that support IKEv2 but for which a Pulse Secure client is not yet available. |
Virtual Desktop Infrastructure (VDI) support | Allows interoperability with VMware View Manager to enable administrators to deploy virtual desktops with Pulse Connect Secure. |
|
ActiveSync Proxy |
|
Enables customers to allow a large number of users (including employees, contractors, and partners) to access corporate resources through mobile phones via ActiveSync. |
Secure Application Manager (SAM) | A lightweight Java or Windows-based download enabling access to client/server applications. |
|
Network Connect (NC) |
|
Full Layer 3 VPN tunnel. |
How It Works:
Secure Access from any device to any app.
Product Options:
Pulse Connect Secure currently includes several license options for enablement on the PSA or MAG Series Appliances.
User License (Connect Secure - ‘CONSEC’)
Pulse Connect Secure (CONSEC) licenses are per concurrent session licenses. (Please see the Ordering Information section below for licensing details.)
CONSEC licenses provide SSL VPN functionality that allows users to access the network. They fully meet the needs of both basic and complex deployments with diverse audiences and use cases, and they require little or no client software, server changes, DMZ buildouts, or software agent deployments. For administrative ease of managing license counts, each user license enables as many concurrent sessions as specified in the license and they are additive. For example, if a 100 user license was originally purchased and the concurrent user session count grows over the next year to exceed that amount, simply adding another 100 user license to the system will now allow for up to 200 concurrent users sessions.
Key features enabled by this license include:
- The combination of core clientless access, SAM, Pulse Client/ Network Connect provides secure access to virtually any audience, from remote and mobile workers to partners or customers, using a wide range of devices from any network.
- Provision -by- purpose goes beyond role-based access controls and allows administrators to properly, accurately, and dynamically balance security concerns with access requirements.
- Advanced PKI support includes the ability to import multiple root and intermediate certificate authorities (CAs), Online Certificate Status Protocol (OCSP), and multiple server certificates.
- User self-service provides the ability for users to create their own favorite bookmarks, including accessing their own workstations from a remote location, and even changing their passwords when they are set to expire.
- Multiple hostname support, for example, https://employees. company.com, https://partners.company.com, and https:// employees.company.com/engineering, can all be made to look as though each individual user community is the only ones using the system, complete with separate logon pages and customized views that uniquely reflect the needs and desires of that audience.
- User interfaces are customizable for users and delegated administrative roles.
- Advanced endpoint security controls such as Host Checker, and, cache cleaner, ensure that users are dynamically provisioned to access systems and resources only to the degree that their remote systems are compliant with the organization’s security policies, after which remnant data is scrubbed from the user’s device so that nothing is left behind.
High Availability Clustering Capability (No Additional License Required)
Customers have the ability to build clusters without buying any additional licenses. The clustering method can be explained in two simple steps:
- Simply place an equal number of user (CONSEC) licenses on each PSA or MAG Series Appliance.
- When the PSA or MAG Series Appliances are joined together to form a cluster, all of the user licenses add up so that the cluster can now support all of the licensed users. For example, building a cluster of 1,000 users is done by bringing together two boxes with 500 user licenses in each of the two units.
If either box fails, the remaining box inherits the full 1,000 user licenses.
Clustering supports stateful peering and failover across LAN connection, so in the unlikely event that one unit fails, system configurations (such as authentication server, authorization groups, and bookmarks), user profile settings (such as user defined bookmarks and cookies), and user sessions are preserved. Failover is seamless, so there is no interruption to user/enterprise productivity, no need for users to log in again, and no downtime.
Please note that WAN clustering is not supported on the PSA or MAG Series. Multisite clustering is supported, however, provided the sites are on a campus network with LAN-like connectivity.
ICE (In Case of Emergency) License (Optional)
SSL VPNs can help keep organizations and businesses functioning by connecting people even during the most unpredictable circumstances—hurricanes, terrorist attacks, transportation strikes, pandemics, or virus outbreaks—the result of which could mean the quarantine or isolation of entire regions or groups of people for an extended period of time. With the right balance of risk and cost, the ICE license delivers a timely solution for addressing a dramatic peak in demand for remote access to ensure business continuity whenever a disastrous event strikes. ICE provides licenses for additional users on a PSA or MAG Series Appliance running Pulse Connect Secure for a limited time.
With ICE licenses, businesses can do the following:
- Maintain productivity by enabling ubiquitous access to applications and information for employees from anywhere, at any time, and on any device
- Sustain partnerships with around-the-clock, real-time access to applications and services while knowing resources are secured and protected
- Meet federal and government mandates for contingencies and continuity of operations (COOP) compliance
- Balance risk and scalability with cost and ease of deployment
For the MAG Series Appliances, the ICE licenses are available in two forms: full ICE (which allows bursting to the full capacity of the MAG Series Appliances); and a 25% burst license (which allows bursting of up to 25% of the installed license count on any given MAG Series Appliances). For example, if the customer has a MAG6610 with a 1,000 user license, the 25% burst license option will support an additional 250 users during an unplanned event. Likewise, for the Pulse PSA Series Appliances, only the full ICE licenses are available.
Premier Java RDP Applet (Optional)
With the Premier Java RDP Applet option, users can remotely access centralized Windows applications independent of the client platform (Mac OS, Linux, Windows, and so on) through Java-based technology. As a platform independent solution, the Premier Java RDP Applet lets you use the entire range of Windows applications running on the Windows Terminal Server, regardless of how the client computer is equipped. By centrally installing and managing all Windows applications, you can significantly reduce your total cost of ownership. The Premier Java RDP Applet is an OEM of the HOBlink JWT (Java Windows Terminal) product created by HOB Inc., a leading European software company specializing in Java programming.
Documentation:
Download the Pulse Secure Pulse Connect Secure Datasheet (.PDF)
Our Price: $2,495.00
Our Price: $4,945.00
Our Price: $8,795.00
Our Price: $13,595.00
Our Price: $1,630.00
Our Price: $3,220.00
Our Price: $5,720.00
Our Price: $8,840.00
Our Price: $2,450.00
Our Price: $4,830.00
Our Price: $8,580.00
Our Price: $13,260.00
Our Price: $2,940.00
Our Price: $5,800.00
Our Price: $10,300.00
Includes Maintenance/Support
Includes Maintenance/Support
Our Price: $8,500.00
Includes Maintenance/Support
Includes Maintenance/Support
Includes Maintenance/Support
Includes Maintenance/Support
Includes Maintenance/Support
Includes Maintenance/Support
Includes Maintenance/Support
Includes Maintenance/Support
Includes Maintenance/Support
Includes Maintenance/Support
Our Price: $14,450.00
Includes Maintenance/Support
Includes Maintenance/Support
Includes Maintenance/Support
Includes Maintenance/Support
Includes Maintenance/Support
Includes Maintenance/Support
Includes Maintenance/Support
Includes Maintenance/Support
Includes Maintenance/Support
Includes Maintenance/Support
Includes Maintenance/Support
Includes Maintenance/Support
Includes Maintenance/Support
Includes Maintenance/Support
Includes Maintenance/Support
Includes Maintenance/Support
Includes Maintenance/Support
Includes Maintenance/Support
Includes Maintenance/Support