2.1 ESP-Enabled Novell SSL VPN

In ESP-enabled Novell SSL VPN, the process involved in establishing a secure connection between a client machine and the different components of Novell Access Manager is as follows:

  1. The user specifies the following URL to access the SSL VPN server:

    https://<www.sslvpn.novell.com>/sslvpn/login

    <www.sslvpn.novell.com> is the DNS name of the SSL VPN server, and /sslvpn/login is the path of the SSL VPN server.

  2. The SSL VPN redirects the browser to the Identity Server for authentication.

  3. After successful authentication, the Identity Server redirects the browser back to SSL VPN.

  4. The Identity Server propagates the session information to the SSL VPN server through the Embedded Service Provider.

  5. The SSL VPN server injects the SSL VPN policy for that user into the SSL VPN servlet. The SSL VPN servlet processes the parameters and sends the policy information back to the server.

  6. The SSL VPN checks if the client machine has sufficient security restraints. For more information on client integrity checks, see Section 14.1, Configuring Policies to Check the Integrity of Client Machine.

  7. When the user accesses the applications behind the protected network, the connection goes through the secure tunnel formed with the SSL VPN server.

  8. The browser stays open throughout the SSL VPN connection to allow the keep-alive packets.

  9. When the user clicks the logout button to close the SSL VPN session, all the client components are automatically uninstalled from the workstation.