4 ms·
This really tempts me to go back to Linux as my "daily driver". My main issue is working from home, and connecting to my work's VPN. We use Pulse Secure, and i
by CorpOverreach 9y ago
This really tempts me to go back to Linux as my "daily driver".
My main issue is working from home, and connecting to my work's VPN. We use Pulse Secure, and it does a host scan that only works on Windows and Mac OS X.
Has anyone had any experience with getting Pulse Secure running under Wine and having it trick a corporate VPN host-checker that it is indeed a compliant version of Windows?
- dunham 9y agoCan you run the VPN in a VM?
- giancarlostoro 9y agoThis has been my simpler workaround at times. Use VPN for intranet specifics and do rest of work from Linux with shared folders just in case on the Windows side. Though we're not forced to use Windows for our VPN but I only ever got it working on Windows first, recently on Ubuntu, hopefully I can export my settings somehow.
- kelnos 9y agoIf it's possible to do that, then the host scan is useless from a security perspective, as that means some sort of malware could also claim to be compliant.
- acdha 9y agoThat describes 90% of enterprise security: no reasoned threat model, only stops the most primitive / old attacks, but the vendor has a nice PowerPoint deck and said it’d check a box for the auditors.
- 616c 9y agoI believe openconnect handles Pulse, which is a Juniper SSL VPN? If so, use it and fake the check script. Google openconnect infradead. I used AnyConnect at work (it does support both, despite name) but didn't have to use this feature.
- Rondom 9y agoI have successfully used OpenConnect to replace PulseSecure. Depending on the server configuration, you might need to change the user agent to Windows and have a fake-host-checker-script. The Linux version of Pulse Secure requires your administrator to configure linux as "supported" on the server-side which is often not the case, which makes it pretty much worthless. One thing I noticed is that the network-manager-plugin will disconnect you when changing networks, while the command-line-version reconnects without a need to re-authenticate. In another instance, I used a windows host with Win32-OpenSSH. I used a proxy.pac script for web browsing and for SSHing I tunnelled using the ProxyJump option. You could also configure your Windows VM to act as a router and set the routes in the Linux host to go to the VM.